Ecosystem metrics

New Repos
5
New
Commits
1,003
up 24.9%
Releases
10
up 0.0%
Contributors
54
up 1.9%
Merges
22
up 46.7%

Repository Explorer

10774 commits in all time May 17, 2026 22:45 – Aug 15, 2026 22:45 UTC
ipaleka frontend
Allauth and bundlename page templates redesigned
Git Commit 6dfeecaf Branch development Document 50/1,472 ++ 707 --
sofinico gGov
Merge dcc580548a22b9bb24f3dfdf68aff3dfaf8c4c43 into 1a1947847e9a212f1fbdd0a78bb9efa3858c6b6c
Git Commit 7cade7e1 Branch pull/105/merge Document 16/1,043 ++ 6 --
sofinico gGov
chore: add useful context prop to the pipeline + readme
Git Commit dcc58054 Branch feat/frac-pipeline Document 2/32 ++ 16 --
ipaleka frontend
Allauth and bundlename page templates redesigned
Git Commit 561a873b Branch development Document 48/1,372 ++ 707 --
sofinico gGov
chore: test run with committee iteration
Git Commit 07f758a9 Branch feat/frac-pipeline Document 6/390 ++ 182 --
ipaleka frontend
First batch of page templates are redesigned using DaisyUI
Git Commit 6da35012 Branch development Document 23/1,222 ++ 604 --
pbennett reti
Merge pull request #411 from algorandfoundation/dev
v1.5.0
Git Commit e23077f5 Branch main Document 55/2,887 ++ 472 --
pbennett reti
chore: release v1.5.0
Git Commit 813a7ced Branch dev Document 3/3 ++ 3 --
github-actions[bot] wallet
cicd deploy 1.2026.08.15-main [skip ci]
Git Commit 0cb734bf Branch master Document 1/1 ++ 1 --
scholtz-aures wallet
Deploying to gh-pages from @ scholtz/wallet@798e72f5f36ead5a572b396292230ab398ee29ea 🚀
Git Commit 0a706417 Branch gh-pages Document 9/15 ++ 15 --
scholtz-aures wallet
feat: Add health check endpoint for Kubernetes readiness and liveness probes
Git Commit 798e72f5 Branch master Document 1/9 ++ 0 --
pbennett reti
Merge pull request #410 from algorandfoundation/perf/ui-bulk-data-loading
perf(ui): load validator and pool state in bulk, persist the query cache
Git Commit 54aa20fd Branch dev Document 55/2,884 ++ 469 --
ipaleka frontend
First batch of page templates are redesigned using DaisyUI
Git Commit b2f4e160 Branch development Document 21/1,111 ++ 603 --
Make the release gate build the library it exists to test
TCE-23's fix was incomplete, and this is my own gate. release.yml gained a
`test` job so a tag could not produce a signed, SLSA-attested artifact without
tests running. It runs `pytest tests` with a floor of 15 executed -- but with
no `env:` block and no Falcon library build step.

So on a release tag every lib-gated test SKIPS, and the floor is satisfied
entirely by tests that touch no cryptography. Measured on this machine:

  tests executed (old floor of 15): 59  -> OLD gate PASSES, signs the release
  crypto tests skipped:             12

A gate that passes while the thing it exists to check did not run is the exact
defect class this repo's register documents, and it was sitting in the fix for
a previous instance of it.

Now mirrors ci.yml's signature-kat job: fetch the pinned Falcon source
(ce15e75, the commit go-algorand vendors), assert the pinned-build digest and
the emulated FP backend, build the shared library, then run the suite with
TRELYAN_REQUIRE_KAT=1 and grep the log for the skip marker.

Keeps the 15-test floor AND adds the skip check, because they catch different
things: the floor catches a suite that silently shrank, the grep catches a
suite that ran without the crypto. The floor alone was satisfied by a run in
which every Falcon test skipped, which is how this survived.

A release must not be held to a weaker standard than a pull request.

Verified both directions on a lib-less run: 59 executed clears the old floor,
12 skip markers trip the new guard.
Git Commit af76dfd6 Branch fix/verify-pubkey-length-oob Document 1/45 ++ 6 --
Reject a mis-sized pubkey in verify() — it was a reachable OOB read
HIGH. `falcon_det1024_verify_compressed` takes NO pubkey length parameter:
deterministic.c calls falcon_verify(..., pubkey, FALCON_DET1024_PUBKEY_SIZE,
...), so it reads exactly 1793 bytes from that pointer regardless of what the
caller allocated. `sig` and `message` are length-delimited and bounded; pubkey
alone was not.

FalconDet1024.verify() passed pubkey straight through as a bare c_char_p with
no check, so a shorter buffer read up to 1729 bytes past the end. Reachable
from the shipped public API -- trelyan_pq.verify is exported from __init__ --
so a verifier reading a pubkey from an arbitrary box or file could crash, or
compute a verdict partly from unrelated adjacent heap memory.

Proved with a guard page (two pages, only the first committed, payload flush
against the boundary):

  full 1793-byte pubkey -> returns cleanly, reads exactly 1793
  1792-byte pubkey      -> ACCESS VIOLATION at the first byte past the buffer
  64-byte pubkey        -> ACCESS VIOLATION

The one-byte-short case is the one that matters: it is the realistic
truncation. Reaching it needs no valid signature -- junk bytes with the right
two header values get there.

The asymmetry is what marks it an oversight rather than a decision: sign() has
always checked len(privkey) != PRIVKEY_SIZE. verify() checked nothing.

WHY NOTHING CAUGHT IT, which is the part worth keeping:

  * tests/fuzz/fuzz_falcon_verify.cc (C/ASan, 13.8M execs) DOCUMENTS this exact
    invariant and honours it -- it always hands the function a fixed 1793-byte
    buffer, and its comment calls a smaller one "a caller-side over-read -- a
    harness bug, not a finding". Correct, and it means that harness could never
    surface this by construction.
  * tests/fuzz/fuzz_encoding_atheris.py DID feed short pubkeys and asserted
    verify() "must return False, not raise" -- an assertion the code could not
    satisfy, because it crashed instead. That file is referenced by no
    workflow, so it has never run.
  * No test varied pubkey length; the KAT and fuzz suites vary the signature
    only, always with a full-size key.

The invariant was written down in one file, violated in another, and the
harness that would have caught it was never wired up.

Fixed in BOTH copies. contracts/falcon_det1024.py is the one deploy_testnet.py
signs real TestNet inscriptions with, and fixing only the SDK is exactly how
TCE-03's cwd hijack survived its first fix.

Raises rather than returning False, matching sign(): a mis-sized key is a
caller error, not a failed verification, and returning False would let a
truncated key read as "signature invalid". The Atheris harness's contract is
corrected to expect that, with the reason recorded inline.

9 regression tests, none needing the C library so they run everywhere.
Mutation-proved: removing either guard fails all 9. SDK suite 50 -> 59 passed,
19 skipped.

Security impact: closes a memory-safety defect reachable from the public API of
an audit-bound crypto SDK. No protocol, wire-format or on-chain change; the
contract's own ABI already pins committed_pubkey to 1793 bytes, so on-chain
state was never the exposure -- the off-chain verifier path was.
Git Commit 906715ca Branch fix/verify-pubkey-length-oob Document 4/171 ++ 3 --
ipaleka frontend
Initial setup for the redesign using DaisyUI
Git Commit 33655ff8 Branch development Document 13/738 ++ 42 --
ipaleka frontend
User widgets are now independent of a frontend framework
Git Commit 3769c949 Branch development Document 5/74 ++ 7 --
ipaleka widgets
Widgets are now independent of a frontend framework
Git Commit fefce7bc Branch main Document 8/106 ++ 54 --
ipaleka frontend
Wallet package is now independent of a frontend framework
Git Commit b8b1ae83 Branch development Document 10/380 ++ 137 --
ipaleka frontend
Bugfixes for stale icons and wrong ALGO available amount in the swap widget
Git Commit 7f873dc7 Branch main Document 4/545 ++ 4 --
jannotti go-algorand
Merge 97a5d16c1dde54714d5b6330bcb06dd8b9964164 into 8d7f8f778c8668bb5162fad3179bbb4cbb1082bb
Git Commit 7f8d48b3 Branch pull/6707/merge Document 14/1,363 ++ 37 --
jannotti go-algorand
Implement ec_map_to ED25519
Git Commit 97a5d16c Branch pull/6707/head Document 13/534 ++ 26 --
ipaleka widgets
Bugfixes for stale icons and wrong ALGO available amount
Git Commit bbf7c7cd Branch main Document 3/204 ++ 2 --