Skip to content

Dependency updates - #1433

Merged
quietbits merged 10 commits into
modernizationfrom
dep-updates-2026-06
Jun 5, 2026
Merged

Dependency updates#1433
quietbits merged 10 commits into
modernizationfrom
dep-updates-2026-06

Conversation

@quietbits

Copy link
Copy Markdown
Contributor

No description provided.

@github-project-automation github-project-automation Bot moved this to Backlog (Not Ready) in DevX Jun 4, 2026
@quietbits
quietbits requested a review from Ryang-21 June 4, 2026 20:48
@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
License policy violation: npm axe-core under MIT AND MPL-2.0

Location: Package overview

From: pnpm-lock.yamlnpm/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@quietbits
quietbits merged commit 3bae81c into modernization Jun 5, 2026
7 checks passed
@quietbits
quietbits deleted the dep-updates-2026-06 branch June 5, 2026 17:33
@github-project-automation github-project-automation Bot moved this from Backlog (Not Ready) to Done in DevX Jun 5, 2026
@Ryang-21 Ryang-21 mentioned this pull request Jun 5, 2026
Ryang-21 added a commit that referenced this pull request Jun 5, 2026
* [Modernization] Make fetch default (#1394)

* Replace __USE_AXIOS__ dynamic require with static fetch default

* Add babel and webpack aliasing to emit axios variant from shared source

* Flip package.json exports: fetch default, /axios opt-in, drop /no-axios

* Update eventsource and remove no-eventsource build (#1395)

* update eventsource to v4.1.0 and remove conditional import of eventsource

* remove the dom-monkeypatch as its now included in the tsconfig lib field

* build and export cjs and esm build varients, remove export of umd bundles

* Base Migration (#1399)

* move stellar-base src under src/base

* migrate from classic yarn to pnpm (#1400)

* remove randomBytes for universal crypto.getRandomValues

* replace sha.js with noble/hashes and update to version 2.2.0

* update BigNumber to v11.0.0

* replace noble/curves with noble/ed25519 for reduced bundle size

* replace toml with smol-toml

* replace URI for native URL (#1402)

* refactor: replace URI usage for native URL + URLSearchParam objects

* allow expandUriTemplate to handle relative templated links

* Tooling modernization: Node 22, husky v9, pnpm minimumReleaseAge, drop nyc (#1408)

* Update husky config + remove nyc

* Root .nvmrc + bump Node to v22

* pnpm minimumReleaseAge config

* Use pnpm workspace (#1417)

* New docs (#1413)

* TypeDoc setup

* P27 updates (#1429)

* Update XDR base URLs and improve Makefile for TypeScript definitions

* pull and regenerate xdr definitions for p27

* handle signing the new SorobanCredential varients

* add CAP-71 delegate-credential signing helpers

  - buildAuthorizationEntryPreimage: expose the signature payload (authorizeEntry
    now builds its preimage through it)
  - buildWithDelegatesEntry: wrap ADDRESS/ADDRESS_V2 into ADDRESS_WITH_DELEGATES,
    sorting + de-duping delegates; top-level signature defaults to Void
  - authorizeEntry: optional forAddress to fill a specific node (top-level or a
    delegate) instead of always the top-level
  - export the new helpers + DelegateSignature/BuildWithDelegatesParams from base

* Update readme + pre-push check for docs (#1430)

* Pre-push hook + updated docs

* Update pre-push hook

* Add @stellar/stellar-base migration guide to the installation docs

* Map xdr.HashIdPreimage in typedoc to fix docs:reference build

---------

Co-authored-by: oceans404 <[email protected]>

* Tx builder type regression (#1438)

* Implement TransactionSource interface for Account and MuxedAccount classes; update TransactionBuilder to use TransactionSource

* TSDoc: Replace @internal with @ignore tag (#1436)

* TSDoc: Replace @internal with @ignore tag

* Add friendbot call builder items

* Dependency updates (#1433)

* Minor: axios + bignumber.js

* Patch: vitest + @vitest

* Minor astro + patch @astro

* Minor: esbuild to v0.27.7 (not latest v0.28.0)

* Some patch + minor

* Major: @rollup/plugin-commonjs

* Major: cross-env + dotenv

* Major: jsdom

* Updated pnpm-lock

* Auth flag namespace (#1441)

* add back AuthFlag namespace

* fix: update build types script for axios to ensure generated types are copied correctly

* P27 guide (#1440)

* add p27 guide

* docs: add task-oriented guides (connect-and-fund, send-a-payment) + internal-link tooling (#1434)

* docs: add internal-link tooling (base-prefix rewriting + dead-link validation)

* docs: add connect-and-fund and send-a-payment guides

* docs: add issue-an-asset guide

* docs: refine issue-an-asset guide (token framing, typed helper, review fixes)

* docs: add query-and-stream guide

* docs: add handle-errors guide

* docs: link guides 02-04 to the handle-errors guide

Add error-handling pointers now that guide 05 exists (sibling-link upgrade):
a primary pointer in guide 02's submit section and lighter pointers in 03/04.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: add invoke-a-contract guide (06)

Teaches invoking a deployed Soroban contract from JS with contract.Client and
AssembledTransaction: connect over RPC, preview a call by simulation, then sign
and send a state change. Uses the increment contract; deployment is linked out
to the Stellar CLI tutorial. Regenerate llms bundles.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: add contract-auth guide (07)

Covers signing Soroban contract authorization for an account other than the
transaction source, framed for AddressV2 (CAP-0071-02) readiness: the same code
is correct on the legacy ADDRESS credential today and on AddressV2 after the
Protocol 28 flip. Distinguishes envelope signing from authorization-entry
signing, and gives a before/after migration for hand-rolled signers
(buildAuthorizationEntryPreimage / authorizeEntry).

Also upgrades the Invoke a Contract guide's closing link to point at this guide,
replaces numbered guide references with named links, and regenerates the llms
bundles.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: fold versioning into the home page, drop it as a guide

Versioning and compatibility is reference material, not a task how-to, so it
moves out of the guides nav into a 'Versioning and compatibility' section on the
home page (README -> index). Repoints the agents.md reference to the new
home-page anchor and regenerates index.md + llms bundles.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: add migration guide (00)

A versioned breaking-changes guide for upgrading to the v16 modernization release (base fold-in, native fetch, ESM, Node 22) and Protocol 27 / 28 Soroban auth (AddressV2). Modeled on viem's migration guide: one section per version, one entry per change, with before/after diffs. Sorts first in the guides nav and opens with a pointer to the home-page versioning section.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

* docs: link API references in migration guide (00)

Link the first mention of each documented symbol (Keypair, the auth helpers, contract.Client/basicNodeSigner/signAuthEntries, rpc.Server/Horizon.Server, getLatestLedger, BalanceResponse, SigningCallback) to its reference page, base-agnostic, matching guide 07. Anchors verified against the rendered reference pages; internal link check passes.

Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Co-authored-by: Ryan Yang <[email protected]>
Co-authored-by: Iveta <[email protected]>

* update package version to 16.0.0-rc.1

* fix: improve token formatting logic

---------

Co-authored-by: Iveta <[email protected]>
Co-authored-by: oceans404 <[email protected]>
Co-authored-by: Steph <[email protected]>
Co-authored-by: Claude Opus 4.8 (1M context) <[email protected]>
Co-authored-by: Iveta <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants