Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 0 additions & 17 deletions .changeset/fix-create-sei-next-sharp-advisories.md

This file was deleted.

18 changes: 0 additions & 18 deletions .changeset/fix-global-wallet-axios-override.md

This file was deleted.

11 changes: 0 additions & 11 deletions .changeset/fix-global-wallet-dynamic-peer-drift.md

This file was deleted.

21 changes: 0 additions & 21 deletions .changeset/fix-global-wallet-sharp-override.md

This file was deleted.

9 changes: 0 additions & 9 deletions .changeset/fix-mcp-server-instance-scoped-wallet.md

This file was deleted.

11 changes: 0 additions & 11 deletions .changeset/precompiles-get-logs-in-range.md

This file was deleted.

8 changes: 4 additions & 4 deletions bun.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

18 changes: 18 additions & 0 deletions packages/create-sei/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,23 @@
# @sei-js/create-sei

## 2.0.1

### Patch Changes

- cb882eb: Bump the Next template's `next` and `sharp` pins to clear three newly published advisories.

The generated-app smoke audits every variant and fails on any high or critical finding. Three advisories landed against the pinned versions, so the check went red without any change to the template:

- `GHSA-p293-qw3h-jr36` — critical, unauthenticated RCE on Windows-hosted Next.js servers, `>=13.4.0 <15.5.24`.
- `GHSA-2xp9-vwfh-vxw4` — critical, unauthenticated RCE in the Image Optimization API when AVIF files are used, `>=10.0.0 <15.5.24`.
- `GHSA-rgj7-g3m4-5g8c` — high, heap overflow in Sharp's bundled libheif decoder, `<0.35.4`.

`next` moves `15.5.21` to `15.5.25` and the `sharp` override `0.35.3` to `0.35.4`, both inside their pinned minors.

Next also widened its own Sharp declaration to `^0.34.3 || ^0.35.4`, so the pinned override now sits inside the range Next supports. The image notes in the template README and `next.config.mjs` said the opposite and are corrected: images stay unoptimized to avoid requiring a native Sharp build, which is a template choice rather than a security tradeoff. The `sharp` override itself still is one, and both notes now say so — the `0.34.x` half of Next's range remains inside the advisory, making `0.35.4` the floor rather than a free upgrade.

The remaining `decode-uri-component` finding is moderate and does not block the smoke.

## 2.0.0

### Major Changes
Expand Down
2 changes: 1 addition & 1 deletion packages/create-sei/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@sei-js/create-sei",
"version": "2.0.0",
"version": "2.0.1",
"description": "Scaffold new Sei applications with pre-configured templates and tooling",
"homepage": "https://github.com/sei-protocol/sei-js/tree/main/packages/create-sei#readme",
"repository": {
Expand Down
10 changes: 10 additions & 0 deletions packages/mcp-server/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,15 @@
# Changelog

## 1.0.1

### Patch Changes

- 5a40dc8: Keep each MCP runtime on the wallet configuration that passed its security check.

A later programmatic `main()` could overwrite the process-wide config object while an HTTP listener started earlier was still serving requests. New sessions on that listener then built their tool list from the updated singleton, so a wallet-disabled HTTP server could expose signing tools after a trusted stdio start in the same process. No shipped CLI or host spawn does that, but the public lifecycle returned independent runtimes without isolating their keys.

`parseArgs()` now returns a frozen `AppConfig` snapshot, and every transport handles requests against that snapshot. Stopping one runtime evicts only its provider cache entry, while other runtimes keep their original signer. HTTP transports require that snapshot and derive signing policy from it.

## 1.0.0

### Major Changes
Expand Down
2 changes: 1 addition & 1 deletion packages/mcp-server/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
"name": "@sei-js/mcp-server",
"description": "Model Context Protocol (MCP) server for interacting with EVM-compatible networks",
"type": "module",
"version": "1.0.0",
"version": "1.0.1",
"bin": "./bin/mcp-server.js",
"main": "./dist/index.js",
"module": "./dist/index.js",
Expand Down
12 changes: 12 additions & 0 deletions packages/precompiles/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,17 @@
# @sei-js/precompiles

## 3.1.0

### Minor Changes

- b7f4e54: Add `getLogsInRange`, `streamLogsInRange`, `blockRanges` and `MAX_GET_LOGS_BLOCK_RANGE` for reading logs across a block range.

`eth_getLogs` is capped per request, so reading more history than one request allows means walking it in chunks, and every project that needs logs writes that loop again. This walk only sends requests a Sei node can answer. Spans are counted inclusively the way the node counts them (2000 blocks passes, 2001 is refused). A span too heavy to answer is halved and asked again, whether the node refuses it for matching more than `max_log_no_block` logs (sei-chain v6.7 and later), the response passes viem's size limit (before v6.7, when bounded requests are served whole), or the span times out. A node whose refusal names a smaller `max_blocks_for_log` is walked at that, and busy or rate limited refusals are retried with backoff. Every request carries an explicit `toBlock`, because nodes before v6.7 silently cut an open-ended request off at the log cap.

`streamLogsInRange` yields each chunk with its logs, so a backfill can store as it goes and resume from the last `toBlock`. `getLogsInRange` collects the walk into one array and awaits an optional `onChunk` for each chunk. Both take viem's `getLogs` filter (`address`, `event` with `args`, `events`, `strict`), accept a whole contract ABI as `events`, and take any viem `Client`, including one that carries an account. Without a `toBlock` they read to the head, since Sei finalises a block as it is produced. `blockRanges` gives the fixed-width plan without making requests.

No dependency or peer range changes: this uses the `viem` peer already declared.

## 3.0.0

### Major Changes
Expand Down
2 changes: 1 addition & 1 deletion packages/precompiles/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@sei-js/precompiles",
"version": "3.0.0",
"version": "3.1.0",
"description": "TypeScript library for EVM interactions on the Sei blockchain",
"type": "module",
"main": "./dist/index.js",
Expand Down
Loading
Loading