chore(deps): bump lucide-react from 1.11.0 to 1.25.0 in /frontend - #1102
dependabot[bot] wants to merge 30 commits into
Conversation
Add contracts/test-support to the workspace members list and register it as a workspace dependency. Wire amm-pool and governance dev-dependencies to use it, demonstrating the pattern for other contracts to follow.
Document the security invariants of the WASM module: input bounds, no side effects, panic safety, no shell injection surface, and the explicit determinism contract (same input → same output). Add a sort on findings by (code, message, location) to enforce determinism at the public API boundary regardless of internal pass ordering. Add tests verifying the sort is stable across calls and that progressive analysis matches plain analysis in total finding count.
Add inline Rust source fixtures (clean contract, auth-gap contract, panic contract) to verify known-bad patterns produce expected findings and clean source produces zero findings. Add idempotency test asserting repeated analysis of the same source returns identical results, and round-trip test for default_config_json validity.
Add three new flags to improve badge UX/DX: - --quiet / -q: suppress all non-error output for CI scripts - --format json: emit a machine-readable BadgeOutput struct (status, color, total_findings, svg_path, markdown, shields_url) for tooling that needs to inspect the badge result programmatically - --shields-url: generate a pre-filled shields.io badge URL alongside the local SVG, useful for README embedding without hosting SVGs Existing markdown/svg behaviour is unchanged when flags are omitted. Add tests for all three flags and for build_shields_url.
…exhaustion rule, and CFG-based taint analysis Fixes the unused-import and missing-Debug-derive clippy failures blocking `make lint`/`cargo build` on sanctifier-core, suppresses trivial constant-folded arithmetic warnings (e.g. 1000 + 500), adds the S031 Gas Exhaustion Risk rule for unbounded user-controlled loops, and replaces the single-pass AST taint walker with an intra-procedural CFG and fixed-point taint dataflow engine so taint introduced inside loop bodies or only one if-branch is no longer missed. Closes #490 Closes #402 Closes #403 Closes #401
Closes #499, #500, #502, #503 S004 (ledger size): add performance benchmarks with budgets for small, nested, many-structs, and vault contract payloads including strict-limit variant using BatchSize::SmallInput. S005 (storage key collision): add unit tests + fixture covering cross- function collisions, cross-storage-type non-collisions, single key non-collision, and threat model edge cases. Fix fixture parse failure caused by outer doc comments before #![no_std] in syn::parse_str. S007 (custom rules): add unit tests for validate_custom_rules (invalid regex, empty pattern, empty name, Display impl) and analyze_custom_rules (line numbers, multi-match, overlapping rules, severity propagation, snippet trimming, graceful invalid-regex handling). S008 (events analysis): add unit tests + fixtures for inconsistent topic count detection and gas optimization hints. Fix multiline event publish calls (env.events()\n.publish(...)) being missed by the line scanner by adding a normalization pass that joins split lines before scanning.
… update README Closes #305, #521, #526, #527. Changes by issue: #305 — README.md - Update `sanctifier analyze` CLI reference to document all flags: --timeout, --exit-code, --min-severity, --profile, --format ndjson|sarif - Refresh quick-start example (sanctifier analyze ./contracts) - Expand JSON output example to match actual schema (error_codes, rule_violations) - Note ndjson streaming mode in the output-contract section #527 — runtime guards integration UX (input validation + error messages) - errors.rs: add E010 (invalid network) and E011 (missing credentials) with constructor methods and actionable hint strings; 6 new unit tests - deploy.rs: validate network against testnet|futurenet|mainnet before any I/O, return structured E010 error on bad value; replace bare eprintln+exit for the missing-credentials path with a structured E011 return - tests/deploy_validation_tests.rs: 8 integration tests covering E010/E011 rejection, hint content, and pass-through for all three valid networks #526 — callgraph command correctness (integration/e2e) - tests/callgraph_tests.rs: 7 integration tests covering empty contract (0 edges), invoke_contract_check variant, multiple callers in one contract, nonexistent path exit, default output file, DOT syntax validity, and two-contract attribution #521 — logging performance benchmarks + budgets - logging.rs: add make_filter(verbosity) helper for filter-build benchmarking without global side-effects; 4 unit tests including a 50 ms build-time budget - tests/logging_bench_tests.rs: 6 integration tests — 30 s wall-clock budget for quiet/verbose/JSON log modes, stderr-stream correctness for text and JSON modes, and a no-ERROR assertion for clean files in quiet mode
… binaries Issue 1 - Devcontainer detection: - Add devcontainer.ts module to detect .devcontainer/devcontainer.json - Show notification suggesting sanctifier-cli feature when missing - Add to devcontainer button inserts ghcr.io/devcontainers/features/sanctifier-cli:1 - Add comprehensive tests for hasSanctifierFeature detection Issue 2 - Hover Provider: - Implement SanctifierHoverProvider in hover.ts - Show rule code, severity, description, and Rust syntax-highlighted fix - Add Learn more link to rule documentation - Add Suppress link via sanctifier.suppressFinding command - Register hover provider for Rust language files Issue 3 - SARIF Viewer integration: - Add sanctifier.openSarifViewer command - Run sanctifier analyze --format sarif and open in SARIF Viewer extension - Save SARIF to temp file and invoke sarif.openLogs - Add sanctifier.suppressFinding command Issue 4 - Cross-platform release: - Add x86_64-unknown-linux-musl target to release matrix - Add SHA256 generation per binary (sha256sum/certutil) - Add SHA256SUMS generation job aggregating all release assets - Update README installation section with verification instructions - Add musl binary download link Also fixed TypeScript compilation by removing merge conflict artifacts in extension.ts.
…vements, and opt-in telemetry - Add RELEASE_CHECKLIST.md with pre-release, release, and post-release steps - Create Winget manifest and Scoop bucket with CI automation workflow - Refactor status bar to show current file finding count with spinner - Status bar click opens Problems panel instead of toggling enable - Add sanctifier.telemetry.enabled config (default false, opt-in) - Track scan count, findings by rule, extension/VS Code version - First-run shows opt-in dialog; never sends source code or file paths - Add vscode-extension/PRIVACY.md explaining data collection
… with exploitable delay vulnerability
- Docker: Rewrite Dockerfile to use pre-built musl binary from GitHub releases. Multi-stage build fetches binary, verifies SHA256, produces minimal scratch image (< 50 MB). Add Dockerfile.ci for CI usage. Update action.yml with optional use-docker input for containerized analysis. - npm: Create @hypersafed/sanctifier-cli wrapper package with platform detection and binary caching in ~/.sanctifier/bin/. Enables npx usage without Rust toolchain. - Homebrew: Add homebrew/sanctifier.rb formula template for macOS and Linux. CI auto-updates checksums and pushes to tap repo on release. - Release automation: Add scripts/release.sh to bump versions across all Cargo.toml, package.json, and formula files. Update RELEASE_CHECKLIST.md and CHANGELOG.md with format guidelines. - CI: Extend release workflow with docker, npm-publish, and homebrew-update jobs triggered on version tags.
…ions - Introduced a README.md for the Timelock Controller contract, detailing its role-based system, safe and vulnerable implementations, and security guarantees. - Implemented `execute()` function with delay enforcement to ensure safe execution of scheduled calls. - Implemented `execute_unsafe()` function that bypasses delay checks, highlighting potential vulnerabilities. - Added tests to validate the functionality of both implementations, ensuring that the safe version enforces delays and the unsafe version allows immediate execution. - Created test snapshots for both safe and unsafe execution scenarios to facilitate testing and validation.
… VS Code quick-fix actions - #1037: update dependabot.yml to weekly intervals with labels, reviewers, and add auto-merge workflow for patch/minor Dependabot PRs - #1041: expand docs/getting-started.md with a 5-minute tutorial covering minimal contract creation, first scan, fixing findings, and clean re-run; update README primary CTA to feature the tutorial - #1044: add ADRs 006-009 documenting rationale for Z3, syn AST parser, SARIF output format, and Soroban/WASM target selection - #1048: implement SanctifierCodeActionProvider (VS Code quick-fix lightbulbs) for S001/S002/S003/S006 findings; add pure fix helpers to analyzer.ts; register provider in extension.ts; 21 new tests, all passing
…ate CONTRIBUTING.md and MUTATION-TESTING.md
Introduce a single, shared SEP-41 conformance suite that every token contract must pass, replacing per-contract ad-hoc checks. - sanctifier-test-support: new `sep41_compliance` harness that verifies a contract's source implements all 10 SEP-41 functions with the exact signatures and correct caller authorization (mirrors core's S012 spec, but syn-only so the suite needs no Z3). - new `sep41-compliance` crate runs the suite against 3+ token contracts (my-contract plus reference AMM-LP and deposit-receipt tokens) and asserts that missing functions, wrong signatures, and missing require_auth all fail compliance. - CI: new `cargo test -p sep41-compliance` job in contracts-ci.
Each rule now has a dedicated page with: what it detects, why it matters, a vulnerable and a safe Soroban example, a CVSS v3.1 risk rating, how to fix, and cross-links to related rules. The README rule table now links every S001-S012 code to its page.
Guide for combining Sanctifier's SARIF output with Semgrep, CodeQL, and other SARIF-aware tools: merging multiple SARIF files, GitHub Code Scanning with Sanctifier + CodeQL, a Semgrep + Sanctifier workflow, Slither in a multi-tool pipeline, and exporting findings to Jira/Linear via webhooks. Ships a working Code Scanning workflow plus sample workflows for each integration.
Add proptest-based fuzzing of the analysis engine: generate random Rust source (structured Soroban contracts, free-form snippets, and arbitrary text) and run every rule, asserting the result is always Ok(findings) or Err(parse_error) and never panics. Runs as a separate CI job with a hard 60-second budget over 10,000 cases. The property test discovered a real crash: deeply nested input overflowed the recursive parser/analyzer stack and aborted the process. Fixed by an EXCESSIVE_NESTING input-validation guard that rejects pathological delimiter nesting before it reaches the recursive passes; the crash input is kept as a regression fixture. Also repairs pre-existing breakage in sanctifier-core that prevented the crate from compiling at all (a brace-spliced analyze_upgrade_patterns / analyze_custom_rules, duplicate SanctifyConfig / scan_events definitions, and an EventIssue field mismatch), without which no core test could run.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Backport the workflow-config half of 802ec32 to the start of this history so downstream commits inherit a working pipeline instead of the broken one: ci.yml's duplicate container: keys that kept it from starting, deny.toml's outdated schema, and the persistently-red non-core workflows pruned to manual dispatch. The code-level fixes from 802ec32 are applied per-commit further down this branch, where the affected files actually exist. Backport-of: 802ec32
Introduce contracts/test-support as a plain rlib crate that centralises shared Soroban test boilerplate. Compiled once by Cargo and linked into every contract's test binary rather than re-compiled per contract.
f8ba54d to
65ac2e2
Compare
|
A newer version of lucide-react exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged. |
Bumps [lucide-react](https://github.com/lucide-icons/lucide/tree/HEAD/packages/lucide-react) from 1.11.0 to 1.25.0. - [Release notes](https://github.com/lucide-icons/lucide/releases) - [Commits](https://github.com/lucide-icons/lucide/commits/1.25.0/packages/lucide-react) --- updated-dependencies: - dependency-name: lucide-react dependency-version: 1.24.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
821ed90 to
bb3ad8a
Compare
cd30c5b to
3e1bd92
Compare
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps lucide-react from 1.11.0 to 1.25.0.
Release notes
Sourced from lucide-react's releases.
... (truncated)
Commits
f229f83chore(depedencies): Update dependencies (#4553)5ff536eci(release.yml): Fix workflow and removeversionscripts in package scripts...07c885efix(docs): fix zephyr-cloud URL in readmes50d8af5docs(readme): Update readme files (#4320)