chore(deps): update dependency uuid to v11.1.1 [security] - #320

Merged
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability
Jul 7, 2026
Merged

chore(deps): update dependency uuid to v11.1.1 [security]#320
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability

Conversation

@renovate

@renovaterenovateBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
uuid11.1.011.1.1ageconfidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

CVE-2026-41907 / GHSA-w5hq-g745-h8pq

More information

Details

Summary

The v3(), v5(), and v6()API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4(), v1(), and v7() API methods explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3()/v5() path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "import {v4,v5,v6} from './dist-node/index.js';const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)],]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); }}"

Observed:

  • v4() THREW RangeError
  • v5() NO_THROW
  • v6() NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
170, 170, 170, 170,
75, 224, 100, 63
]
v6 [
187, 187, 187, 187,
31, 19, 185, 64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4()/v1()/v7():

if(offset<0||offset+16>buf.length){thrownewRangeError(`UUID byte range ${offset}:${offset+15} is out of buffer bounds`);}

Apply to:

  • src/v35.ts (covers v3() and v5())
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v11.1.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch 2 times, most recently from b681dae to 7fe547cCompareMay 28, 2026 21:02
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7fe547c to 7677f37CompareJune 10, 2026 14:57
@renovate
renovateBot changed the base branch from v0.39 to mainJune 10, 2026 14:57
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJune 10, 2026 14:57
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

2 similar comments
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security]chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedJul 1, 2026
@renovaterenovateBot closed this Jul 1, 2026
@renovate
renovateBot deleted the renovate/npm-uuid-vulnerability branch July 1, 2026 01:05
@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedchore(deps): update dependency uuid to v11.1.1 [security]Jul 1, 2026
@renovaterenovateBot reopened this Jul 1, 2026
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 33fa729 to 7677f37CompareJuly 1, 2026 21:30
@renovate
renovateBot changed the base branch from v0.40-dev to mainJuly 1, 2026 21:30
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7677f37 to 33fa729CompareJuly 1, 2026 21:30
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

1 similar comment
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@MuncleUscles
MuncleUscles merged commit 45a3ce9 into v0.40-devJul 7, 2026
20 of 21 checks passed
MuncleUscles added a commit that referenced this pull request Jul 8, 2026
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350)
Propagates #349 to v0.40-dev.
* docs: add branching guide (#353)
* docs: add branching guide
* ci: harden testnet smoke timeout
* feat: support fee profiles in contract commands (#355)
* feat: support fee profiles in contract commands
* test: make fee profile deploy test portable
* feat: staking validators discovery (#357)
* feat: add staking validators discovery
* feat: epoch-aware validator listing with below-min indicator
* fix(staking): account-less client for read-only staking queries
getReadOnlyStakingClient threw 'Account not found' on fresh installs;
listings and other reads don't need a local account.
* feat: vesting commands (#358)
* feat: add vesting commands
* feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status
Drives the CON-607 Vesting.sol validator leg through the SDK's named
vestingValidator* actions; list/status enumerate getValidatorWallets
with per-wallet deposited principal.
* chore(deps): update dependency uuid to v11.1.1 [security] (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(init): use backend provider id "google" for Gemini (#359)
Selecting Gemini during `genlayer init` failed with:
Requested providers '{'geminiai'}' do not match any stored providers.
The selected provider id is forwarded verbatim to
sim_createRandomValidators, but the backend's llm_provider table stores
Gemini as "google". Rename the provider id geminiai -> google so it
matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are
unchanged.
Since "geminiai" never resolved to a valid provider, no working
configuration relied on it.
Fixes#271
Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com>
* fix(docs-sync): stop overwriting the generated root _meta.json (#352)
The sync-docs workflow rsynced the generated category-based
docs/api-references/_meta.json into genlayer-docs and then immediately
overwrote it with a hardcoded heredoc containing the pre-grouping flat
command list (init, up, deploy, ...). Those keys no longer match the
directory layout, so the genlayer-docs sidebar rendered broken entries
on every sync (fixed manually in genlayer-docs#426; this removes the
cause).
Also make the generated root meta complete:
- add "index": "Overview" for the generated index.mdx
- append ungrouped top-level commands (estimate-fees, finalize,
finalize-batch) so they get explicit nav entries instead of relying
on Nextra's implicit append
Snapshot under docs/api-references regenerated against current main
(picks up the new estimate-fees command and latest help text).
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* fix: drop getSlashingAddress from validator-history (#361)
getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev),
causing `genlayer staking validator-history` to crash with
`client.getSlashingAddress is not a function` before any history is fetched.
Resolve the idleness (slashing) contract address dynamically via viem
readContract against consensusMainContract.getIdlenessAddress(), falling
back to the staking contract address if resolution fails so reward events
still display.
Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev.
Supersedes #344.
Fixes#341
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* feat(network): custom network profiles with deployment-file import (#362)
* feat(network): custom network profiles with deployment-file import
genlayer network add <alias> --base <built-in> [--deployment <json>]
[--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager
|--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>]
Profiles persist as base + address overrides only; resolveNetwork loads
the base chain fresh from genlayer-js and applies overrides, so ABIs
never go stale. network set/list/info/remove and StakingAction --network
accept custom aliases. The consensus deployments.json shape is parsed by
walking the tree for ContractName->address leaves (ConsensusMain,
ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage,
Appeals); flags take precedence over the file. Adds a prepare script so
npm install from a git ref builds dist. Verified: 576 vitest tests, full
manual smoke (add/list/set/info/remove with a deployment file).
* chore(deps): bump genlayer-js to v2-dev tip for vesting actions
The locked v2-dev SHA (28e99fbc) predates the vesting client actions;
vestingValidatorJoin and friends land at 666d1156. Verified live:
vesting validator create succeeds against a #1162-branch consensus
deployment.
* docs(cli): regenerate API references; fix option placeholder regex
The docs generator's option regex only matched <word> placeholders, so
flags with dots or hyphens in the value name (--base <built-in-alias>,
--deployment <path.json>, --deployment-key <dot.path>) were silently
dropped from the options tables. Widen to <[^>]+> and regenerate: adds
the network add/remove pages and the previously undocumented vesting
command section (validator create/deposit/exit/claim, operator-transfer,
set-identity, delegate/undelegate/claim/withdraw/list).
* fix(vesting): resolve validator wallet address in create output
The join receipt does not carry the new wallet address, so the output
printed validatorWallet: undefined. Read getValidatorWallets from the
vesting contract after the join and report the newest entry. Verified
live against a #1162-branch deployment.
* fix: make git install build lifecycle robust (#363)
* fix: make git install build script self contained
* chore: refresh genlayer-js lockfile
* fix: make keychain dependency optional
* fix: restore git prepare build
* fix: include build dependency for git installs
* chore: keep esbuild as dev dependency
* ci: publish prereleases to npm dist tags (#364)
* ci: add clarke cli tarball release
* ci: publish prereleases to npm dist tags
* Release v0.40.0-rc1 [skip ci]
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com>
Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com>
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MuncleUscles
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

chore(deps): update dependency uuid to v11.1.1 [security] - #320

Merged
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability
Jul 7, 2026
Merged

chore(deps): update dependency uuid to v11.1.1 [security]#320
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability

Conversation

@renovate

@renovaterenovateBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
uuid11.1.011.1.1ageconfidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

CVE-2026-41907 / GHSA-w5hq-g745-h8pq

More information

Details

Summary

The v3(), v5(), and v6()API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4(), v1(), and v7() API methods explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3()/v5() path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "import {v4,v5,v6} from './dist-node/index.js';const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)],]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); }}"

Observed:

  • v4() THREW RangeError
  • v5() NO_THROW
  • v6() NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
170, 170, 170, 170,
75, 224, 100, 63
]
v6 [
187, 187, 187, 187,
31, 19, 185, 64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4()/v1()/v7():

if(offset<0||offset+16>buf.length){thrownewRangeError(`UUID byte range ${offset}:${offset+15} is out of buffer bounds`);}

Apply to:

  • src/v35.ts (covers v3() and v5())
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v11.1.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch 2 times, most recently from b681dae to 7fe547cCompareMay 28, 2026 21:02
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7fe547c to 7677f37CompareJune 10, 2026 14:57
@renovate
renovateBot changed the base branch from v0.39 to mainJune 10, 2026 14:57
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJune 10, 2026 14:57
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

2 similar comments
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security]chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedJul 1, 2026
@renovaterenovateBot closed this Jul 1, 2026
@renovate
renovateBot deleted the renovate/npm-uuid-vulnerability branch July 1, 2026 01:05
@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedchore(deps): update dependency uuid to v11.1.1 [security]Jul 1, 2026
@renovaterenovateBot reopened this Jul 1, 2026
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 33fa729 to 7677f37CompareJuly 1, 2026 21:30
@renovate
renovateBot changed the base branch from v0.40-dev to mainJuly 1, 2026 21:30
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7677f37 to 33fa729CompareJuly 1, 2026 21:30
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

1 similar comment
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@MuncleUscles
MuncleUscles merged commit 45a3ce9 into v0.40-devJul 7, 2026
20 of 21 checks passed
MuncleUscles added a commit that referenced this pull request Jul 8, 2026
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350)
Propagates #349 to v0.40-dev.
* docs: add branching guide (#353)
* docs: add branching guide
* ci: harden testnet smoke timeout
* feat: support fee profiles in contract commands (#355)
* feat: support fee profiles in contract commands
* test: make fee profile deploy test portable
* feat: staking validators discovery (#357)
* feat: add staking validators discovery
* feat: epoch-aware validator listing with below-min indicator
* fix(staking): account-less client for read-only staking queries
getReadOnlyStakingClient threw 'Account not found' on fresh installs;
listings and other reads don't need a local account.
* feat: vesting commands (#358)
* feat: add vesting commands
* feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status
Drives the CON-607 Vesting.sol validator leg through the SDK's named
vestingValidator* actions; list/status enumerate getValidatorWallets
with per-wallet deposited principal.
* chore(deps): update dependency uuid to v11.1.1 [security] (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(init): use backend provider id "google" for Gemini (#359)
Selecting Gemini during `genlayer init` failed with:
Requested providers '{'geminiai'}' do not match any stored providers.
The selected provider id is forwarded verbatim to
sim_createRandomValidators, but the backend's llm_provider table stores
Gemini as "google". Rename the provider id geminiai -> google so it
matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are
unchanged.
Since "geminiai" never resolved to a valid provider, no working
configuration relied on it.
Fixes#271
Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com>
* fix(docs-sync): stop overwriting the generated root _meta.json (#352)
The sync-docs workflow rsynced the generated category-based
docs/api-references/_meta.json into genlayer-docs and then immediately
overwrote it with a hardcoded heredoc containing the pre-grouping flat
command list (init, up, deploy, ...). Those keys no longer match the
directory layout, so the genlayer-docs sidebar rendered broken entries
on every sync (fixed manually in genlayer-docs#426; this removes the
cause).
Also make the generated root meta complete:
- add "index": "Overview" for the generated index.mdx
- append ungrouped top-level commands (estimate-fees, finalize,
finalize-batch) so they get explicit nav entries instead of relying
on Nextra's implicit append
Snapshot under docs/api-references regenerated against current main
(picks up the new estimate-fees command and latest help text).
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* fix: drop getSlashingAddress from validator-history (#361)
getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev),
causing `genlayer staking validator-history` to crash with
`client.getSlashingAddress is not a function` before any history is fetched.
Resolve the idleness (slashing) contract address dynamically via viem
readContract against consensusMainContract.getIdlenessAddress(), falling
back to the staking contract address if resolution fails so reward events
still display.
Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev.
Supersedes #344.
Fixes#341
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* feat(network): custom network profiles with deployment-file import (#362)
* feat(network): custom network profiles with deployment-file import
genlayer network add <alias> --base <built-in> [--deployment <json>]
[--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager
|--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>]
Profiles persist as base + address overrides only; resolveNetwork loads
the base chain fresh from genlayer-js and applies overrides, so ABIs
never go stale. network set/list/info/remove and StakingAction --network
accept custom aliases. The consensus deployments.json shape is parsed by
walking the tree for ContractName->address leaves (ConsensusMain,
ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage,
Appeals); flags take precedence over the file. Adds a prepare script so
npm install from a git ref builds dist. Verified: 576 vitest tests, full
manual smoke (add/list/set/info/remove with a deployment file).
* chore(deps): bump genlayer-js to v2-dev tip for vesting actions
The locked v2-dev SHA (28e99fbc) predates the vesting client actions;
vestingValidatorJoin and friends land at 666d1156. Verified live:
vesting validator create succeeds against a #1162-branch consensus
deployment.
* docs(cli): regenerate API references; fix option placeholder regex
The docs generator's option regex only matched <word> placeholders, so
flags with dots or hyphens in the value name (--base <built-in-alias>,
--deployment <path.json>, --deployment-key <dot.path>) were silently
dropped from the options tables. Widen to <[^>]+> and regenerate: adds
the network add/remove pages and the previously undocumented vesting
command section (validator create/deposit/exit/claim, operator-transfer,
set-identity, delegate/undelegate/claim/withdraw/list).
* fix(vesting): resolve validator wallet address in create output
The join receipt does not carry the new wallet address, so the output
printed validatorWallet: undefined. Read getValidatorWallets from the
vesting contract after the join and report the newest entry. Verified
live against a #1162-branch deployment.
* fix: make git install build lifecycle robust (#363)
* fix: make git install build script self contained
* chore: refresh genlayer-js lockfile
* fix: make keychain dependency optional
* fix: restore git prepare build
* fix: include build dependency for git installs
* chore: keep esbuild as dev dependency
* ci: publish prereleases to npm dist tags (#364)
* ci: add clarke cli tarball release
* ci: publish prereleases to npm dist tags
* Release v0.40.0-rc1 [skip ci]
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com>
Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com>
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MuncleUscles
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): update dependency uuid to v11.1.1 [security] - #320

Merged
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability
Jul 7, 2026
Merged

chore(deps): update dependency uuid to v11.1.1 [security]#320
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability

Conversation

@renovate

@renovaterenovateBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
uuid11.1.011.1.1ageconfidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

CVE-2026-41907 / GHSA-w5hq-g745-h8pq

More information

Details

Summary

The v3(), v5(), and v6()API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4(), v1(), and v7() API methods explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3()/v5() path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "import {v4,v5,v6} from './dist-node/index.js';const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)],]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); }}"

Observed:

  • v4() THREW RangeError
  • v5() NO_THROW
  • v6() NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
170, 170, 170, 170,
75, 224, 100, 63
]
v6 [
187, 187, 187, 187,
31, 19, 185, 64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4()/v1()/v7():

if(offset<0||offset+16>buf.length){thrownewRangeError(`UUID byte range ${offset}:${offset+15} is out of buffer bounds`);}

Apply to:

  • src/v35.ts (covers v3() and v5())
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v11.1.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch 2 times, most recently from b681dae to 7fe547cCompareMay 28, 2026 21:02
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7fe547c to 7677f37CompareJune 10, 2026 14:57
@renovate
renovateBot changed the base branch from v0.39 to mainJune 10, 2026 14:57
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJune 10, 2026 14:57
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

2 similar comments
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security]chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedJul 1, 2026
@renovaterenovateBot closed this Jul 1, 2026
@renovate
renovateBot deleted the renovate/npm-uuid-vulnerability branch July 1, 2026 01:05
@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedchore(deps): update dependency uuid to v11.1.1 [security]Jul 1, 2026
@renovaterenovateBot reopened this Jul 1, 2026
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 33fa729 to 7677f37CompareJuly 1, 2026 21:30
@renovate
renovateBot changed the base branch from v0.40-dev to mainJuly 1, 2026 21:30
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7677f37 to 33fa729CompareJuly 1, 2026 21:30
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

1 similar comment
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@MuncleUscles
MuncleUscles merged commit 45a3ce9 into v0.40-devJul 7, 2026
20 of 21 checks passed
MuncleUscles added a commit that referenced this pull request Jul 8, 2026
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350)
Propagates #349 to v0.40-dev.
* docs: add branching guide (#353)
* docs: add branching guide
* ci: harden testnet smoke timeout
* feat: support fee profiles in contract commands (#355)
* feat: support fee profiles in contract commands
* test: make fee profile deploy test portable
* feat: staking validators discovery (#357)
* feat: add staking validators discovery
* feat: epoch-aware validator listing with below-min indicator
* fix(staking): account-less client for read-only staking queries
getReadOnlyStakingClient threw 'Account not found' on fresh installs;
listings and other reads don't need a local account.
* feat: vesting commands (#358)
* feat: add vesting commands
* feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status
Drives the CON-607 Vesting.sol validator leg through the SDK's named
vestingValidator* actions; list/status enumerate getValidatorWallets
with per-wallet deposited principal.
* chore(deps): update dependency uuid to v11.1.1 [security] (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(init): use backend provider id "google" for Gemini (#359)
Selecting Gemini during `genlayer init` failed with:
Requested providers '{'geminiai'}' do not match any stored providers.
The selected provider id is forwarded verbatim to
sim_createRandomValidators, but the backend's llm_provider table stores
Gemini as "google". Rename the provider id geminiai -> google so it
matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are
unchanged.
Since "geminiai" never resolved to a valid provider, no working
configuration relied on it.
Fixes#271
Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com>
* fix(docs-sync): stop overwriting the generated root _meta.json (#352)
The sync-docs workflow rsynced the generated category-based
docs/api-references/_meta.json into genlayer-docs and then immediately
overwrote it with a hardcoded heredoc containing the pre-grouping flat
command list (init, up, deploy, ...). Those keys no longer match the
directory layout, so the genlayer-docs sidebar rendered broken entries
on every sync (fixed manually in genlayer-docs#426; this removes the
cause).
Also make the generated root meta complete:
- add "index": "Overview" for the generated index.mdx
- append ungrouped top-level commands (estimate-fees, finalize,
finalize-batch) so they get explicit nav entries instead of relying
on Nextra's implicit append
Snapshot under docs/api-references regenerated against current main
(picks up the new estimate-fees command and latest help text).
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* fix: drop getSlashingAddress from validator-history (#361)
getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev),
causing `genlayer staking validator-history` to crash with
`client.getSlashingAddress is not a function` before any history is fetched.
Resolve the idleness (slashing) contract address dynamically via viem
readContract against consensusMainContract.getIdlenessAddress(), falling
back to the staking contract address if resolution fails so reward events
still display.
Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev.
Supersedes #344.
Fixes#341
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* feat(network): custom network profiles with deployment-file import (#362)
* feat(network): custom network profiles with deployment-file import
genlayer network add <alias> --base <built-in> [--deployment <json>]
[--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager
|--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>]
Profiles persist as base + address overrides only; resolveNetwork loads
the base chain fresh from genlayer-js and applies overrides, so ABIs
never go stale. network set/list/info/remove and StakingAction --network
accept custom aliases. The consensus deployments.json shape is parsed by
walking the tree for ContractName->address leaves (ConsensusMain,
ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage,
Appeals); flags take precedence over the file. Adds a prepare script so
npm install from a git ref builds dist. Verified: 576 vitest tests, full
manual smoke (add/list/set/info/remove with a deployment file).
* chore(deps): bump genlayer-js to v2-dev tip for vesting actions
The locked v2-dev SHA (28e99fbc) predates the vesting client actions;
vestingValidatorJoin and friends land at 666d1156. Verified live:
vesting validator create succeeds against a #1162-branch consensus
deployment.
* docs(cli): regenerate API references; fix option placeholder regex
The docs generator's option regex only matched <word> placeholders, so
flags with dots or hyphens in the value name (--base <built-in-alias>,
--deployment <path.json>, --deployment-key <dot.path>) were silently
dropped from the options tables. Widen to <[^>]+> and regenerate: adds
the network add/remove pages and the previously undocumented vesting
command section (validator create/deposit/exit/claim, operator-transfer,
set-identity, delegate/undelegate/claim/withdraw/list).
* fix(vesting): resolve validator wallet address in create output
The join receipt does not carry the new wallet address, so the output
printed validatorWallet: undefined. Read getValidatorWallets from the
vesting contract after the join and report the newest entry. Verified
live against a #1162-branch deployment.
* fix: make git install build lifecycle robust (#363)
* fix: make git install build script self contained
* chore: refresh genlayer-js lockfile
* fix: make keychain dependency optional
* fix: restore git prepare build
* fix: include build dependency for git installs
* chore: keep esbuild as dev dependency
* ci: publish prereleases to npm dist tags (#364)
* ci: add clarke cli tarball release
* ci: publish prereleases to npm dist tags
* Release v0.40.0-rc1 [skip ci]
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com>
Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com>
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MuncleUscles
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): update dependency uuid to v11.1.1 [security] - #320

Merged
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability
Jul 7, 2026
Merged

chore(deps): update dependency uuid to v11.1.1 [security]#320
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability

Conversation

@renovate

@renovaterenovateBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
uuid11.1.011.1.1ageconfidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

CVE-2026-41907 / GHSA-w5hq-g745-h8pq

More information

Details

Summary

The v3(), v5(), and v6()API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4(), v1(), and v7() API methods explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3()/v5() path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "import {v4,v5,v6} from './dist-node/index.js';const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)],]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); }}"

Observed:

  • v4() THREW RangeError
  • v5() NO_THROW
  • v6() NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
170, 170, 170, 170,
75, 224, 100, 63
]
v6 [
187, 187, 187, 187,
31, 19, 185, 64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4()/v1()/v7():

if(offset<0||offset+16>buf.length){thrownewRangeError(`UUID byte range ${offset}:${offset+15} is out of buffer bounds`);}

Apply to:

  • src/v35.ts (covers v3() and v5())
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v11.1.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch 2 times, most recently from b681dae to 7fe547cCompareMay 28, 2026 21:02
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7fe547c to 7677f37CompareJune 10, 2026 14:57
@renovate
renovateBot changed the base branch from v0.39 to mainJune 10, 2026 14:57
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJune 10, 2026 14:57
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

2 similar comments
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security]chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedJul 1, 2026
@renovaterenovateBot closed this Jul 1, 2026
@renovate
renovateBot deleted the renovate/npm-uuid-vulnerability branch July 1, 2026 01:05
@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedchore(deps): update dependency uuid to v11.1.1 [security]Jul 1, 2026
@renovaterenovateBot reopened this Jul 1, 2026
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 33fa729 to 7677f37CompareJuly 1, 2026 21:30
@renovate
renovateBot changed the base branch from v0.40-dev to mainJuly 1, 2026 21:30
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7677f37 to 33fa729CompareJuly 1, 2026 21:30
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

1 similar comment
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@MuncleUscles
MuncleUscles merged commit 45a3ce9 into v0.40-devJul 7, 2026
20 of 21 checks passed
MuncleUscles added a commit that referenced this pull request Jul 8, 2026
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350)
Propagates #349 to v0.40-dev.
* docs: add branching guide (#353)
* docs: add branching guide
* ci: harden testnet smoke timeout
* feat: support fee profiles in contract commands (#355)
* feat: support fee profiles in contract commands
* test: make fee profile deploy test portable
* feat: staking validators discovery (#357)
* feat: add staking validators discovery
* feat: epoch-aware validator listing with below-min indicator
* fix(staking): account-less client for read-only staking queries
getReadOnlyStakingClient threw 'Account not found' on fresh installs;
listings and other reads don't need a local account.
* feat: vesting commands (#358)
* feat: add vesting commands
* feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status
Drives the CON-607 Vesting.sol validator leg through the SDK's named
vestingValidator* actions; list/status enumerate getValidatorWallets
with per-wallet deposited principal.
* chore(deps): update dependency uuid to v11.1.1 [security] (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(init): use backend provider id "google" for Gemini (#359)
Selecting Gemini during `genlayer init` failed with:
Requested providers '{'geminiai'}' do not match any stored providers.
The selected provider id is forwarded verbatim to
sim_createRandomValidators, but the backend's llm_provider table stores
Gemini as "google". Rename the provider id geminiai -> google so it
matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are
unchanged.
Since "geminiai" never resolved to a valid provider, no working
configuration relied on it.
Fixes#271
Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com>
* fix(docs-sync): stop overwriting the generated root _meta.json (#352)
The sync-docs workflow rsynced the generated category-based
docs/api-references/_meta.json into genlayer-docs and then immediately
overwrote it with a hardcoded heredoc containing the pre-grouping flat
command list (init, up, deploy, ...). Those keys no longer match the
directory layout, so the genlayer-docs sidebar rendered broken entries
on every sync (fixed manually in genlayer-docs#426; this removes the
cause).
Also make the generated root meta complete:
- add "index": "Overview" for the generated index.mdx
- append ungrouped top-level commands (estimate-fees, finalize,
finalize-batch) so they get explicit nav entries instead of relying
on Nextra's implicit append
Snapshot under docs/api-references regenerated against current main
(picks up the new estimate-fees command and latest help text).
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* fix: drop getSlashingAddress from validator-history (#361)
getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev),
causing `genlayer staking validator-history` to crash with
`client.getSlashingAddress is not a function` before any history is fetched.
Resolve the idleness (slashing) contract address dynamically via viem
readContract against consensusMainContract.getIdlenessAddress(), falling
back to the staking contract address if resolution fails so reward events
still display.
Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev.
Supersedes #344.
Fixes#341
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* feat(network): custom network profiles with deployment-file import (#362)
* feat(network): custom network profiles with deployment-file import
genlayer network add <alias> --base <built-in> [--deployment <json>]
[--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager
|--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>]
Profiles persist as base + address overrides only; resolveNetwork loads
the base chain fresh from genlayer-js and applies overrides, so ABIs
never go stale. network set/list/info/remove and StakingAction --network
accept custom aliases. The consensus deployments.json shape is parsed by
walking the tree for ContractName->address leaves (ConsensusMain,
ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage,
Appeals); flags take precedence over the file. Adds a prepare script so
npm install from a git ref builds dist. Verified: 576 vitest tests, full
manual smoke (add/list/set/info/remove with a deployment file).
* chore(deps): bump genlayer-js to v2-dev tip for vesting actions
The locked v2-dev SHA (28e99fbc) predates the vesting client actions;
vestingValidatorJoin and friends land at 666d1156. Verified live:
vesting validator create succeeds against a #1162-branch consensus
deployment.
* docs(cli): regenerate API references; fix option placeholder regex
The docs generator's option regex only matched <word> placeholders, so
flags with dots or hyphens in the value name (--base <built-in-alias>,
--deployment <path.json>, --deployment-key <dot.path>) were silently
dropped from the options tables. Widen to <[^>]+> and regenerate: adds
the network add/remove pages and the previously undocumented vesting
command section (validator create/deposit/exit/claim, operator-transfer,
set-identity, delegate/undelegate/claim/withdraw/list).
* fix(vesting): resolve validator wallet address in create output
The join receipt does not carry the new wallet address, so the output
printed validatorWallet: undefined. Read getValidatorWallets from the
vesting contract after the join and report the newest entry. Verified
live against a #1162-branch deployment.
* fix: make git install build lifecycle robust (#363)
* fix: make git install build script self contained
* chore: refresh genlayer-js lockfile
* fix: make keychain dependency optional
* fix: restore git prepare build
* fix: include build dependency for git installs
* chore: keep esbuild as dev dependency
* ci: publish prereleases to npm dist tags (#364)
* ci: add clarke cli tarball release
* ci: publish prereleases to npm dist tags
* Release v0.40.0-rc1 [skip ci]
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com>
Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com>
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MuncleUscles
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

chore(deps): update dependency uuid to v11.1.1 [security] - #320

Merged
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability
Jul 7, 2026
Merged

chore(deps): update dependency uuid to v11.1.1 [security]#320
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability

Conversation

@renovate

@renovaterenovateBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
uuid11.1.011.1.1ageconfidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

CVE-2026-41907 / GHSA-w5hq-g745-h8pq

More information

Details

Summary

The v3(), v5(), and v6()API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4(), v1(), and v7() API methods explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3()/v5() path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "import {v4,v5,v6} from './dist-node/index.js';const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)],]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); }}"

Observed:

  • v4() THREW RangeError
  • v5() NO_THROW
  • v6() NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
170, 170, 170, 170,
75, 224, 100, 63
]
v6 [
187, 187, 187, 187,
31, 19, 185, 64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4()/v1()/v7():

if(offset<0||offset+16>buf.length){thrownewRangeError(`UUID byte range ${offset}:${offset+15} is out of buffer bounds`);}

Apply to:

  • src/v35.ts (covers v3() and v5())
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v11.1.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch 2 times, most recently from b681dae to 7fe547cCompareMay 28, 2026 21:02
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7fe547c to 7677f37CompareJune 10, 2026 14:57
@renovate
renovateBot changed the base branch from v0.39 to mainJune 10, 2026 14:57
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJune 10, 2026 14:57
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

2 similar comments
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security]chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedJul 1, 2026
@renovaterenovateBot closed this Jul 1, 2026
@renovate
renovateBot deleted the renovate/npm-uuid-vulnerability branch July 1, 2026 01:05
@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedchore(deps): update dependency uuid to v11.1.1 [security]Jul 1, 2026
@renovaterenovateBot reopened this Jul 1, 2026
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 33fa729 to 7677f37CompareJuly 1, 2026 21:30
@renovate
renovateBot changed the base branch from v0.40-dev to mainJuly 1, 2026 21:30
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7677f37 to 33fa729CompareJuly 1, 2026 21:30
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

1 similar comment
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@MuncleUscles
MuncleUscles merged commit 45a3ce9 into v0.40-devJul 7, 2026
20 of 21 checks passed
MuncleUscles added a commit that referenced this pull request Jul 8, 2026
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350)
Propagates #349 to v0.40-dev.
* docs: add branching guide (#353)
* docs: add branching guide
* ci: harden testnet smoke timeout
* feat: support fee profiles in contract commands (#355)
* feat: support fee profiles in contract commands
* test: make fee profile deploy test portable
* feat: staking validators discovery (#357)
* feat: add staking validators discovery
* feat: epoch-aware validator listing with below-min indicator
* fix(staking): account-less client for read-only staking queries
getReadOnlyStakingClient threw 'Account not found' on fresh installs;
listings and other reads don't need a local account.
* feat: vesting commands (#358)
* feat: add vesting commands
* feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status
Drives the CON-607 Vesting.sol validator leg through the SDK's named
vestingValidator* actions; list/status enumerate getValidatorWallets
with per-wallet deposited principal.
* chore(deps): update dependency uuid to v11.1.1 [security] (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(init): use backend provider id "google" for Gemini (#359)
Selecting Gemini during `genlayer init` failed with:
Requested providers '{'geminiai'}' do not match any stored providers.
The selected provider id is forwarded verbatim to
sim_createRandomValidators, but the backend's llm_provider table stores
Gemini as "google". Rename the provider id geminiai -> google so it
matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are
unchanged.
Since "geminiai" never resolved to a valid provider, no working
configuration relied on it.
Fixes#271
Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com>
* fix(docs-sync): stop overwriting the generated root _meta.json (#352)
The sync-docs workflow rsynced the generated category-based
docs/api-references/_meta.json into genlayer-docs and then immediately
overwrote it with a hardcoded heredoc containing the pre-grouping flat
command list (init, up, deploy, ...). Those keys no longer match the
directory layout, so the genlayer-docs sidebar rendered broken entries
on every sync (fixed manually in genlayer-docs#426; this removes the
cause).
Also make the generated root meta complete:
- add "index": "Overview" for the generated index.mdx
- append ungrouped top-level commands (estimate-fees, finalize,
finalize-batch) so they get explicit nav entries instead of relying
on Nextra's implicit append
Snapshot under docs/api-references regenerated against current main
(picks up the new estimate-fees command and latest help text).
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* fix: drop getSlashingAddress from validator-history (#361)
getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev),
causing `genlayer staking validator-history` to crash with
`client.getSlashingAddress is not a function` before any history is fetched.
Resolve the idleness (slashing) contract address dynamically via viem
readContract against consensusMainContract.getIdlenessAddress(), falling
back to the staking contract address if resolution fails so reward events
still display.
Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev.
Supersedes #344.
Fixes#341
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* feat(network): custom network profiles with deployment-file import (#362)
* feat(network): custom network profiles with deployment-file import
genlayer network add <alias> --base <built-in> [--deployment <json>]
[--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager
|--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>]
Profiles persist as base + address overrides only; resolveNetwork loads
the base chain fresh from genlayer-js and applies overrides, so ABIs
never go stale. network set/list/info/remove and StakingAction --network
accept custom aliases. The consensus deployments.json shape is parsed by
walking the tree for ContractName->address leaves (ConsensusMain,
ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage,
Appeals); flags take precedence over the file. Adds a prepare script so
npm install from a git ref builds dist. Verified: 576 vitest tests, full
manual smoke (add/list/set/info/remove with a deployment file).
* chore(deps): bump genlayer-js to v2-dev tip for vesting actions
The locked v2-dev SHA (28e99fbc) predates the vesting client actions;
vestingValidatorJoin and friends land at 666d1156. Verified live:
vesting validator create succeeds against a #1162-branch consensus
deployment.
* docs(cli): regenerate API references; fix option placeholder regex
The docs generator's option regex only matched <word> placeholders, so
flags with dots or hyphens in the value name (--base <built-in-alias>,
--deployment <path.json>, --deployment-key <dot.path>) were silently
dropped from the options tables. Widen to <[^>]+> and regenerate: adds
the network add/remove pages and the previously undocumented vesting
command section (validator create/deposit/exit/claim, operator-transfer,
set-identity, delegate/undelegate/claim/withdraw/list).
* fix(vesting): resolve validator wallet address in create output
The join receipt does not carry the new wallet address, so the output
printed validatorWallet: undefined. Read getValidatorWallets from the
vesting contract after the join and report the newest entry. Verified
live against a #1162-branch deployment.
* fix: make git install build lifecycle robust (#363)
* fix: make git install build script self contained
* chore: refresh genlayer-js lockfile
* fix: make keychain dependency optional
* fix: restore git prepare build
* fix: include build dependency for git installs
* chore: keep esbuild as dev dependency
* ci: publish prereleases to npm dist tags (#364)
* ci: add clarke cli tarball release
* ci: publish prereleases to npm dist tags
* Release v0.40.0-rc1 [skip ci]
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com>
Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com>
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MuncleUscles
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): update dependency uuid to v11.1.1 [security] - #320

Merged
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability
Jul 7, 2026
Merged

chore(deps): update dependency uuid to v11.1.1 [security]#320
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability

Conversation

@renovate

@renovaterenovateBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
uuid11.1.011.1.1ageconfidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

CVE-2026-41907 / GHSA-w5hq-g745-h8pq

More information

Details

Summary

The v3(), v5(), and v6()API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4(), v1(), and v7() API methods explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3()/v5() path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "import {v4,v5,v6} from './dist-node/index.js';const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)],]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); }}"

Observed:

  • v4() THREW RangeError
  • v5() NO_THROW
  • v6() NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
170, 170, 170, 170,
75, 224, 100, 63
]
v6 [
187, 187, 187, 187,
31, 19, 185, 64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4()/v1()/v7():

if(offset<0||offset+16>buf.length){thrownewRangeError(`UUID byte range ${offset}:${offset+15} is out of buffer bounds`);}

Apply to:

  • src/v35.ts (covers v3() and v5())
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v11.1.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch 2 times, most recently from b681dae to 7fe547cCompareMay 28, 2026 21:02
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7fe547c to 7677f37CompareJune 10, 2026 14:57
@renovate
renovateBot changed the base branch from v0.39 to mainJune 10, 2026 14:57
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJune 10, 2026 14:57
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

2 similar comments
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security]chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedJul 1, 2026
@renovaterenovateBot closed this Jul 1, 2026
@renovate
renovateBot deleted the renovate/npm-uuid-vulnerability branch July 1, 2026 01:05
@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedchore(deps): update dependency uuid to v11.1.1 [security]Jul 1, 2026
@renovaterenovateBot reopened this Jul 1, 2026
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 33fa729 to 7677f37CompareJuly 1, 2026 21:30
@renovate
renovateBot changed the base branch from v0.40-dev to mainJuly 1, 2026 21:30
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7677f37 to 33fa729CompareJuly 1, 2026 21:30
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

1 similar comment
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@MuncleUscles
MuncleUscles merged commit 45a3ce9 into v0.40-devJul 7, 2026
20 of 21 checks passed
MuncleUscles added a commit that referenced this pull request Jul 8, 2026
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350)
Propagates #349 to v0.40-dev.
* docs: add branching guide (#353)
* docs: add branching guide
* ci: harden testnet smoke timeout
* feat: support fee profiles in contract commands (#355)
* feat: support fee profiles in contract commands
* test: make fee profile deploy test portable
* feat: staking validators discovery (#357)
* feat: add staking validators discovery
* feat: epoch-aware validator listing with below-min indicator
* fix(staking): account-less client for read-only staking queries
getReadOnlyStakingClient threw 'Account not found' on fresh installs;
listings and other reads don't need a local account.
* feat: vesting commands (#358)
* feat: add vesting commands
* feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status
Drives the CON-607 Vesting.sol validator leg through the SDK's named
vestingValidator* actions; list/status enumerate getValidatorWallets
with per-wallet deposited principal.
* chore(deps): update dependency uuid to v11.1.1 [security] (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(init): use backend provider id "google" for Gemini (#359)
Selecting Gemini during `genlayer init` failed with:
Requested providers '{'geminiai'}' do not match any stored providers.
The selected provider id is forwarded verbatim to
sim_createRandomValidators, but the backend's llm_provider table stores
Gemini as "google". Rename the provider id geminiai -> google so it
matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are
unchanged.
Since "geminiai" never resolved to a valid provider, no working
configuration relied on it.
Fixes#271
Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com>
* fix(docs-sync): stop overwriting the generated root _meta.json (#352)
The sync-docs workflow rsynced the generated category-based
docs/api-references/_meta.json into genlayer-docs and then immediately
overwrote it with a hardcoded heredoc containing the pre-grouping flat
command list (init, up, deploy, ...). Those keys no longer match the
directory layout, so the genlayer-docs sidebar rendered broken entries
on every sync (fixed manually in genlayer-docs#426; this removes the
cause).
Also make the generated root meta complete:
- add "index": "Overview" for the generated index.mdx
- append ungrouped top-level commands (estimate-fees, finalize,
finalize-batch) so they get explicit nav entries instead of relying
on Nextra's implicit append
Snapshot under docs/api-references regenerated against current main
(picks up the new estimate-fees command and latest help text).
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* fix: drop getSlashingAddress from validator-history (#361)
getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev),
causing `genlayer staking validator-history` to crash with
`client.getSlashingAddress is not a function` before any history is fetched.
Resolve the idleness (slashing) contract address dynamically via viem
readContract against consensusMainContract.getIdlenessAddress(), falling
back to the staking contract address if resolution fails so reward events
still display.
Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev.
Supersedes #344.
Fixes#341
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* feat(network): custom network profiles with deployment-file import (#362)
* feat(network): custom network profiles with deployment-file import
genlayer network add <alias> --base <built-in> [--deployment <json>]
[--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager
|--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>]
Profiles persist as base + address overrides only; resolveNetwork loads
the base chain fresh from genlayer-js and applies overrides, so ABIs
never go stale. network set/list/info/remove and StakingAction --network
accept custom aliases. The consensus deployments.json shape is parsed by
walking the tree for ContractName->address leaves (ConsensusMain,
ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage,
Appeals); flags take precedence over the file. Adds a prepare script so
npm install from a git ref builds dist. Verified: 576 vitest tests, full
manual smoke (add/list/set/info/remove with a deployment file).
* chore(deps): bump genlayer-js to v2-dev tip for vesting actions
The locked v2-dev SHA (28e99fbc) predates the vesting client actions;
vestingValidatorJoin and friends land at 666d1156. Verified live:
vesting validator create succeeds against a #1162-branch consensus
deployment.
* docs(cli): regenerate API references; fix option placeholder regex
The docs generator's option regex only matched <word> placeholders, so
flags with dots or hyphens in the value name (--base <built-in-alias>,
--deployment <path.json>, --deployment-key <dot.path>) were silently
dropped from the options tables. Widen to <[^>]+> and regenerate: adds
the network add/remove pages and the previously undocumented vesting
command section (validator create/deposit/exit/claim, operator-transfer,
set-identity, delegate/undelegate/claim/withdraw/list).
* fix(vesting): resolve validator wallet address in create output
The join receipt does not carry the new wallet address, so the output
printed validatorWallet: undefined. Read getValidatorWallets from the
vesting contract after the join and report the newest entry. Verified
live against a #1162-branch deployment.
* fix: make git install build lifecycle robust (#363)
* fix: make git install build script self contained
* chore: refresh genlayer-js lockfile
* fix: make keychain dependency optional
* fix: restore git prepare build
* fix: include build dependency for git installs
* chore: keep esbuild as dev dependency
* ci: publish prereleases to npm dist tags (#364)
* ci: add clarke cli tarball release
* ci: publish prereleases to npm dist tags
* Release v0.40.0-rc1 [skip ci]
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com>
Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com>
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MuncleUscles
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

chore(deps): update dependency uuid to v11.1.1 [security] - #320

Merged
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability
Jul 7, 2026
Merged

chore(deps): update dependency uuid to v11.1.1 [security]#320
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability

Conversation

@renovate

@renovaterenovateBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
uuid11.1.011.1.1ageconfidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

CVE-2026-41907 / GHSA-w5hq-g745-h8pq

More information

Details

Summary

The v3(), v5(), and v6()API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4(), v1(), and v7() API methods explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3()/v5() path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "import {v4,v5,v6} from './dist-node/index.js';const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)],]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); }}"

Observed:

  • v4() THREW RangeError
  • v5() NO_THROW
  • v6() NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
170, 170, 170, 170,
75, 224, 100, 63
]
v6 [
187, 187, 187, 187,
31, 19, 185, 64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4()/v1()/v7():

if(offset<0||offset+16>buf.length){thrownewRangeError(`UUID byte range ${offset}:${offset+15} is out of buffer bounds`);}

Apply to:

  • src/v35.ts (covers v3() and v5())
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v11.1.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch 2 times, most recently from b681dae to 7fe547cCompareMay 28, 2026 21:02
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7fe547c to 7677f37CompareJune 10, 2026 14:57
@renovate
renovateBot changed the base branch from v0.39 to mainJune 10, 2026 14:57
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJune 10, 2026 14:57
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

2 similar comments
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security]chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedJul 1, 2026
@renovaterenovateBot closed this Jul 1, 2026
@renovate
renovateBot deleted the renovate/npm-uuid-vulnerability branch July 1, 2026 01:05
@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedchore(deps): update dependency uuid to v11.1.1 [security]Jul 1, 2026
@renovaterenovateBot reopened this Jul 1, 2026
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 33fa729 to 7677f37CompareJuly 1, 2026 21:30
@renovate
renovateBot changed the base branch from v0.40-dev to mainJuly 1, 2026 21:30
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7677f37 to 33fa729CompareJuly 1, 2026 21:30
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

1 similar comment
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@MuncleUscles
MuncleUscles merged commit 45a3ce9 into v0.40-devJul 7, 2026
20 of 21 checks passed
MuncleUscles added a commit that referenced this pull request Jul 8, 2026
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350)
Propagates #349 to v0.40-dev.
* docs: add branching guide (#353)
* docs: add branching guide
* ci: harden testnet smoke timeout
* feat: support fee profiles in contract commands (#355)
* feat: support fee profiles in contract commands
* test: make fee profile deploy test portable
* feat: staking validators discovery (#357)
* feat: add staking validators discovery
* feat: epoch-aware validator listing with below-min indicator
* fix(staking): account-less client for read-only staking queries
getReadOnlyStakingClient threw 'Account not found' on fresh installs;
listings and other reads don't need a local account.
* feat: vesting commands (#358)
* feat: add vesting commands
* feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status
Drives the CON-607 Vesting.sol validator leg through the SDK's named
vestingValidator* actions; list/status enumerate getValidatorWallets
with per-wallet deposited principal.
* chore(deps): update dependency uuid to v11.1.1 [security] (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(init): use backend provider id "google" for Gemini (#359)
Selecting Gemini during `genlayer init` failed with:
Requested providers '{'geminiai'}' do not match any stored providers.
The selected provider id is forwarded verbatim to
sim_createRandomValidators, but the backend's llm_provider table stores
Gemini as "google". Rename the provider id geminiai -> google so it
matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are
unchanged.
Since "geminiai" never resolved to a valid provider, no working
configuration relied on it.
Fixes#271
Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com>
* fix(docs-sync): stop overwriting the generated root _meta.json (#352)
The sync-docs workflow rsynced the generated category-based
docs/api-references/_meta.json into genlayer-docs and then immediately
overwrote it with a hardcoded heredoc containing the pre-grouping flat
command list (init, up, deploy, ...). Those keys no longer match the
directory layout, so the genlayer-docs sidebar rendered broken entries
on every sync (fixed manually in genlayer-docs#426; this removes the
cause).
Also make the generated root meta complete:
- add "index": "Overview" for the generated index.mdx
- append ungrouped top-level commands (estimate-fees, finalize,
finalize-batch) so they get explicit nav entries instead of relying
on Nextra's implicit append
Snapshot under docs/api-references regenerated against current main
(picks up the new estimate-fees command and latest help text).
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* fix: drop getSlashingAddress from validator-history (#361)
getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev),
causing `genlayer staking validator-history` to crash with
`client.getSlashingAddress is not a function` before any history is fetched.
Resolve the idleness (slashing) contract address dynamically via viem
readContract against consensusMainContract.getIdlenessAddress(), falling
back to the staking contract address if resolution fails so reward events
still display.
Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev.
Supersedes #344.
Fixes#341
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* feat(network): custom network profiles with deployment-file import (#362)
* feat(network): custom network profiles with deployment-file import
genlayer network add <alias> --base <built-in> [--deployment <json>]
[--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager
|--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>]
Profiles persist as base + address overrides only; resolveNetwork loads
the base chain fresh from genlayer-js and applies overrides, so ABIs
never go stale. network set/list/info/remove and StakingAction --network
accept custom aliases. The consensus deployments.json shape is parsed by
walking the tree for ContractName->address leaves (ConsensusMain,
ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage,
Appeals); flags take precedence over the file. Adds a prepare script so
npm install from a git ref builds dist. Verified: 576 vitest tests, full
manual smoke (add/list/set/info/remove with a deployment file).
* chore(deps): bump genlayer-js to v2-dev tip for vesting actions
The locked v2-dev SHA (28e99fbc) predates the vesting client actions;
vestingValidatorJoin and friends land at 666d1156. Verified live:
vesting validator create succeeds against a #1162-branch consensus
deployment.
* docs(cli): regenerate API references; fix option placeholder regex
The docs generator's option regex only matched <word> placeholders, so
flags with dots or hyphens in the value name (--base <built-in-alias>,
--deployment <path.json>, --deployment-key <dot.path>) were silently
dropped from the options tables. Widen to <[^>]+> and regenerate: adds
the network add/remove pages and the previously undocumented vesting
command section (validator create/deposit/exit/claim, operator-transfer,
set-identity, delegate/undelegate/claim/withdraw/list).
* fix(vesting): resolve validator wallet address in create output
The join receipt does not carry the new wallet address, so the output
printed validatorWallet: undefined. Read getValidatorWallets from the
vesting contract after the join and report the newest entry. Verified
live against a #1162-branch deployment.
* fix: make git install build lifecycle robust (#363)
* fix: make git install build script self contained
* chore: refresh genlayer-js lockfile
* fix: make keychain dependency optional
* fix: restore git prepare build
* fix: include build dependency for git installs
* chore: keep esbuild as dev dependency
* ci: publish prereleases to npm dist tags (#364)
* ci: add clarke cli tarball release
* ci: publish prereleases to npm dist tags
* Release v0.40.0-rc1 [skip ci]
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com>
Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com>
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MuncleUscles
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

chore(deps): update dependency uuid to v11.1.1 [security] - #320

Merged
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability
Jul 7, 2026
Merged

chore(deps): update dependency uuid to v11.1.1 [security]#320
MuncleUscles merged 1 commit into
v0.40-devfrom
renovate/npm-uuid-vulnerability

Conversation

@renovate

@renovaterenovateBot commented May 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

PackageChangeAgeConfidence
uuid11.1.011.1.1ageconfidence

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

CVE-2026-41907 / GHSA-w5hq-g745-h8pq

More information

Details

Summary

The v3(), v5(), and v6()API methods (not uuid release versions) accept external output buffers but do not reject out-of-range writes (small buf or large offset).
By contrast, v4(), v1(), and v7() API methods explicitly throw RangeError on invalid bounds.

This inconsistency allows silent partial writes into caller-provided buffers.

Affected code
  • src/v35.ts (v3()/v5() path) writes buf[offset + i] without bounds validation.
  • src/v6.ts writes buf[offset + i] without bounds validation.
Reproducible PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "import {v4,v5,v6} from './dist-node/index.js';const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';for (const [name,fn] of [ ['v4()',()=>v4({},new Uint8Array(8),4)], ['v5()',()=>v5('x',ns,new Uint8Array(8),4)], ['v6()',()=>v6({},new Uint8Array(8),4)],]) { try { fn(); console.log(name,'NO_THROW'); } catch(e){ console.log(name,'THREW',e.name); }}"

Observed:

  • v4() THREW RangeError
  • v5() NO_THROW
  • v6() NO_THROW

Example partial overwrite evidence captured during audit:

same true buf [
170, 170, 170, 170,
75, 224, 100, 63
]
v6 [
187, 187, 187, 187,
31, 19, 185, 64
]
Security impact
  • Primary: integrity/robustness issue (silent partial output).
  • If an application assumes full UUID writes into preallocated buffers, this can produce malformed/truncated/partially stale identifiers without error.
  • In systems where caller-controlled offsets/buffer sizes are exposed indirectly, this may become a security-relevant logic flaw.
Suggested fix

Add the same guard used by v4()/v1()/v7():

if(offset<0||offset+16>buf.length){thrownewRangeError(`UUID byte range ${offset}:${offset+15} is out of buffer bounds`);}

Apply to:

  • src/v35.ts (covers v3() and v5())
  • src/v6.ts

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

uuidjs/uuid (uuid)

v11.1.1

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch 2 times, most recently from b681dae to 7fe547cCompareMay 28, 2026 21:02
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7fe547c to 7677f37CompareJune 10, 2026 14:57
@renovate
renovateBot changed the base branch from v0.39 to mainJune 10, 2026 14:57
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJune 10, 2026 14:57
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

2 similar comments
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@renovate

renovateBot commented Jun 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️Warning: custom changes will be lost.

@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security]chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedJul 1, 2026
@renovaterenovateBot closed this Jul 1, 2026
@renovate
renovateBot deleted the renovate/npm-uuid-vulnerability branch July 1, 2026 01:05
@renovaterenovateBot changed the title chore(deps): update dependency uuid to v11.1.1 [security] - autoclosedchore(deps): update dependency uuid to v11.1.1 [security]Jul 1, 2026
@renovaterenovateBot reopened this Jul 1, 2026
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 33fa729 to 7677f37CompareJuly 1, 2026 21:30
@renovate
renovateBot changed the base branch from v0.40-dev to mainJuly 1, 2026 21:30
@renovate
renovateBotforce-pushed the renovate/npm-uuid-vulnerability branch from 7677f37 to 33fa729CompareJuly 1, 2026 21:30
@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

1 similar comment
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@github-actions
github-actionsBot changed the base branch from main to v0.40-devJuly 1, 2026 21:30
@github-actions

Copy link
Copy Markdown

This PR targeted main, which is only the default/static branch.

I retargeted it to v0.40-dev, the active development branch. Pushes to v0.40-dev automatically fast-forward main.

@MuncleUscles
MuncleUscles merged commit 45a3ce9 into v0.40-devJul 7, 2026
20 of 21 checks passed
MuncleUscles added a commit that referenced this pull request Jul 8, 2026
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350)
Propagates #349 to v0.40-dev.
* docs: add branching guide (#353)
* docs: add branching guide
* ci: harden testnet smoke timeout
* feat: support fee profiles in contract commands (#355)
* feat: support fee profiles in contract commands
* test: make fee profile deploy test portable
* feat: staking validators discovery (#357)
* feat: add staking validators discovery
* feat: epoch-aware validator listing with below-min indicator
* fix(staking): account-less client for read-only staking queries
getReadOnlyStakingClient threw 'Account not found' on fresh installs;
listings and other reads don't need a local account.
* feat: vesting commands (#358)
* feat: add vesting commands
* feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status
Drives the CON-607 Vesting.sol validator leg through the SDK's named
vestingValidator* actions; list/status enumerate getValidatorWallets
with per-wallet deposited principal.
* chore(deps): update dependency uuid to v11.1.1 [security] (#320)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
* fix(init): use backend provider id "google" for Gemini (#359)
Selecting Gemini during `genlayer init` failed with:
Requested providers '{'geminiai'}' do not match any stored providers.
The selected provider id is forwarded verbatim to
sim_createRandomValidators, but the backend's llm_provider table stores
Gemini as "google". Rename the provider id geminiai -> google so it
matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are
unchanged.
Since "geminiai" never resolved to a valid provider, no working
configuration relied on it.
Fixes#271
Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com>
* fix(docs-sync): stop overwriting the generated root _meta.json (#352)
The sync-docs workflow rsynced the generated category-based
docs/api-references/_meta.json into genlayer-docs and then immediately
overwrote it with a hardcoded heredoc containing the pre-grouping flat
command list (init, up, deploy, ...). Those keys no longer match the
directory layout, so the genlayer-docs sidebar rendered broken entries
on every sync (fixed manually in genlayer-docs#426; this removes the
cause).
Also make the generated root meta complete:
- add "index": "Overview" for the generated index.mdx
- append ungrouped top-level commands (estimate-fees, finalize,
finalize-batch) so they get explicit nav entries instead of relying
on Nextra's implicit append
Snapshot under docs/api-references regenerated against current main
(picks up the new estimate-fees command and latest help text).
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* fix: drop getSlashingAddress from validator-history (#361)
getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev),
causing `genlayer staking validator-history` to crash with
`client.getSlashingAddress is not a function` before any history is fetched.
Resolve the idleness (slashing) contract address dynamically via viem
readContract against consensusMainContract.getIdlenessAddress(), falling
back to the staking contract address if resolution fails so reward events
still display.
Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev.
Supersedes #344.
Fixes#341
Co-authored-by: Edgars <edgars@entropicsolutions.io>
* feat(network): custom network profiles with deployment-file import (#362)
* feat(network): custom network profiles with deployment-file import
genlayer network add <alias> --base <built-in> [--deployment <json>]
[--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager
|--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>]
Profiles persist as base + address overrides only; resolveNetwork loads
the base chain fresh from genlayer-js and applies overrides, so ABIs
never go stale. network set/list/info/remove and StakingAction --network
accept custom aliases. The consensus deployments.json shape is parsed by
walking the tree for ContractName->address leaves (ConsensusMain,
ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage,
Appeals); flags take precedence over the file. Adds a prepare script so
npm install from a git ref builds dist. Verified: 576 vitest tests, full
manual smoke (add/list/set/info/remove with a deployment file).
* chore(deps): bump genlayer-js to v2-dev tip for vesting actions
The locked v2-dev SHA (28e99fbc) predates the vesting client actions;
vestingValidatorJoin and friends land at 666d1156. Verified live:
vesting validator create succeeds against a #1162-branch consensus
deployment.
* docs(cli): regenerate API references; fix option placeholder regex
The docs generator's option regex only matched <word> placeholders, so
flags with dots or hyphens in the value name (--base <built-in-alias>,
--deployment <path.json>, --deployment-key <dot.path>) were silently
dropped from the options tables. Widen to <[^>]+> and regenerate: adds
the network add/remove pages and the previously undocumented vesting
command section (validator create/deposit/exit/claim, operator-transfer,
set-identity, delegate/undelegate/claim/withdraw/list).
* fix(vesting): resolve validator wallet address in create output
The join receipt does not carry the new wallet address, so the output
printed validatorWallet: undefined. Read getValidatorWallets from the
vesting contract after the join and report the newest entry. Verified
live against a #1162-branch deployment.
* fix: make git install build lifecycle robust (#363)
* fix: make git install build script self contained
* chore: refresh genlayer-js lockfile
* fix: make keychain dependency optional
* fix: restore git prepare build
* fix: include build dependency for git installs
* chore: keep esbuild as dev dependency
* ci: publish prereleases to npm dist tags (#364)
* ci: add clarke cli tarball release
* ci: publish prereleases to npm dist tags
* Release v0.40.0-rc1 [skip ci]
---------
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com>
Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com>
Co-authored-by: Albert Castellana <albert@genlayer.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Edgars <edgars@entropicsolutions.io>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@MuncleUscles