Uh oh!
There was an error while loading. Please reload this page.
chore(deps): update dependency uuid to v11.1.1 [security] - #320
Conversation
b681dae to
7fe547cCompare7fe547c to
7677f37CompareThis PR targeted I retargeted it to |
2 similar comments
This PR targeted I retargeted it to |
This PR targeted I retargeted it to |
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
33fa729 to
7677f37Compare7677f37 to
33fa729CompareThis PR targeted I retargeted it to |
1 similar comment
This PR targeted I retargeted it to |
This PR targeted I retargeted it to |
Uh oh!
There was an error while loading. Please reload this page.
* fix(system): propagate command-check and version parse fixes to v0.40-dev (#350) Propagates #349 to v0.40-dev. * docs: add branching guide (#353) * docs: add branching guide * ci: harden testnet smoke timeout * feat: support fee profiles in contract commands (#355) * feat: support fee profiles in contract commands * test: make fee profile deploy test portable * feat: staking validators discovery (#357) * feat: add staking validators discovery * feat: epoch-aware validator listing with below-min indicator * fix(staking): account-less client for read-only staking queries getReadOnlyStakingClient threw 'Account not found' on fresh installs; listings and other reads don't need a local account. * feat: vesting commands (#358) * feat: add vesting commands * feat(vesting): validator subcommands — create/join, deposit, exit, claim, operator-transfer, set-identity, list/status Drives the CON-607 Vesting.sol validator leg through the SDK's named vestingValidator* actions; list/status enumerate getValidatorWallets with per-wallet deposited principal. * chore(deps): update dependency uuid to v11.1.1 [security] (#320) Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> * fix(init): use backend provider id "google" for Gemini (#359) Selecting Gemini during `genlayer init` failed with: Requested providers '{'geminiai'}' do not match any stored providers. The selected provider id is forwarded verbatim to sim_createRandomValidators, but the backend's llm_provider table stores Gemini as "google". Rename the provider id geminiai -> google so it matches. Display name ("Gemini") and env var (GEMINI_API_KEY) are unchanged. Since "geminiai" never resolved to a valid provider, no working configuration relied on it. Fixes#271 Co-authored-by: Edgars Nemše <edgars@genlayerlabs.com> * fix(docs-sync): stop overwriting the generated root _meta.json (#352) The sync-docs workflow rsynced the generated category-based docs/api-references/_meta.json into genlayer-docs and then immediately overwrote it with a hardcoded heredoc containing the pre-grouping flat command list (init, up, deploy, ...). Those keys no longer match the directory layout, so the genlayer-docs sidebar rendered broken entries on every sync (fixed manually in genlayer-docs#426; this removes the cause). Also make the generated root meta complete: - add "index": "Overview" for the generated index.mdx - append ungrouped top-level commands (estimate-fees, finalize, finalize-batch) so they get explicit nav entries instead of relying on Nextra's implicit append Snapshot under docs/api-references regenerated against current main (picks up the new estimate-fees command and latest help text). Co-authored-by: Albert Castellana <albert@genlayer.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Edgars <edgars@entropicsolutions.io> * fix: drop getSlashingAddress from validator-history (#361) getSlashingAddress() was removed from the genlayer-js SDK (v0.39+/v2-dev), causing `genlayer staking validator-history` to crash with `client.getSlashingAddress is not a function` before any history is fetched. Resolve the idleness (slashing) contract address dynamically via viem readContract against consensusMainContract.getIdlenessAddress(), falling back to the staking contract address if resolution fails so reward events still display. Port of #344 (by @ygd58) from the dead v0.39 line to v0.40-dev. Supersedes #344. Fixes#341 Co-authored-by: Edgars <edgars@entropicsolutions.io> * feat(network): custom network profiles with deployment-file import (#362) * feat(network): custom network profiles with deployment-file import genlayer network add <alias> --base <built-in> [--deployment <json>] [--rpc <url>] [--consensus-main|--consensus-data|--staking|--fee-manager |--rounds-storage|--appeals <addr>] [--chain-id <n>] [--deployment-key <path>] Profiles persist as base + address overrides only; resolveNetwork loads the base chain fresh from genlayer-js and applies overrides, so ABIs never go stale. network set/list/info/remove and StakingAction --network accept custom aliases. The consensus deployments.json shape is parsed by walking the tree for ContractName->address leaves (ConsensusMain, ConsensusData, GenStaking/Staking, FeeManager, Rounds/RoundsStorage, Appeals); flags take precedence over the file. Adds a prepare script so npm install from a git ref builds dist. Verified: 576 vitest tests, full manual smoke (add/list/set/info/remove with a deployment file). * chore(deps): bump genlayer-js to v2-dev tip for vesting actions The locked v2-dev SHA (28e99fbc) predates the vesting client actions; vestingValidatorJoin and friends land at 666d1156. Verified live: vesting validator create succeeds against a #1162-branch consensus deployment. * docs(cli): regenerate API references; fix option placeholder regex The docs generator's option regex only matched <word> placeholders, so flags with dots or hyphens in the value name (--base <built-in-alias>, --deployment <path.json>, --deployment-key <dot.path>) were silently dropped from the options tables. Widen to <[^>]+> and regenerate: adds the network add/remove pages and the previously undocumented vesting command section (validator create/deposit/exit/claim, operator-transfer, set-identity, delegate/undelegate/claim/withdraw/list). * fix(vesting): resolve validator wallet address in create output The join receipt does not carry the new wallet address, so the output printed validatorWallet: undefined. Read getValidatorWallets from the vesting contract after the join and report the newest entry. Verified live against a #1162-branch deployment. * fix: make git install build lifecycle robust (#363) * fix: make git install build script self contained * chore: refresh genlayer-js lockfile * fix: make keychain dependency optional * fix: restore git prepare build * fix: include build dependency for git installs * chore: keep esbuild as dev dependency * ci: publish prereleases to npm dist tags (#364) * ci: add clarke cli tarball release * ci: publish prereleases to npm dist tags * Release v0.40.0-rc1 [skip ci] --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Tobu <36818942+Tobu8888@users.noreply.github.com> Co-authored-by: Albert Castellana <acastellana@users.noreply.github.com> Co-authored-by: Albert Castellana <albert@genlayer.com> Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Edgars <edgars@entropicsolutions.io>
This PR contains the following updates:
11.1.0→11.1.1uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided
CVE-2026-41907 / GHSA-w5hq-g745-h8pq
More information
Details
Summary
The
v3(),v5(), andv6()API methods (notuuidrelease versions) accept external output buffers but do not reject out-of-range writes (smallbufor largeoffset).By contrast,
v4(),v1(), andv7()API methods explicitly throwRangeErroron invalid bounds.This inconsistency allows silent partial writes into caller-provided buffers.
Affected code
src/v35.ts(v3()/v5()path) writesbuf[offset + i]without bounds validation.src/v6.tswritesbuf[offset + i]without bounds validation.Reproducible PoC
Observed:
v4() THREW RangeErrorv5() NO_THROWv6() NO_THROWExample partial overwrite evidence captured during audit:
Security impact
Suggested fix
Add the same guard used by
v4()/v1()/v7():Apply to:
src/v35.ts(coversv3()andv5())src/v6.tsSeverity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
uuidjs/uuid (uuid)
v11.1.1Compare Source
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.