Update stellar dependencies to protocol 27 - #2613

Merged
mootz12 merged 11 commits into
mainfrom
p27-update
Jun 17, 2026
Merged

Update stellar dependencies to protocol 27#2613
mootz12 merged 11 commits into
mainfrom
p27-update

Conversation

@mootz12

@mootz12mootz12 commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

What

Updates protocol dependencies to protocol 27, cleans up clippy warnings, and adds the ability to sign AddressV2 auth entries.

Known limitations

Support for signing with delegated signers does not exist at this time

TODO

  • Update rs-soroban-sdk packages once an RC release is available

@github-project-automationgithub-project-automationBot moved this to Backlog (Not Ready) in DevXJun 17, 2026
@mootz12
mootz12 requested a review from fnandoJune 17, 2026 02:15
@mootz12
mootz12 marked this pull request as ready for review June 17, 2026 15:16
@mootz12
mootz12 requested a review from a team as a code ownerJune 17, 2026 15:16
CopilotAI review requested due to automatic review settings June 17, 2026 15:16
@socket-security

socket-securityBot commented Jun 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?cargo/bollard@0.20.2cargo/testcontainers@0.27.2cargo/sep5@0.1.0cargo/tokio@1.52.3cargo/stellar-xdr@27.0.0cargo/soroban-sdk@27.0.0-rc.1cargo/soroban-ledger-snapshot@27.0.0-rc.1cargo/sha2@0.10.9cargo/sha2@0.9.9cargo/which@4.4.2cargo/ulid@1.2.1cargo/directories@5.0.1cargo/mockito@1.7.0cargo/whoami@1.6.1cargo/reqwest@0.12.23cargo/httpmock@0.7.0cargo/ledger-transport-hid@0.10.0cargo/wasm-opt@0.116.1cargo/tempfile@3.21.0cargo/open@5.3.2cargo/rpassword@7.4.0cargo/keyring@3.6.3cargo/serial_test@3.2.0cargo/assert_cmd@2.0.17cargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates stellar-cli’s Rust workspace to Protocol 27-compatible dependencies (notably stellar-xdr / Soroban crates), adjusts code to the new stellar_xdr API surface (removing curr usage), and extends the signer to support signing AddressV2 Soroban auth entries using the correct CAP-0071-02 payload preimage.

Changes:

  • Bump workspace protocol dependencies to v27 (including stellar-xdr = 27.0.0, soroban-env-host = 27.0.0, and soroban-* = 27.0.0-rc.1) and update the lockfile accordingly.
  • Replace stellar_xdr::curr::* imports/usages with top-level stellar_xdr::* and update CLI encode/decode helpers to the new stellar_xdr::cli API.
  • Add AddressV2 signing support by hashing the SorobanAuthorizationWithAddress preimage, plus unit tests ensuring the AddressV2 variant is preserved and produces distinct signatures from V1.

Reviewed changes

Copilot reviewed 41 out of 42 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
cmd/soroban-cli/src/wasm.rsSwitch XDR imports from curr to top-level stellar_xdr.
cmd/soroban-cli/src/utils.rsUpdate XDR imports and tests to use top-level stellar_xdr types.
cmd/soroban-cli/src/signer/validation.rsUpdate contract ID construction for non-curr XDR types in tests.
cmd/soroban-cli/src/signer/mod.rsAdd AddressV2 auth signing using SorobanAuthorizationWithAddress preimage + new tests; update contract ID pattern matching.
cmd/soroban-cli/src/log/auth.rsFormat auth entries for AddressV2 and AddressWithDelegates; minor iterator/clippy cleanups; update contract ID formatting match.
cmd/soroban-cli/src/lib.rsRe-export stellar_xdr directly as xdr (removing curr re-export).
cmd/soroban-cli/src/key.rsUpdate contract address construction to non-curr XDR types.
cmd/soroban-cli/src/config/sc_address.rsUpdate ScAddress::Contract construction to non-curr XDR types.
cmd/soroban-cli/src/commands/version.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/tx/xdr.rsUpdate Limited/error types to non-curr XDR.
cmd/soroban-cli/src/commands/tx/update/sequence_number/next.rsUpdate MuxedAccount import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/send.rsUpdate XDR error type to stellar_xdr::Error and remove curr import.
cmd/soroban-cli/src/commands/tx/encode.rsUpdate stellar_xdr::cli::encode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/tx/edit.rsUpdate XDR read/write trait bounds and envelope types to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/decode.rsUpdate stellar_xdr::cli::decode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/snapshot/merge.rsUpdate snapshot merge key/value types to non-curr XDR types.
cmd/soroban-cli/src/commands/snapshot/create.rsSwitch broad XDR imports and contract address creation off curr.
cmd/soroban-cli/src/commands/network/settings.rsUpdate XDR imports and error types to non-curr.
cmd/soroban-cli/src/commands/ledger/entry/fetch/contract_data.rsUpdate XDR error type to stellar_xdr::Error.
cmd/soroban-cli/src/commands/doctor.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/contract/info/shared.rsUpdate ContractId import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/meta.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/build.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/deploy/asset.rsUpdate contract address creation to non-curr XDR types.
cmd/soroban-cli/src/commands/contract/build.rsUpdate XDR imports/error types and spec entry typing to non-curr.
cmd/soroban-cli/src/commands/contract/arg_parsing.rsUpdate many spec/XDR type imports/usages to non-curr and clean up iterator style.
cmd/soroban-cli/src/assembled.rsUpdate broad XDR imports and contract ID construction to non-curr.
cmd/crates/stellar-ledger/tests/test/emulator_tests.rsUpdate test XDR imports to non-curr.
cmd/crates/stellar-ledger/src/lib.rsUpdate crate XDR imports to non-curr.
cmd/crates/stellar-ledger/src/emulator_test_support/util.rsUpdate Hash import to non-curr.
cmd/crates/stellar-ledger/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-typescript/src/types.rsUpdate spec/XDR imports to non-curr.
cmd/crates/soroban-spec-typescript/src/lib.rsUpdate spec/XDR imports and error typing to non-curr.
cmd/crates/soroban-spec-typescript/src/boilerplate.rsImprove ignored-test messages and adjust directory-compare helper logic.
cmd/crates/soroban-spec-typescript/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-tools/src/verify.rsUpdate spec/XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/src/lib.rsUpdate broad XDR imports to non-curr and adjust remaining curr-scoped enums.
cmd/crates/soroban-spec-tools/src/event.rsUpdate XDR imports to non-curr.
cmd/crates/soroban-spec-tools/src/contract.rsUpdate XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/Cargo.tomlDrop stellar-xdr feature curr from this crate.
Cargo.tomlBump workspace protocol dependency versions to v27 / v27 RCs and add soroban-env-host v27.
Cargo.lockRefresh lockfile for the new dependency set.

Comment threadcmd/crates/soroban-spec-typescript/src/boilerplate.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:8a70c15cc7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment threadcmd/soroban-cli/src/signer/mod.rs Outdated
Comment threadcmd/soroban-cli/src/signer/mod.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:46e035db10

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread.github/workflows/bindings-ts.yml
@mootz12
mootz12 merged commit 6ceb032 into mainJun 17, 2026
227 checks passed
@mootz12
mootz12 deleted the p27-update branch June 17, 2026 20:29
@github-project-automationgithub-project-automationBot moved this from Backlog (Not Ready) to Done in DevXJun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants

@mootz12@fnando
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Update stellar dependencies to protocol 27 - #2613

Merged
mootz12 merged 11 commits into
mainfrom
p27-update
Jun 17, 2026
Merged

Update stellar dependencies to protocol 27#2613
mootz12 merged 11 commits into
mainfrom
p27-update

Conversation

@mootz12

@mootz12mootz12 commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

What

Updates protocol dependencies to protocol 27, cleans up clippy warnings, and adds the ability to sign AddressV2 auth entries.

Known limitations

Support for signing with delegated signers does not exist at this time

TODO

  • Update rs-soroban-sdk packages once an RC release is available

@github-project-automationgithub-project-automationBot moved this to Backlog (Not Ready) in DevXJun 17, 2026
@mootz12
mootz12 requested a review from fnandoJune 17, 2026 02:15
@mootz12
mootz12 marked this pull request as ready for review June 17, 2026 15:16
@mootz12
mootz12 requested a review from a team as a code ownerJune 17, 2026 15:16
CopilotAI review requested due to automatic review settings June 17, 2026 15:16
@socket-security

socket-securityBot commented Jun 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?cargo/bollard@0.20.2cargo/testcontainers@0.27.2cargo/sep5@0.1.0cargo/tokio@1.52.3cargo/stellar-xdr@27.0.0cargo/soroban-sdk@27.0.0-rc.1cargo/soroban-ledger-snapshot@27.0.0-rc.1cargo/sha2@0.10.9cargo/sha2@0.9.9cargo/which@4.4.2cargo/ulid@1.2.1cargo/directories@5.0.1cargo/mockito@1.7.0cargo/whoami@1.6.1cargo/reqwest@0.12.23cargo/httpmock@0.7.0cargo/ledger-transport-hid@0.10.0cargo/wasm-opt@0.116.1cargo/tempfile@3.21.0cargo/open@5.3.2cargo/rpassword@7.4.0cargo/keyring@3.6.3cargo/serial_test@3.2.0cargo/assert_cmd@2.0.17cargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates stellar-cli’s Rust workspace to Protocol 27-compatible dependencies (notably stellar-xdr / Soroban crates), adjusts code to the new stellar_xdr API surface (removing curr usage), and extends the signer to support signing AddressV2 Soroban auth entries using the correct CAP-0071-02 payload preimage.

Changes:

  • Bump workspace protocol dependencies to v27 (including stellar-xdr = 27.0.0, soroban-env-host = 27.0.0, and soroban-* = 27.0.0-rc.1) and update the lockfile accordingly.
  • Replace stellar_xdr::curr::* imports/usages with top-level stellar_xdr::* and update CLI encode/decode helpers to the new stellar_xdr::cli API.
  • Add AddressV2 signing support by hashing the SorobanAuthorizationWithAddress preimage, plus unit tests ensuring the AddressV2 variant is preserved and produces distinct signatures from V1.

Reviewed changes

Copilot reviewed 41 out of 42 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
cmd/soroban-cli/src/wasm.rsSwitch XDR imports from curr to top-level stellar_xdr.
cmd/soroban-cli/src/utils.rsUpdate XDR imports and tests to use top-level stellar_xdr types.
cmd/soroban-cli/src/signer/validation.rsUpdate contract ID construction for non-curr XDR types in tests.
cmd/soroban-cli/src/signer/mod.rsAdd AddressV2 auth signing using SorobanAuthorizationWithAddress preimage + new tests; update contract ID pattern matching.
cmd/soroban-cli/src/log/auth.rsFormat auth entries for AddressV2 and AddressWithDelegates; minor iterator/clippy cleanups; update contract ID formatting match.
cmd/soroban-cli/src/lib.rsRe-export stellar_xdr directly as xdr (removing curr re-export).
cmd/soroban-cli/src/key.rsUpdate contract address construction to non-curr XDR types.
cmd/soroban-cli/src/config/sc_address.rsUpdate ScAddress::Contract construction to non-curr XDR types.
cmd/soroban-cli/src/commands/version.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/tx/xdr.rsUpdate Limited/error types to non-curr XDR.
cmd/soroban-cli/src/commands/tx/update/sequence_number/next.rsUpdate MuxedAccount import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/send.rsUpdate XDR error type to stellar_xdr::Error and remove curr import.
cmd/soroban-cli/src/commands/tx/encode.rsUpdate stellar_xdr::cli::encode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/tx/edit.rsUpdate XDR read/write trait bounds and envelope types to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/decode.rsUpdate stellar_xdr::cli::decode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/snapshot/merge.rsUpdate snapshot merge key/value types to non-curr XDR types.
cmd/soroban-cli/src/commands/snapshot/create.rsSwitch broad XDR imports and contract address creation off curr.
cmd/soroban-cli/src/commands/network/settings.rsUpdate XDR imports and error types to non-curr.
cmd/soroban-cli/src/commands/ledger/entry/fetch/contract_data.rsUpdate XDR error type to stellar_xdr::Error.
cmd/soroban-cli/src/commands/doctor.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/contract/info/shared.rsUpdate ContractId import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/meta.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/build.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/deploy/asset.rsUpdate contract address creation to non-curr XDR types.
cmd/soroban-cli/src/commands/contract/build.rsUpdate XDR imports/error types and spec entry typing to non-curr.
cmd/soroban-cli/src/commands/contract/arg_parsing.rsUpdate many spec/XDR type imports/usages to non-curr and clean up iterator style.
cmd/soroban-cli/src/assembled.rsUpdate broad XDR imports and contract ID construction to non-curr.
cmd/crates/stellar-ledger/tests/test/emulator_tests.rsUpdate test XDR imports to non-curr.
cmd/crates/stellar-ledger/src/lib.rsUpdate crate XDR imports to non-curr.
cmd/crates/stellar-ledger/src/emulator_test_support/util.rsUpdate Hash import to non-curr.
cmd/crates/stellar-ledger/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-typescript/src/types.rsUpdate spec/XDR imports to non-curr.
cmd/crates/soroban-spec-typescript/src/lib.rsUpdate spec/XDR imports and error typing to non-curr.
cmd/crates/soroban-spec-typescript/src/boilerplate.rsImprove ignored-test messages and adjust directory-compare helper logic.
cmd/crates/soroban-spec-typescript/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-tools/src/verify.rsUpdate spec/XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/src/lib.rsUpdate broad XDR imports to non-curr and adjust remaining curr-scoped enums.
cmd/crates/soroban-spec-tools/src/event.rsUpdate XDR imports to non-curr.
cmd/crates/soroban-spec-tools/src/contract.rsUpdate XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/Cargo.tomlDrop stellar-xdr feature curr from this crate.
Cargo.tomlBump workspace protocol dependency versions to v27 / v27 RCs and add soroban-env-host v27.
Cargo.lockRefresh lockfile for the new dependency set.

Comment threadcmd/crates/soroban-spec-typescript/src/boilerplate.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:8a70c15cc7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment threadcmd/soroban-cli/src/signer/mod.rs Outdated
Comment threadcmd/soroban-cli/src/signer/mod.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:46e035db10

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread.github/workflows/bindings-ts.yml
@mootz12
mootz12 merged commit 6ceb032 into mainJun 17, 2026
227 checks passed
@mootz12
mootz12 deleted the p27-update branch June 17, 2026 20:29
@github-project-automationgithub-project-automationBot moved this from Backlog (Not Ready) to Done in DevXJun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants

@mootz12@fnando
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update stellar dependencies to protocol 27 - #2613

Merged
mootz12 merged 11 commits into
mainfrom
p27-update
Jun 17, 2026
Merged

Update stellar dependencies to protocol 27#2613
mootz12 merged 11 commits into
mainfrom
p27-update

Conversation

@mootz12

@mootz12mootz12 commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

What

Updates protocol dependencies to protocol 27, cleans up clippy warnings, and adds the ability to sign AddressV2 auth entries.

Known limitations

Support for signing with delegated signers does not exist at this time

TODO

  • Update rs-soroban-sdk packages once an RC release is available

@github-project-automationgithub-project-automationBot moved this to Backlog (Not Ready) in DevXJun 17, 2026
@mootz12
mootz12 requested a review from fnandoJune 17, 2026 02:15
@mootz12
mootz12 marked this pull request as ready for review June 17, 2026 15:16
@mootz12
mootz12 requested a review from a team as a code ownerJune 17, 2026 15:16
CopilotAI review requested due to automatic review settings June 17, 2026 15:16
@socket-security

socket-securityBot commented Jun 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?cargo/bollard@0.20.2cargo/testcontainers@0.27.2cargo/sep5@0.1.0cargo/tokio@1.52.3cargo/stellar-xdr@27.0.0cargo/soroban-sdk@27.0.0-rc.1cargo/soroban-ledger-snapshot@27.0.0-rc.1cargo/sha2@0.10.9cargo/sha2@0.9.9cargo/which@4.4.2cargo/ulid@1.2.1cargo/directories@5.0.1cargo/mockito@1.7.0cargo/whoami@1.6.1cargo/reqwest@0.12.23cargo/httpmock@0.7.0cargo/ledger-transport-hid@0.10.0cargo/wasm-opt@0.116.1cargo/tempfile@3.21.0cargo/open@5.3.2cargo/rpassword@7.4.0cargo/keyring@3.6.3cargo/serial_test@3.2.0cargo/assert_cmd@2.0.17cargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates stellar-cli’s Rust workspace to Protocol 27-compatible dependencies (notably stellar-xdr / Soroban crates), adjusts code to the new stellar_xdr API surface (removing curr usage), and extends the signer to support signing AddressV2 Soroban auth entries using the correct CAP-0071-02 payload preimage.

Changes:

  • Bump workspace protocol dependencies to v27 (including stellar-xdr = 27.0.0, soroban-env-host = 27.0.0, and soroban-* = 27.0.0-rc.1) and update the lockfile accordingly.
  • Replace stellar_xdr::curr::* imports/usages with top-level stellar_xdr::* and update CLI encode/decode helpers to the new stellar_xdr::cli API.
  • Add AddressV2 signing support by hashing the SorobanAuthorizationWithAddress preimage, plus unit tests ensuring the AddressV2 variant is preserved and produces distinct signatures from V1.

Reviewed changes

Copilot reviewed 41 out of 42 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
cmd/soroban-cli/src/wasm.rsSwitch XDR imports from curr to top-level stellar_xdr.
cmd/soroban-cli/src/utils.rsUpdate XDR imports and tests to use top-level stellar_xdr types.
cmd/soroban-cli/src/signer/validation.rsUpdate contract ID construction for non-curr XDR types in tests.
cmd/soroban-cli/src/signer/mod.rsAdd AddressV2 auth signing using SorobanAuthorizationWithAddress preimage + new tests; update contract ID pattern matching.
cmd/soroban-cli/src/log/auth.rsFormat auth entries for AddressV2 and AddressWithDelegates; minor iterator/clippy cleanups; update contract ID formatting match.
cmd/soroban-cli/src/lib.rsRe-export stellar_xdr directly as xdr (removing curr re-export).
cmd/soroban-cli/src/key.rsUpdate contract address construction to non-curr XDR types.
cmd/soroban-cli/src/config/sc_address.rsUpdate ScAddress::Contract construction to non-curr XDR types.
cmd/soroban-cli/src/commands/version.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/tx/xdr.rsUpdate Limited/error types to non-curr XDR.
cmd/soroban-cli/src/commands/tx/update/sequence_number/next.rsUpdate MuxedAccount import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/send.rsUpdate XDR error type to stellar_xdr::Error and remove curr import.
cmd/soroban-cli/src/commands/tx/encode.rsUpdate stellar_xdr::cli::encode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/tx/edit.rsUpdate XDR read/write trait bounds and envelope types to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/decode.rsUpdate stellar_xdr::cli::decode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/snapshot/merge.rsUpdate snapshot merge key/value types to non-curr XDR types.
cmd/soroban-cli/src/commands/snapshot/create.rsSwitch broad XDR imports and contract address creation off curr.
cmd/soroban-cli/src/commands/network/settings.rsUpdate XDR imports and error types to non-curr.
cmd/soroban-cli/src/commands/ledger/entry/fetch/contract_data.rsUpdate XDR error type to stellar_xdr::Error.
cmd/soroban-cli/src/commands/doctor.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/contract/info/shared.rsUpdate ContractId import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/meta.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/build.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/deploy/asset.rsUpdate contract address creation to non-curr XDR types.
cmd/soroban-cli/src/commands/contract/build.rsUpdate XDR imports/error types and spec entry typing to non-curr.
cmd/soroban-cli/src/commands/contract/arg_parsing.rsUpdate many spec/XDR type imports/usages to non-curr and clean up iterator style.
cmd/soroban-cli/src/assembled.rsUpdate broad XDR imports and contract ID construction to non-curr.
cmd/crates/stellar-ledger/tests/test/emulator_tests.rsUpdate test XDR imports to non-curr.
cmd/crates/stellar-ledger/src/lib.rsUpdate crate XDR imports to non-curr.
cmd/crates/stellar-ledger/src/emulator_test_support/util.rsUpdate Hash import to non-curr.
cmd/crates/stellar-ledger/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-typescript/src/types.rsUpdate spec/XDR imports to non-curr.
cmd/crates/soroban-spec-typescript/src/lib.rsUpdate spec/XDR imports and error typing to non-curr.
cmd/crates/soroban-spec-typescript/src/boilerplate.rsImprove ignored-test messages and adjust directory-compare helper logic.
cmd/crates/soroban-spec-typescript/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-tools/src/verify.rsUpdate spec/XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/src/lib.rsUpdate broad XDR imports to non-curr and adjust remaining curr-scoped enums.
cmd/crates/soroban-spec-tools/src/event.rsUpdate XDR imports to non-curr.
cmd/crates/soroban-spec-tools/src/contract.rsUpdate XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/Cargo.tomlDrop stellar-xdr feature curr from this crate.
Cargo.tomlBump workspace protocol dependency versions to v27 / v27 RCs and add soroban-env-host v27.
Cargo.lockRefresh lockfile for the new dependency set.

Comment threadcmd/crates/soroban-spec-typescript/src/boilerplate.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:8a70c15cc7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment threadcmd/soroban-cli/src/signer/mod.rs Outdated
Comment threadcmd/soroban-cli/src/signer/mod.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:46e035db10

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread.github/workflows/bindings-ts.yml
@mootz12
mootz12 merged commit 6ceb032 into mainJun 17, 2026
227 checks passed
@mootz12
mootz12 deleted the p27-update branch June 17, 2026 20:29
@github-project-automationgithub-project-automationBot moved this from Backlog (Not Ready) to Done in DevXJun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants

@mootz12@fnando
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update stellar dependencies to protocol 27 - #2613

Merged
mootz12 merged 11 commits into
mainfrom
p27-update
Jun 17, 2026
Merged

Update stellar dependencies to protocol 27#2613
mootz12 merged 11 commits into
mainfrom
p27-update

Conversation

@mootz12

@mootz12mootz12 commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

What

Updates protocol dependencies to protocol 27, cleans up clippy warnings, and adds the ability to sign AddressV2 auth entries.

Known limitations

Support for signing with delegated signers does not exist at this time

TODO

  • Update rs-soroban-sdk packages once an RC release is available

@github-project-automationgithub-project-automationBot moved this to Backlog (Not Ready) in DevXJun 17, 2026
@mootz12
mootz12 requested a review from fnandoJune 17, 2026 02:15
@mootz12
mootz12 marked this pull request as ready for review June 17, 2026 15:16
@mootz12
mootz12 requested a review from a team as a code ownerJune 17, 2026 15:16
CopilotAI review requested due to automatic review settings June 17, 2026 15:16
@socket-security

socket-securityBot commented Jun 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?cargo/bollard@0.20.2cargo/testcontainers@0.27.2cargo/sep5@0.1.0cargo/tokio@1.52.3cargo/stellar-xdr@27.0.0cargo/soroban-sdk@27.0.0-rc.1cargo/soroban-ledger-snapshot@27.0.0-rc.1cargo/sha2@0.10.9cargo/sha2@0.9.9cargo/which@4.4.2cargo/ulid@1.2.1cargo/directories@5.0.1cargo/mockito@1.7.0cargo/whoami@1.6.1cargo/reqwest@0.12.23cargo/httpmock@0.7.0cargo/ledger-transport-hid@0.10.0cargo/wasm-opt@0.116.1cargo/tempfile@3.21.0cargo/open@5.3.2cargo/rpassword@7.4.0cargo/keyring@3.6.3cargo/serial_test@3.2.0cargo/assert_cmd@2.0.17cargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates stellar-cli’s Rust workspace to Protocol 27-compatible dependencies (notably stellar-xdr / Soroban crates), adjusts code to the new stellar_xdr API surface (removing curr usage), and extends the signer to support signing AddressV2 Soroban auth entries using the correct CAP-0071-02 payload preimage.

Changes:

  • Bump workspace protocol dependencies to v27 (including stellar-xdr = 27.0.0, soroban-env-host = 27.0.0, and soroban-* = 27.0.0-rc.1) and update the lockfile accordingly.
  • Replace stellar_xdr::curr::* imports/usages with top-level stellar_xdr::* and update CLI encode/decode helpers to the new stellar_xdr::cli API.
  • Add AddressV2 signing support by hashing the SorobanAuthorizationWithAddress preimage, plus unit tests ensuring the AddressV2 variant is preserved and produces distinct signatures from V1.

Reviewed changes

Copilot reviewed 41 out of 42 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
cmd/soroban-cli/src/wasm.rsSwitch XDR imports from curr to top-level stellar_xdr.
cmd/soroban-cli/src/utils.rsUpdate XDR imports and tests to use top-level stellar_xdr types.
cmd/soroban-cli/src/signer/validation.rsUpdate contract ID construction for non-curr XDR types in tests.
cmd/soroban-cli/src/signer/mod.rsAdd AddressV2 auth signing using SorobanAuthorizationWithAddress preimage + new tests; update contract ID pattern matching.
cmd/soroban-cli/src/log/auth.rsFormat auth entries for AddressV2 and AddressWithDelegates; minor iterator/clippy cleanups; update contract ID formatting match.
cmd/soroban-cli/src/lib.rsRe-export stellar_xdr directly as xdr (removing curr re-export).
cmd/soroban-cli/src/key.rsUpdate contract address construction to non-curr XDR types.
cmd/soroban-cli/src/config/sc_address.rsUpdate ScAddress::Contract construction to non-curr XDR types.
cmd/soroban-cli/src/commands/version.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/tx/xdr.rsUpdate Limited/error types to non-curr XDR.
cmd/soroban-cli/src/commands/tx/update/sequence_number/next.rsUpdate MuxedAccount import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/send.rsUpdate XDR error type to stellar_xdr::Error and remove curr import.
cmd/soroban-cli/src/commands/tx/encode.rsUpdate stellar_xdr::cli::encode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/tx/edit.rsUpdate XDR read/write trait bounds and envelope types to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/decode.rsUpdate stellar_xdr::cli::decode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/snapshot/merge.rsUpdate snapshot merge key/value types to non-curr XDR types.
cmd/soroban-cli/src/commands/snapshot/create.rsSwitch broad XDR imports and contract address creation off curr.
cmd/soroban-cli/src/commands/network/settings.rsUpdate XDR imports and error types to non-curr.
cmd/soroban-cli/src/commands/ledger/entry/fetch/contract_data.rsUpdate XDR error type to stellar_xdr::Error.
cmd/soroban-cli/src/commands/doctor.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/contract/info/shared.rsUpdate ContractId import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/meta.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/build.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/deploy/asset.rsUpdate contract address creation to non-curr XDR types.
cmd/soroban-cli/src/commands/contract/build.rsUpdate XDR imports/error types and spec entry typing to non-curr.
cmd/soroban-cli/src/commands/contract/arg_parsing.rsUpdate many spec/XDR type imports/usages to non-curr and clean up iterator style.
cmd/soroban-cli/src/assembled.rsUpdate broad XDR imports and contract ID construction to non-curr.
cmd/crates/stellar-ledger/tests/test/emulator_tests.rsUpdate test XDR imports to non-curr.
cmd/crates/stellar-ledger/src/lib.rsUpdate crate XDR imports to non-curr.
cmd/crates/stellar-ledger/src/emulator_test_support/util.rsUpdate Hash import to non-curr.
cmd/crates/stellar-ledger/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-typescript/src/types.rsUpdate spec/XDR imports to non-curr.
cmd/crates/soroban-spec-typescript/src/lib.rsUpdate spec/XDR imports and error typing to non-curr.
cmd/crates/soroban-spec-typescript/src/boilerplate.rsImprove ignored-test messages and adjust directory-compare helper logic.
cmd/crates/soroban-spec-typescript/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-tools/src/verify.rsUpdate spec/XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/src/lib.rsUpdate broad XDR imports to non-curr and adjust remaining curr-scoped enums.
cmd/crates/soroban-spec-tools/src/event.rsUpdate XDR imports to non-curr.
cmd/crates/soroban-spec-tools/src/contract.rsUpdate XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/Cargo.tomlDrop stellar-xdr feature curr from this crate.
Cargo.tomlBump workspace protocol dependency versions to v27 / v27 RCs and add soroban-env-host v27.
Cargo.lockRefresh lockfile for the new dependency set.

Comment threadcmd/crates/soroban-spec-typescript/src/boilerplate.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:8a70c15cc7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment threadcmd/soroban-cli/src/signer/mod.rs Outdated
Comment threadcmd/soroban-cli/src/signer/mod.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:46e035db10

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread.github/workflows/bindings-ts.yml
@mootz12
mootz12 merged commit 6ceb032 into mainJun 17, 2026
227 checks passed
@mootz12
mootz12 deleted the p27-update branch June 17, 2026 20:29
@github-project-automationgithub-project-automationBot moved this from Backlog (Not Ready) to Done in DevXJun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants

@mootz12@fnando
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Update stellar dependencies to protocol 27 - #2613

Merged
mootz12 merged 11 commits into
mainfrom
p27-update
Jun 17, 2026
Merged

Update stellar dependencies to protocol 27#2613
mootz12 merged 11 commits into
mainfrom
p27-update

Conversation

@mootz12

@mootz12mootz12 commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

What

Updates protocol dependencies to protocol 27, cleans up clippy warnings, and adds the ability to sign AddressV2 auth entries.

Known limitations

Support for signing with delegated signers does not exist at this time

TODO

  • Update rs-soroban-sdk packages once an RC release is available

@github-project-automationgithub-project-automationBot moved this to Backlog (Not Ready) in DevXJun 17, 2026
@mootz12
mootz12 requested a review from fnandoJune 17, 2026 02:15
@mootz12
mootz12 marked this pull request as ready for review June 17, 2026 15:16
@mootz12
mootz12 requested a review from a team as a code ownerJune 17, 2026 15:16
CopilotAI review requested due to automatic review settings June 17, 2026 15:16
@socket-security

socket-securityBot commented Jun 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?cargo/bollard@0.20.2cargo/testcontainers@0.27.2cargo/sep5@0.1.0cargo/tokio@1.52.3cargo/stellar-xdr@27.0.0cargo/soroban-sdk@27.0.0-rc.1cargo/soroban-ledger-snapshot@27.0.0-rc.1cargo/sha2@0.10.9cargo/sha2@0.9.9cargo/which@4.4.2cargo/ulid@1.2.1cargo/directories@5.0.1cargo/mockito@1.7.0cargo/whoami@1.6.1cargo/reqwest@0.12.23cargo/httpmock@0.7.0cargo/ledger-transport-hid@0.10.0cargo/wasm-opt@0.116.1cargo/tempfile@3.21.0cargo/open@5.3.2cargo/rpassword@7.4.0cargo/keyring@3.6.3cargo/serial_test@3.2.0cargo/assert_cmd@2.0.17cargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates stellar-cli’s Rust workspace to Protocol 27-compatible dependencies (notably stellar-xdr / Soroban crates), adjusts code to the new stellar_xdr API surface (removing curr usage), and extends the signer to support signing AddressV2 Soroban auth entries using the correct CAP-0071-02 payload preimage.

Changes:

  • Bump workspace protocol dependencies to v27 (including stellar-xdr = 27.0.0, soroban-env-host = 27.0.0, and soroban-* = 27.0.0-rc.1) and update the lockfile accordingly.
  • Replace stellar_xdr::curr::* imports/usages with top-level stellar_xdr::* and update CLI encode/decode helpers to the new stellar_xdr::cli API.
  • Add AddressV2 signing support by hashing the SorobanAuthorizationWithAddress preimage, plus unit tests ensuring the AddressV2 variant is preserved and produces distinct signatures from V1.

Reviewed changes

Copilot reviewed 41 out of 42 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
cmd/soroban-cli/src/wasm.rsSwitch XDR imports from curr to top-level stellar_xdr.
cmd/soroban-cli/src/utils.rsUpdate XDR imports and tests to use top-level stellar_xdr types.
cmd/soroban-cli/src/signer/validation.rsUpdate contract ID construction for non-curr XDR types in tests.
cmd/soroban-cli/src/signer/mod.rsAdd AddressV2 auth signing using SorobanAuthorizationWithAddress preimage + new tests; update contract ID pattern matching.
cmd/soroban-cli/src/log/auth.rsFormat auth entries for AddressV2 and AddressWithDelegates; minor iterator/clippy cleanups; update contract ID formatting match.
cmd/soroban-cli/src/lib.rsRe-export stellar_xdr directly as xdr (removing curr re-export).
cmd/soroban-cli/src/key.rsUpdate contract address construction to non-curr XDR types.
cmd/soroban-cli/src/config/sc_address.rsUpdate ScAddress::Contract construction to non-curr XDR types.
cmd/soroban-cli/src/commands/version.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/tx/xdr.rsUpdate Limited/error types to non-curr XDR.
cmd/soroban-cli/src/commands/tx/update/sequence_number/next.rsUpdate MuxedAccount import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/send.rsUpdate XDR error type to stellar_xdr::Error and remove curr import.
cmd/soroban-cli/src/commands/tx/encode.rsUpdate stellar_xdr::cli::encode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/tx/edit.rsUpdate XDR read/write trait bounds and envelope types to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/decode.rsUpdate stellar_xdr::cli::decode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/snapshot/merge.rsUpdate snapshot merge key/value types to non-curr XDR types.
cmd/soroban-cli/src/commands/snapshot/create.rsSwitch broad XDR imports and contract address creation off curr.
cmd/soroban-cli/src/commands/network/settings.rsUpdate XDR imports and error types to non-curr.
cmd/soroban-cli/src/commands/ledger/entry/fetch/contract_data.rsUpdate XDR error type to stellar_xdr::Error.
cmd/soroban-cli/src/commands/doctor.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/contract/info/shared.rsUpdate ContractId import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/meta.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/build.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/deploy/asset.rsUpdate contract address creation to non-curr XDR types.
cmd/soroban-cli/src/commands/contract/build.rsUpdate XDR imports/error types and spec entry typing to non-curr.
cmd/soroban-cli/src/commands/contract/arg_parsing.rsUpdate many spec/XDR type imports/usages to non-curr and clean up iterator style.
cmd/soroban-cli/src/assembled.rsUpdate broad XDR imports and contract ID construction to non-curr.
cmd/crates/stellar-ledger/tests/test/emulator_tests.rsUpdate test XDR imports to non-curr.
cmd/crates/stellar-ledger/src/lib.rsUpdate crate XDR imports to non-curr.
cmd/crates/stellar-ledger/src/emulator_test_support/util.rsUpdate Hash import to non-curr.
cmd/crates/stellar-ledger/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-typescript/src/types.rsUpdate spec/XDR imports to non-curr.
cmd/crates/soroban-spec-typescript/src/lib.rsUpdate spec/XDR imports and error typing to non-curr.
cmd/crates/soroban-spec-typescript/src/boilerplate.rsImprove ignored-test messages and adjust directory-compare helper logic.
cmd/crates/soroban-spec-typescript/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-tools/src/verify.rsUpdate spec/XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/src/lib.rsUpdate broad XDR imports to non-curr and adjust remaining curr-scoped enums.
cmd/crates/soroban-spec-tools/src/event.rsUpdate XDR imports to non-curr.
cmd/crates/soroban-spec-tools/src/contract.rsUpdate XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/Cargo.tomlDrop stellar-xdr feature curr from this crate.
Cargo.tomlBump workspace protocol dependency versions to v27 / v27 RCs and add soroban-env-host v27.
Cargo.lockRefresh lockfile for the new dependency set.

Comment threadcmd/crates/soroban-spec-typescript/src/boilerplate.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:8a70c15cc7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment threadcmd/soroban-cli/src/signer/mod.rs Outdated
Comment threadcmd/soroban-cli/src/signer/mod.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:46e035db10

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread.github/workflows/bindings-ts.yml
@mootz12
mootz12 merged commit 6ceb032 into mainJun 17, 2026
227 checks passed
@mootz12
mootz12 deleted the p27-update branch June 17, 2026 20:29
@github-project-automationgithub-project-automationBot moved this from Backlog (Not Ready) to Done in DevXJun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants

@mootz12@fnando
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update stellar dependencies to protocol 27 - #2613

Merged
mootz12 merged 11 commits into
mainfrom
p27-update
Jun 17, 2026
Merged

Update stellar dependencies to protocol 27#2613
mootz12 merged 11 commits into
mainfrom
p27-update

Conversation

@mootz12

@mootz12mootz12 commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

What

Updates protocol dependencies to protocol 27, cleans up clippy warnings, and adds the ability to sign AddressV2 auth entries.

Known limitations

Support for signing with delegated signers does not exist at this time

TODO

  • Update rs-soroban-sdk packages once an RC release is available

@github-project-automationgithub-project-automationBot moved this to Backlog (Not Ready) in DevXJun 17, 2026
@mootz12
mootz12 requested a review from fnandoJune 17, 2026 02:15
@mootz12
mootz12 marked this pull request as ready for review June 17, 2026 15:16
@mootz12
mootz12 requested a review from a team as a code ownerJune 17, 2026 15:16
CopilotAI review requested due to automatic review settings June 17, 2026 15:16
@socket-security

socket-securityBot commented Jun 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?cargo/bollard@0.20.2cargo/testcontainers@0.27.2cargo/sep5@0.1.0cargo/tokio@1.52.3cargo/stellar-xdr@27.0.0cargo/soroban-sdk@27.0.0-rc.1cargo/soroban-ledger-snapshot@27.0.0-rc.1cargo/sha2@0.10.9cargo/sha2@0.9.9cargo/which@4.4.2cargo/ulid@1.2.1cargo/directories@5.0.1cargo/mockito@1.7.0cargo/whoami@1.6.1cargo/reqwest@0.12.23cargo/httpmock@0.7.0cargo/ledger-transport-hid@0.10.0cargo/wasm-opt@0.116.1cargo/tempfile@3.21.0cargo/open@5.3.2cargo/rpassword@7.4.0cargo/keyring@3.6.3cargo/serial_test@3.2.0cargo/assert_cmd@2.0.17cargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates stellar-cli’s Rust workspace to Protocol 27-compatible dependencies (notably stellar-xdr / Soroban crates), adjusts code to the new stellar_xdr API surface (removing curr usage), and extends the signer to support signing AddressV2 Soroban auth entries using the correct CAP-0071-02 payload preimage.

Changes:

  • Bump workspace protocol dependencies to v27 (including stellar-xdr = 27.0.0, soroban-env-host = 27.0.0, and soroban-* = 27.0.0-rc.1) and update the lockfile accordingly.
  • Replace stellar_xdr::curr::* imports/usages with top-level stellar_xdr::* and update CLI encode/decode helpers to the new stellar_xdr::cli API.
  • Add AddressV2 signing support by hashing the SorobanAuthorizationWithAddress preimage, plus unit tests ensuring the AddressV2 variant is preserved and produces distinct signatures from V1.

Reviewed changes

Copilot reviewed 41 out of 42 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
cmd/soroban-cli/src/wasm.rsSwitch XDR imports from curr to top-level stellar_xdr.
cmd/soroban-cli/src/utils.rsUpdate XDR imports and tests to use top-level stellar_xdr types.
cmd/soroban-cli/src/signer/validation.rsUpdate contract ID construction for non-curr XDR types in tests.
cmd/soroban-cli/src/signer/mod.rsAdd AddressV2 auth signing using SorobanAuthorizationWithAddress preimage + new tests; update contract ID pattern matching.
cmd/soroban-cli/src/log/auth.rsFormat auth entries for AddressV2 and AddressWithDelegates; minor iterator/clippy cleanups; update contract ID formatting match.
cmd/soroban-cli/src/lib.rsRe-export stellar_xdr directly as xdr (removing curr re-export).
cmd/soroban-cli/src/key.rsUpdate contract address construction to non-curr XDR types.
cmd/soroban-cli/src/config/sc_address.rsUpdate ScAddress::Contract construction to non-curr XDR types.
cmd/soroban-cli/src/commands/version.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/tx/xdr.rsUpdate Limited/error types to non-curr XDR.
cmd/soroban-cli/src/commands/tx/update/sequence_number/next.rsUpdate MuxedAccount import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/send.rsUpdate XDR error type to stellar_xdr::Error and remove curr import.
cmd/soroban-cli/src/commands/tx/encode.rsUpdate stellar_xdr::cli::encode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/tx/edit.rsUpdate XDR read/write trait bounds and envelope types to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/decode.rsUpdate stellar_xdr::cli::decode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/snapshot/merge.rsUpdate snapshot merge key/value types to non-curr XDR types.
cmd/soroban-cli/src/commands/snapshot/create.rsSwitch broad XDR imports and contract address creation off curr.
cmd/soroban-cli/src/commands/network/settings.rsUpdate XDR imports and error types to non-curr.
cmd/soroban-cli/src/commands/ledger/entry/fetch/contract_data.rsUpdate XDR error type to stellar_xdr::Error.
cmd/soroban-cli/src/commands/doctor.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/contract/info/shared.rsUpdate ContractId import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/meta.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/build.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/deploy/asset.rsUpdate contract address creation to non-curr XDR types.
cmd/soroban-cli/src/commands/contract/build.rsUpdate XDR imports/error types and spec entry typing to non-curr.
cmd/soroban-cli/src/commands/contract/arg_parsing.rsUpdate many spec/XDR type imports/usages to non-curr and clean up iterator style.
cmd/soroban-cli/src/assembled.rsUpdate broad XDR imports and contract ID construction to non-curr.
cmd/crates/stellar-ledger/tests/test/emulator_tests.rsUpdate test XDR imports to non-curr.
cmd/crates/stellar-ledger/src/lib.rsUpdate crate XDR imports to non-curr.
cmd/crates/stellar-ledger/src/emulator_test_support/util.rsUpdate Hash import to non-curr.
cmd/crates/stellar-ledger/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-typescript/src/types.rsUpdate spec/XDR imports to non-curr.
cmd/crates/soroban-spec-typescript/src/lib.rsUpdate spec/XDR imports and error typing to non-curr.
cmd/crates/soroban-spec-typescript/src/boilerplate.rsImprove ignored-test messages and adjust directory-compare helper logic.
cmd/crates/soroban-spec-typescript/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-tools/src/verify.rsUpdate spec/XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/src/lib.rsUpdate broad XDR imports to non-curr and adjust remaining curr-scoped enums.
cmd/crates/soroban-spec-tools/src/event.rsUpdate XDR imports to non-curr.
cmd/crates/soroban-spec-tools/src/contract.rsUpdate XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/Cargo.tomlDrop stellar-xdr feature curr from this crate.
Cargo.tomlBump workspace protocol dependency versions to v27 / v27 RCs and add soroban-env-host v27.
Cargo.lockRefresh lockfile for the new dependency set.

Comment threadcmd/crates/soroban-spec-typescript/src/boilerplate.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:8a70c15cc7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment threadcmd/soroban-cli/src/signer/mod.rs Outdated
Comment threadcmd/soroban-cli/src/signer/mod.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:46e035db10

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread.github/workflows/bindings-ts.yml
@mootz12
mootz12 merged commit 6ceb032 into mainJun 17, 2026
227 checks passed
@mootz12
mootz12 deleted the p27-update branch June 17, 2026 20:29
@github-project-automationgithub-project-automationBot moved this from Backlog (Not Ready) to Done in DevXJun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants

@mootz12@fnando
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Update stellar dependencies to protocol 27 - #2613

Merged
mootz12 merged 11 commits into
mainfrom
p27-update
Jun 17, 2026
Merged

Update stellar dependencies to protocol 27#2613
mootz12 merged 11 commits into
mainfrom
p27-update

Conversation

@mootz12

@mootz12mootz12 commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

What

Updates protocol dependencies to protocol 27, cleans up clippy warnings, and adds the ability to sign AddressV2 auth entries.

Known limitations

Support for signing with delegated signers does not exist at this time

TODO

  • Update rs-soroban-sdk packages once an RC release is available

@github-project-automationgithub-project-automationBot moved this to Backlog (Not Ready) in DevXJun 17, 2026
@mootz12
mootz12 requested a review from fnandoJune 17, 2026 02:15
@mootz12
mootz12 marked this pull request as ready for review June 17, 2026 15:16
@mootz12
mootz12 requested a review from a team as a code ownerJune 17, 2026 15:16
CopilotAI review requested due to automatic review settings June 17, 2026 15:16
@socket-security

socket-securityBot commented Jun 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?cargo/bollard@0.20.2cargo/testcontainers@0.27.2cargo/sep5@0.1.0cargo/tokio@1.52.3cargo/stellar-xdr@27.0.0cargo/soroban-sdk@27.0.0-rc.1cargo/soroban-ledger-snapshot@27.0.0-rc.1cargo/sha2@0.10.9cargo/sha2@0.9.9cargo/which@4.4.2cargo/ulid@1.2.1cargo/directories@5.0.1cargo/mockito@1.7.0cargo/whoami@1.6.1cargo/reqwest@0.12.23cargo/httpmock@0.7.0cargo/ledger-transport-hid@0.10.0cargo/wasm-opt@0.116.1cargo/tempfile@3.21.0cargo/open@5.3.2cargo/rpassword@7.4.0cargo/keyring@3.6.3cargo/serial_test@3.2.0cargo/assert_cmd@2.0.17cargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates stellar-cli’s Rust workspace to Protocol 27-compatible dependencies (notably stellar-xdr / Soroban crates), adjusts code to the new stellar_xdr API surface (removing curr usage), and extends the signer to support signing AddressV2 Soroban auth entries using the correct CAP-0071-02 payload preimage.

Changes:

  • Bump workspace protocol dependencies to v27 (including stellar-xdr = 27.0.0, soroban-env-host = 27.0.0, and soroban-* = 27.0.0-rc.1) and update the lockfile accordingly.
  • Replace stellar_xdr::curr::* imports/usages with top-level stellar_xdr::* and update CLI encode/decode helpers to the new stellar_xdr::cli API.
  • Add AddressV2 signing support by hashing the SorobanAuthorizationWithAddress preimage, plus unit tests ensuring the AddressV2 variant is preserved and produces distinct signatures from V1.

Reviewed changes

Copilot reviewed 41 out of 42 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
cmd/soroban-cli/src/wasm.rsSwitch XDR imports from curr to top-level stellar_xdr.
cmd/soroban-cli/src/utils.rsUpdate XDR imports and tests to use top-level stellar_xdr types.
cmd/soroban-cli/src/signer/validation.rsUpdate contract ID construction for non-curr XDR types in tests.
cmd/soroban-cli/src/signer/mod.rsAdd AddressV2 auth signing using SorobanAuthorizationWithAddress preimage + new tests; update contract ID pattern matching.
cmd/soroban-cli/src/log/auth.rsFormat auth entries for AddressV2 and AddressWithDelegates; minor iterator/clippy cleanups; update contract ID formatting match.
cmd/soroban-cli/src/lib.rsRe-export stellar_xdr directly as xdr (removing curr re-export).
cmd/soroban-cli/src/key.rsUpdate contract address construction to non-curr XDR types.
cmd/soroban-cli/src/config/sc_address.rsUpdate ScAddress::Contract construction to non-curr XDR types.
cmd/soroban-cli/src/commands/version.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/tx/xdr.rsUpdate Limited/error types to non-curr XDR.
cmd/soroban-cli/src/commands/tx/update/sequence_number/next.rsUpdate MuxedAccount import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/send.rsUpdate XDR error type to stellar_xdr::Error and remove curr import.
cmd/soroban-cli/src/commands/tx/encode.rsUpdate stellar_xdr::cli::encode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/tx/edit.rsUpdate XDR read/write trait bounds and envelope types to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/decode.rsUpdate stellar_xdr::cli::decode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/snapshot/merge.rsUpdate snapshot merge key/value types to non-curr XDR types.
cmd/soroban-cli/src/commands/snapshot/create.rsSwitch broad XDR imports and contract address creation off curr.
cmd/soroban-cli/src/commands/network/settings.rsUpdate XDR imports and error types to non-curr.
cmd/soroban-cli/src/commands/ledger/entry/fetch/contract_data.rsUpdate XDR error type to stellar_xdr::Error.
cmd/soroban-cli/src/commands/doctor.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/contract/info/shared.rsUpdate ContractId import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/meta.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/build.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/deploy/asset.rsUpdate contract address creation to non-curr XDR types.
cmd/soroban-cli/src/commands/contract/build.rsUpdate XDR imports/error types and spec entry typing to non-curr.
cmd/soroban-cli/src/commands/contract/arg_parsing.rsUpdate many spec/XDR type imports/usages to non-curr and clean up iterator style.
cmd/soroban-cli/src/assembled.rsUpdate broad XDR imports and contract ID construction to non-curr.
cmd/crates/stellar-ledger/tests/test/emulator_tests.rsUpdate test XDR imports to non-curr.
cmd/crates/stellar-ledger/src/lib.rsUpdate crate XDR imports to non-curr.
cmd/crates/stellar-ledger/src/emulator_test_support/util.rsUpdate Hash import to non-curr.
cmd/crates/stellar-ledger/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-typescript/src/types.rsUpdate spec/XDR imports to non-curr.
cmd/crates/soroban-spec-typescript/src/lib.rsUpdate spec/XDR imports and error typing to non-curr.
cmd/crates/soroban-spec-typescript/src/boilerplate.rsImprove ignored-test messages and adjust directory-compare helper logic.
cmd/crates/soroban-spec-typescript/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-tools/src/verify.rsUpdate spec/XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/src/lib.rsUpdate broad XDR imports to non-curr and adjust remaining curr-scoped enums.
cmd/crates/soroban-spec-tools/src/event.rsUpdate XDR imports to non-curr.
cmd/crates/soroban-spec-tools/src/contract.rsUpdate XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/Cargo.tomlDrop stellar-xdr feature curr from this crate.
Cargo.tomlBump workspace protocol dependency versions to v27 / v27 RCs and add soroban-env-host v27.
Cargo.lockRefresh lockfile for the new dependency set.

Comment threadcmd/crates/soroban-spec-typescript/src/boilerplate.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:8a70c15cc7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment threadcmd/soroban-cli/src/signer/mod.rs Outdated
Comment threadcmd/soroban-cli/src/signer/mod.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:46e035db10

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread.github/workflows/bindings-ts.yml
@mootz12
mootz12 merged commit 6ceb032 into mainJun 17, 2026
227 checks passed
@mootz12
mootz12 deleted the p27-update branch June 17, 2026 20:29
@github-project-automationgithub-project-automationBot moved this from Backlog (Not Ready) to Done in DevXJun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants

@mootz12@fnando
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Update stellar dependencies to protocol 27 - #2613

Merged
mootz12 merged 11 commits into
mainfrom
p27-update
Jun 17, 2026
Merged

Update stellar dependencies to protocol 27#2613
mootz12 merged 11 commits into
mainfrom
p27-update

Conversation

@mootz12

@mootz12mootz12 commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

What

Updates protocol dependencies to protocol 27, cleans up clippy warnings, and adds the ability to sign AddressV2 auth entries.

Known limitations

Support for signing with delegated signers does not exist at this time

TODO

  • Update rs-soroban-sdk packages once an RC release is available

@github-project-automationgithub-project-automationBot moved this to Backlog (Not Ready) in DevXJun 17, 2026
@mootz12
mootz12 requested a review from fnandoJune 17, 2026 02:15
@mootz12
mootz12 marked this pull request as ready for review June 17, 2026 15:16
@mootz12
mootz12 requested a review from a team as a code ownerJune 17, 2026 15:16
CopilotAI review requested due to automatic review settings June 17, 2026 15:16
@socket-security

socket-securityBot commented Jun 17, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

ActionSeverityAlert (click "▶" to expand/collapse)
WarnHigh
Obfuscated code: cargo libc is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:?cargo/bollard@0.20.2cargo/testcontainers@0.27.2cargo/sep5@0.1.0cargo/tokio@1.52.3cargo/stellar-xdr@27.0.0cargo/soroban-sdk@27.0.0-rc.1cargo/soroban-ledger-snapshot@27.0.0-rc.1cargo/sha2@0.10.9cargo/sha2@0.9.9cargo/which@4.4.2cargo/ulid@1.2.1cargo/directories@5.0.1cargo/mockito@1.7.0cargo/whoami@1.6.1cargo/reqwest@0.12.23cargo/httpmock@0.7.0cargo/ledger-transport-hid@0.10.0cargo/wasm-opt@0.116.1cargo/tempfile@3.21.0cargo/open@5.3.2cargo/rpassword@7.4.0cargo/keyring@3.6.3cargo/serial_test@3.2.0cargo/assert_cmd@2.0.17cargo/libc@0.2.186

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/libc@0.2.186. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

WarnHigh
Obfuscated code: cargo tokio is 90.0% likely obfuscated

Confidence: 0.90

Location:Package overview

From:Cargo.lockcargo/tokio@1.52.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore cargo/tokio@1.52.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates stellar-cli’s Rust workspace to Protocol 27-compatible dependencies (notably stellar-xdr / Soroban crates), adjusts code to the new stellar_xdr API surface (removing curr usage), and extends the signer to support signing AddressV2 Soroban auth entries using the correct CAP-0071-02 payload preimage.

Changes:

  • Bump workspace protocol dependencies to v27 (including stellar-xdr = 27.0.0, soroban-env-host = 27.0.0, and soroban-* = 27.0.0-rc.1) and update the lockfile accordingly.
  • Replace stellar_xdr::curr::* imports/usages with top-level stellar_xdr::* and update CLI encode/decode helpers to the new stellar_xdr::cli API.
  • Add AddressV2 signing support by hashing the SorobanAuthorizationWithAddress preimage, plus unit tests ensuring the AddressV2 variant is preserved and produces distinct signatures from V1.

Reviewed changes

Copilot reviewed 41 out of 42 changed files in this pull request and generated 1 comment.

Show a summary per file
FileDescription
cmd/soroban-cli/src/wasm.rsSwitch XDR imports from curr to top-level stellar_xdr.
cmd/soroban-cli/src/utils.rsUpdate XDR imports and tests to use top-level stellar_xdr types.
cmd/soroban-cli/src/signer/validation.rsUpdate contract ID construction for non-curr XDR types in tests.
cmd/soroban-cli/src/signer/mod.rsAdd AddressV2 auth signing using SorobanAuthorizationWithAddress preimage + new tests; update contract ID pattern matching.
cmd/soroban-cli/src/log/auth.rsFormat auth entries for AddressV2 and AddressWithDelegates; minor iterator/clippy cleanups; update contract ID formatting match.
cmd/soroban-cli/src/lib.rsRe-export stellar_xdr directly as xdr (removing curr re-export).
cmd/soroban-cli/src/key.rsUpdate contract address construction to non-curr XDR types.
cmd/soroban-cli/src/config/sc_address.rsUpdate ScAddress::Contract construction to non-curr XDR types.
cmd/soroban-cli/src/commands/version.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/tx/xdr.rsUpdate Limited/error types to non-curr XDR.
cmd/soroban-cli/src/commands/tx/update/sequence_number/next.rsUpdate MuxedAccount import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/send.rsUpdate XDR error type to stellar_xdr::Error and remove curr import.
cmd/soroban-cli/src/commands/tx/encode.rsUpdate stellar_xdr::cli::encode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/tx/edit.rsUpdate XDR read/write trait bounds and envelope types to top-level stellar_xdr.
cmd/soroban-cli/src/commands/tx/decode.rsUpdate stellar_xdr::cli::decode invocation to new API (cmd.run() without Channel::Curr).
cmd/soroban-cli/src/commands/snapshot/merge.rsUpdate snapshot merge key/value types to non-curr XDR types.
cmd/soroban-cli/src/commands/snapshot/create.rsSwitch broad XDR imports and contract address creation off curr.
cmd/soroban-cli/src/commands/network/settings.rsUpdate XDR imports and error types to non-curr.
cmd/soroban-cli/src/commands/ledger/entry/fetch/contract_data.rsUpdate XDR error type to stellar_xdr::Error.
cmd/soroban-cli/src/commands/doctor.rsUpdate displayed XDR version field naming (from xdr_curr to xdr).
cmd/soroban-cli/src/commands/contract/info/shared.rsUpdate ContractId import to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/meta.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/info/build.rsUpdate meta XDR imports to top-level stellar_xdr.
cmd/soroban-cli/src/commands/contract/deploy/asset.rsUpdate contract address creation to non-curr XDR types.
cmd/soroban-cli/src/commands/contract/build.rsUpdate XDR imports/error types and spec entry typing to non-curr.
cmd/soroban-cli/src/commands/contract/arg_parsing.rsUpdate many spec/XDR type imports/usages to non-curr and clean up iterator style.
cmd/soroban-cli/src/assembled.rsUpdate broad XDR imports and contract ID construction to non-curr.
cmd/crates/stellar-ledger/tests/test/emulator_tests.rsUpdate test XDR imports to non-curr.
cmd/crates/stellar-ledger/src/lib.rsUpdate crate XDR imports to non-curr.
cmd/crates/stellar-ledger/src/emulator_test_support/util.rsUpdate Hash import to non-curr.
cmd/crates/stellar-ledger/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-typescript/src/types.rsUpdate spec/XDR imports to non-curr.
cmd/crates/soroban-spec-typescript/src/lib.rsUpdate spec/XDR imports and error typing to non-curr.
cmd/crates/soroban-spec-typescript/src/boilerplate.rsImprove ignored-test messages and adjust directory-compare helper logic.
cmd/crates/soroban-spec-typescript/Cargo.tomlDrop stellar-xdr feature curr from this crate.
cmd/crates/soroban-spec-tools/src/verify.rsUpdate spec/XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/src/lib.rsUpdate broad XDR imports to non-curr and adjust remaining curr-scoped enums.
cmd/crates/soroban-spec-tools/src/event.rsUpdate XDR imports to non-curr.
cmd/crates/soroban-spec-tools/src/contract.rsUpdate XDR imports to non-curr and clean up iterator style.
cmd/crates/soroban-spec-tools/Cargo.tomlDrop stellar-xdr feature curr from this crate.
Cargo.tomlBump workspace protocol dependency versions to v27 / v27 RCs and add soroban-env-host v27.
Cargo.lockRefresh lockfile for the new dependency set.

Comment threadcmd/crates/soroban-spec-typescript/src/boilerplate.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:8a70c15cc7

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment threadcmd/soroban-cli/src/signer/mod.rs Outdated
Comment threadcmd/soroban-cli/src/signer/mod.rs

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:46e035db10

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread.github/workflows/bindings-ts.yml
@mootz12
mootz12 merged commit 6ceb032 into mainJun 17, 2026
227 checks passed
@mootz12
mootz12 deleted the p27-update branch June 17, 2026 20:29
@github-project-automationgithub-project-automationBot moved this from Backlog (Not Ready) to Done in DevXJun 17, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants

@mootz12@fnando