Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions docs/packages/sdk/bsv-sdk.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,10 +3,10 @@ id: bsv-sdk
title: '@bsv/sdk'
kind: package
domain: sdk
version: '2.8.8'
version: '2.8.9'
npm: '@bsv/sdk'
last_updated: '2026-09-25'
last_verified: '2026-09-25'
last_updated: '2026-09-27'
last_verified: '2026-09-27'
review_cadence_days: 30
status: stable
tags: ['sdk', 'crypto', 'transactions']
Expand Down
6 changes: 3 additions & 3 deletions docs/reference/package-api-migrations.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ and clean-consumer tests remain the executable type authority.
| `@bsv/overlay-topics` | `1.9.1` | `1.9.1` | none | [API and usage](../packages/overlays/overlay-topics.md) | No wire, API, or database migration. Deploy the reviewed patch through the protected release workflow; retain existing validation and configured resource bounds. |
| `@bsv/paymail` | `2.4.9` | `2.4.10` | patch | [API and usage](../packages/messaging/paymail.md) | None. ESM consumers are unaffected. |
| `@bsv/payment-express-middleware` | `2.1.8` | `2.1.8` | none | [API and usage](../packages/middleware/payment-express-middleware.md) | No BRC100 call, wire or wallet-data migration. maxPaymentHeaderBytes is now ignored, including existing explicit values: move transport policy to the HTTP server, CDN, proxy or WAF and remove the deprecated option. Validate the complete HTTP route for supported payment proofs. Published 2.1.8 is verified against protected release 36052862859 and its immutable source artifacts. |
| `@bsv/sdk` | `2.8.7` | `2.8.8` | patch | [API and usage](../packages/sdk/bsv-sdk.md) | No API, wire or wallet-data migration. Omitting memoryLimit continues to leave local allocation unbounded. The default JavaScript interpreter still lacks block and coin heights and is not an exact node consensus validator. OP_NUM2BIN rejects sizes above the node's signed 32-bit limit before allocation; an optional finite memoryLimit bounds otherwise permitted local work before allocation. Resource exhaustion does not establish script invalidity. Published 2.8.7 remains the registry baseline until protected release. |
| `@bsv/sdk` | `2.8.8` | `2.8.9` | patch | [API and usage](../packages/sdk/bsv-sdk.md) | No API, wire or wallet-data migration. Omitting memoryLimit continues to leave local allocation unbounded. The default JavaScript interpreter still lacks block and coin heights and is not an exact node consensus validator. OP_NUM2BIN rejects sizes above the node's signed 32-bit limit before allocation; an optional finite memoryLimit bounds otherwise permitted local work before allocation. Resource exhaustion does not establish script invalidity. Published 2.8.8 is the registry baseline; source 2.8.9 remains a candidate until protected release. Update applications using full-size authenticated binary uploads to SDK 2.8.9. No API, wire or wallet-data migration is required; custom Peer transports retain their existing default policy. |
| `@bsv/simple` | `0.6.0` | `0.6.0` | none | [API and usage](../packages/helpers/simple.md) | Replace createServerWalletHandler() deployments with createServerWalletHandler({ authorize: async ({ action, headers }) => authenticatedSessionCanUseAction(headers, action) }). The callback must return literal true for each status, create, request, receive, balance, outputs, or reset action; omission now returns HTTP 403 for every action. Roll out the authentication layer and callback with the package, update anonymous probes or automation, and apply the same policy to every replica. Do not emulate the old public behavior with an unconditional authorize: () => true callback. Valid recipient derivations and authenticated Message Box peers remain supported; malformed, wrong-owner, or transaction-mutated flows now fail closed. New DID, CredentialSchema, and Certifier records use canonical 32-byte types. Current SDK wallet methods reject historical short types, so do not put migration aliases in wallet list, acquire, prove, or relinquish calls. Export affected records through the storage version that created them, authenticate them offline against the exact locally configured identifier, and reissue/import canonical replacements; no legacy certificate is rewritten automatically. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/. The internal comparator consolidation requires no migration and is included in the existing unpublished 0.6.0 candidate. |
| `@bsv/templates` | `1.10.2` | `1.10.3` | patch | [API and usage](../packages/helpers/templates.md) | None. CommonJS consumers that patched 1.10.2 locally can drop the patch after upgrading to 1.10.3; ESM consumers are unaffected. |
| `@bsv/teranode-listener` | `1.1.6` | `1.1.6` | none | [API and usage](../packages/network/teranode-listener.md) | No API migration is required for valid consumers: raw callbacks remain the default and decoding is opt-in with decodeMessages: true. Configuration arrays and callbacks are snapshotted at construction, boolean controls must be literal booleans, and malformed or duplicate topics, addresses, keys, and unsupported properties now fail closed. usePrivateDHT: false now actually omits the DHT service. The published mainnet PNET value is transport compatibility data, not a publisher credential; decoded sender and payload fields remain untrusted and security-critical claims require independent validation. Distributors must retain THIRD_PARTY_NOTICES.md and LICENSES/ with the package. |
Expand Down Expand Up @@ -359,8 +359,8 @@ CLI entry points: `{"lch":"./dist/cli.js"}`.

- Package documentation: [docs/packages/sdk/bsv-sdk.md](../packages/sdk/bsv-sdk.md)
- Source: [packages/sdk](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/sdk)
- Release note: Aligns explicit Script verification with bitcoin-sv coin-era, Chronicle version, locktime, sequence, signature-hash and numeric rules, including original-digest serialization. Rejects node-invalid OP_NUM2BIN sizes and checks an optional local memory budget before allocation.
- Migration: No API, wire or wallet-data migration. Omitting memoryLimit continues to leave local allocation unbounded. The default JavaScript interpreter still lacks block and coin heights and is not an exact node consensus validator. OP_NUM2BIN rejects sizes above the node's signed 32-bit limit before allocation; an optional finite memoryLimit bounds otherwise permitted local work before allocation. Resource exhaustion does not establish script invalidity. Published 2.8.7 remains the registry baseline until protected release.
- Release note: Aligns explicit Script verification with bitcoin-sv coin-era, Chronicle version, locktime, sequence, signature-hash and numeric rules, including original-digest serialization. Rejects node-invalid OP_NUM2BIN sizes and checks an optional local memory budget before allocation. AuthFetch retains a finite general payload budget matching HTTP request and configured response capacity, allowing full 4 MiB CHIRP chunks without charging their JSON expansion against the generic envelope budget. Existing HTTP, handshake, certificate, nonce, signature and redirect limits remain enforced.
- Migration: No API, wire or wallet-data migration. Omitting memoryLimit continues to leave local allocation unbounded. The default JavaScript interpreter still lacks block and coin heights and is not an exact node consensus validator. OP_NUM2BIN rejects sizes above the node's signed 32-bit limit before allocation; an optional finite memoryLimit bounds otherwise permitted local work before allocation. Resource exhaustion does not establish script invalidity. Published 2.8.8 is the registry baseline; source 2.8.9 remains a candidate until protected release. Update applications using full-size authenticated binary uploads to SDK 2.8.9. No API, wire or wallet-data migration is required; custom Peer transports retain their existing default policy.

| Public subpath | Runtime target(s) | Declaration target(s) |
| ---------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
Expand Down
2 changes: 1 addition & 1 deletion docs/reference/stack-facts.md
Original file line number Diff line number Diff line change
Expand Up @@ -62,7 +62,7 @@ authorized release action.
| overlays | `@bsv/overlay-discovery-services` | `2.2.6` | node-library | node-cjs, node-esm | node | `>=22` | [packages/overlays/overlay-discovery-services](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/overlays/overlay-discovery-services) |
| overlays | `@bsv/overlay-express` | `2.7.3` | node-library | node-cjs, node-esm | node | `>=22` | [packages/overlays/overlay-express](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/overlays/overlay-express) |
| overlays | `@bsv/overlay-topics` | `1.9.1` | node-library | node-esm | node | `>=22` | [packages/overlays/topics](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/overlays/topics) |
| sdk | `@bsv/sdk` | `2.8.8` | browser-library | browser-bundler, browser-esm, node-cjs, node-esm, umd-global | browser, node, umd | `>=22` | [packages/sdk](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/sdk) |
| sdk | `@bsv/sdk` | `2.8.9` | browser-library | browser-bundler, browser-esm, node-cjs, node-esm, umd-global | browser, node, umd | `>=22` | [packages/sdk](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/sdk) |
| sdk | `@bsv/verifast` | `0.3.6` | wasm-library | browser-bundler, browser-esm, node-cjs, node-esm, umd-global, wasm-worker | browser, node, umd, wasm, worker | `>=22` | [packages/verifast](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/verifast) |
| wallet | `@bsv/btms` | `1.2.3` | node-library | node-cjs, node-esm | node | `>=22` | [packages/wallet/btms](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/btms) |
| wallet | `@bsv/btms-permission-module` | `1.2.1` | node-library | node-esm | node | `>=22` | [packages/wallet/btms-permission-module](https://github.com/bsv-blockchain/ts-stack/tree/main/packages/wallet/btms-permission-module) |
Expand Down
6 changes: 3 additions & 3 deletions governance/package-release-notes.json
Original file line number Diff line number Diff line change
Expand Up @@ -166,10 +166,10 @@
},
{
"name": "@bsv/sdk",
"publishedVersion": "2.8.7",
"publishedVersion": "2.8.8",
"releaseType": "patch",
"summary": "Aligns explicit Script verification with bitcoin-sv coin-era, Chronicle version, locktime, sequence, signature-hash and numeric rules, including original-digest serialization. Rejects node-invalid OP_NUM2BIN sizes and checks an optional local memory budget before allocation.",
"migration": "No API, wire or wallet-data migration. Omitting memoryLimit continues to leave local allocation unbounded. The default JavaScript interpreter still lacks block and coin heights and is not an exact node consensus validator. OP_NUM2BIN rejects sizes above the node's signed 32-bit limit before allocation; an optional finite memoryLimit bounds otherwise permitted local work before allocation. Resource exhaustion does not establish script invalidity. Published 2.8.7 remains the registry baseline until protected release."
"summary": "Aligns explicit Script verification with bitcoin-sv coin-era, Chronicle version, locktime, sequence, signature-hash and numeric rules, including original-digest serialization. Rejects node-invalid OP_NUM2BIN sizes and checks an optional local memory budget before allocation. AuthFetch retains a finite general payload budget matching HTTP request and configured response capacity, allowing full 4 MiB CHIRP chunks without charging their JSON expansion against the generic envelope budget. Existing HTTP, handshake, certificate, nonce, signature and redirect limits remain enforced.",
"migration": "No API, wire or wallet-data migration. Omitting memoryLimit continues to leave local allocation unbounded. The default JavaScript interpreter still lacks block and coin heights and is not an exact node consensus validator. OP_NUM2BIN rejects sizes above the node's signed 32-bit limit before allocation; an optional finite memoryLimit bounds otherwise permitted local work before allocation. Resource exhaustion does not establish script invalidity. Published 2.8.8 is the registry baseline; source 2.8.9 remains a candidate until protected release. Update applications using full-size authenticated binary uploads to SDK 2.8.9. No API, wire or wallet-data migration is required; custom Peer transports retain their existing default policy."
},
{
"name": "@bsv/simple",
Expand Down
2 changes: 1 addition & 1 deletion governance/repository-health/baselines.json
Original file line number Diff line number Diff line change
Expand Up @@ -322,7 +322,7 @@
"@bsv/overlay-discovery-services": "2.2.6",
"@bsv/overlay-express": "2.7.3",
"@bsv/overlay-topics": "1.9.1",
"@bsv/sdk": "2.8.8",
"@bsv/sdk": "2.8.9",
"@bsv/verifast": "0.3.6",
"@bsv/btms": "1.2.3",
"@bsv/btms-permission-module": "1.2.1",
Expand Down
Loading
Loading