Repository navigation
0.7.0 (7/7): MPP-01's network, README and site, release 0.7.0 - #10
Merged
Merged
Conversation
The unreleased 0.7.0 cycle had left five evidence files dated 2026-10-05 and one dated 2026-10-06. Each date now has one file, 2026-10-05-0.7.0-verification-runs.md and 2026-10-06-0.7.0-verification-runs.md, opening with a table of its parts (what each checks, and its outcome) and then the parts in the order they were run, each naming its own commits and targets: Base Sepolia, the three negative checks, Solana devnet, the payer balance read, and the wallet and serve additions on the 5th; Ethereum Sepolia, the client's spend cap and named settlement failures on the 6th. The date, environment and authorization statement are said once per file. Nothing in the runs themselves changed. Every link to the old files (CHANGELOG, CHECKS.md, the CLI guide, the core README, the evidence index) now points at the part it meant, and each link and anchor was checked to resolve. Files already published on main keep their names, since links to them have been sent. A public test comment that named a local, unpublished run record now names the evidence instead. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The CLI demo on the homepage played a 0.6.0 run: seven checks, X402-07 refused with a bare 402. It now plays a real 10/10 run of the 0.7.0 branch against Wasit's own Stellar fixture (2026-10-06), copied line by line: X402-06's settlement and transaction, and X402-07..10 each refused with its reason. Texts that said Stellar alone now say what 0.7.0 does, Stellar first: the homepage's settlement row, the "never trusts the receipt" note and the FAQ on safety; the docs overview; the Requirements page, whose note also claimed there was no mainnet mode at all although stellar:pubnet pays when given an explicit --rpc-url, and whose table now covers X402-06..10 on each chain; the Quick setup page, which said `wasit wallet` had no --network and now shows it for Base Sepolia, Ethereum Sepolia and Solana devnet; and SECURITY.md's testnet section, rendered on the site. The hero's one-line description is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
MPP-01 read the amount, currency and recipient from the target's challenge, never its network. The SDK's charge client signs for the network the challenge names (resolveNetworkId in @stellar/mpp 0.7.1), through its own default RPC endpoint for that network, pubnet included. A target asking for stellar:pubnet could therefore have a mainnet transfer signed by the payer key. The network is now read the way the SDK reads it (none means testnet), and a challenge for any network but the run's is refused before anything is signed, as ERROR (configuration). The check runs twice: on the unpaid read, and on the exact challenge about to be signed, since mppx requests the target again and pays whatever that answer carries. A network that is not stellar:testnet or stellar:pubnet fails. The payment also goes through the run's RPC endpoint instead of the SDK's default, and the SDK's client cannot reach an http endpoint, so an http one is refused before anything is sent rather than reported as the target's failure. And it is made once: mppx paid up to three times (maxPaymentRetries, default 3) when a target kept answering 402. Tested offline against the official charge server in process; each rule was broken on purpose and a test failed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The check catalogue, the security policy, the scope boundary, the agent skill and the MCP tool description now say that a target cannot choose the network: MPP-01 refuses a challenge for any network but the run's before anything is signed. The --rpc-url rows say the payment uses the endpoint too, https only. The changelog records the fix and what the previous behaviour was, read from the SDK's source. Evidence for 2026-10-08: an honest testnet target passes with the settlement read back, a target asking for stellar:pubnet gets no verdict and no credential, and each rule broken on purpose fails a test. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The command's one-line description still said Stellar testnet wallets, while its subcommands take --network for Base Sepolia, Ethereum Sepolia and Solana devnet, where they manage the x402 payer. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The README described 0.6.0: Stellar only, thirteen checks, four fixtures, five subcommands, and a passing run of seven checks. It now says what 0.7.0 does: x402 on Stellar testnet, Base Sepolia, Ethereum Sepolia and Solana devnet, MPP on Stellar, sixteen checks, the eight fixtures and what each needs in .env, wasit serve and wallet --network, and example output from a 0.7.0 run, a pass and a failure with its Fix line. The CLI and MCP captures of 0.6.0 at the top are gone, and with them the paragraph about them: the release video covers that, and the files stay in docs/media for the evidence that links them. The link to the channel-mode note pointed at an anchor that never existed; it now opens the section the note is in. The roadmap item about a third-party run was already done, as the Status table says; it gives way to BNB Smart Chain testnet payments. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The hero, the page description, the docs overview and the legal pages called Wasit a tester for x402 and MPP on Stellar, and the stack strip said it trusts one chain. Since 0.7.0 the x402 payment checks also pay on Base Sepolia, Ethereum Sepolia and Solana devnet. The hero now says x402 on Stellar, Base, Ethereum and Solana testnets and MPP on Stellar, settlement read from the chain's own record of the transfer; the ticker lists the four chains; the stack strip trusts only the chain, with the x402 chains named in Stellar's cell. The terms page's description of the service changes, so its date does too. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
All three packages move to 0.7.0, the CLI and the MCP server depending on core ^0.7.0, and the CHANGELOG's Unreleased section becomes the dated 0.7.0 entry, opening with a summary and what can change on upgrade. SECURITY.md's count of advisories in a clean install was out of date. On the 0.7.0 tarballs it is nine packages, eight high and one moderate (the CLI alone eight), because axios advisories published since 0.6.0 now match axios 1.18.0, which @stellar/stellar-sdk 16.3.1 pins; no 16.x release moves past it, and @x402/stellar 2.28.0 requires ^16.3.0. It also says that 0.7.0 has no advisory of its own, while earlier versions have MPP-01's network issue. The evidence index names 0.7.0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Part 2 of the 2026-10-08 file: the release commit's packages installed as a user gets them, every suite against every fixture with each settlement read back from its chain by hand, and wasit serve's lying modes on Stellar testnet and Base Sepolia. The Permit2 suite's first run failed at the public facilitator's broadcast, the intermittent failure recorded on 2026-10-06; its second run passed and is the settlement read back. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 7 of 7 of 0.7.0, which is on npm since 2026-10-08. The PRs follow the release branch's commit order and are merged with merge commits, so every commit keeps its hash.
What changes
MPP-01signs only for the network the run names, through the run's RPC endpoint, and pays once.wasit wallet's help names every testnet; the README describes 0.7.0.chore(release): 0.7.0.Commits
10d98e2docs(evidence): one file per date for the 0.7.0 runsde8df7adocs(site): the site and the security policy match 0.7.05f0d8b2fix(core): MPP-01 signs only for the run's network, and pays once15e45bfdocs: MPP-01 pays only on the run's network, through its RPC, onced529603fix(cli): wasit wallet's help names every testnet it coverscb067d1docs(readme): 0.7.0, without the 0.6.0 capturesfa9ebc5feat(site): say where each protocol is tested, not "on Stellar" aloned18a9ddchore(release): 0.7.00cf2310docs(evidence): the 0.7.0 release build on every chainVerification
Unit tests and the clean install run in CI.
MPP-01's network and the full release run, every suite on every chain with each settlement read back, are indocs/evidence/2026-10-08-0.7.0-verification-runs.md.🤖 Generated with Claude Code