Skip to content

0.7.0 (7/7): MPP-01's network, README and site, release 0.7.0 - #10

Merged
dzakwannajmi merged 9 commits into
mainfrom
0.7.0/7-evidence-site-release
Oct 8, 2026
Merged

dzakwannajmi merged 9 commits into
mainfrom
0.7.0/7-evidence-site-release

Conversation

@dzakwannajmi

Copy link
Copy Markdown
Collaborator

Part 7 of 7 of 0.7.0, which is on npm since 2026-10-08. The PRs follow the release branch's commit order and are merged with merge commits, so every commit keeps its hash.

What changes

  • The 0.7.0 evidence, one file per date.
  • The site and the security policy match 0.7.0; the hero says where each protocol is tested.
  • MPP-01 signs only for the network the run names, through the run's RPC endpoint, and pays once.
  • wasit wallet's help names every testnet; the README describes 0.7.0.
  • chore(release): 0.7.0.

Commits

  • 10d98e2 docs(evidence): one file per date for the 0.7.0 runs
  • de8df7a docs(site): the site and the security policy match 0.7.0
  • 5f0d8b2 fix(core): MPP-01 signs only for the run's network, and pays once
  • 15e45bf docs: MPP-01 pays only on the run's network, through its RPC, once
  • d529603 fix(cli): wasit wallet's help names every testnet it covers
  • cb067d1 docs(readme): 0.7.0, without the 0.6.0 captures
  • fa9ebc5 feat(site): say where each protocol is tested, not "on Stellar" alone
  • d18a9dd chore(release): 0.7.0
  • 0cf2310 docs(evidence): the 0.7.0 release build on every chain

Verification

Unit tests and the clean install run in CI. MPP-01's network and the full release run, every suite on every chain with each settlement read back, are in docs/evidence/2026-10-08-0.7.0-verification-runs.md.

🤖 Generated with Claude Code

dzakwannajmi and others added 9 commits October 6, 2026 00:51
The unreleased 0.7.0 cycle had left five evidence files dated
2026-10-05 and one dated 2026-10-06. Each date now has one file,
2026-10-05-0.7.0-verification-runs.md and
2026-10-06-0.7.0-verification-runs.md, opening with a table of its parts
(what each checks, and its outcome) and then the parts in the order they
were run, each naming its own commits and targets: Base Sepolia,
the three negative checks, Solana devnet, the payer balance read, and
the wallet and serve additions on the 5th; Ethereum Sepolia, the
client's spend cap and named settlement failures on the 6th. The date,
environment and authorization statement are said once per file. Nothing
in the runs themselves changed.

Every link to the old files (CHANGELOG, CHECKS.md, the CLI guide, the
core README, the evidence index) now points at the part it meant, and
each link and anchor was checked to resolve. Files already published on
main keep their names, since links to them have been sent. A public test
comment that named a local, unpublished run record now names the
evidence instead.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The CLI demo on the homepage played a 0.6.0 run: seven checks, X402-07
refused with a bare 402. It now plays a real 10/10 run of the 0.7.0
branch against Wasit's own Stellar fixture (2026-10-06), copied line by
line: X402-06's settlement and transaction, and X402-07..10 each refused
with its reason.

Texts that said Stellar alone now say what 0.7.0 does, Stellar first:
the homepage's settlement row, the "never trusts the receipt" note and
the FAQ on safety; the docs overview; the Requirements page, whose note
also claimed there was no mainnet mode at all although stellar:pubnet
pays when given an explicit --rpc-url, and whose table now covers
X402-06..10 on each chain; the Quick setup page, which said `wasit
wallet` had no --network and now shows it for Base Sepolia, Ethereum
Sepolia and Solana devnet; and SECURITY.md's testnet section, rendered
on the site.

The hero's one-line description is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
MPP-01 read the amount, currency and recipient from the target's
challenge, never its network. The SDK's charge client signs for the
network the challenge names (resolveNetworkId in @stellar/mpp 0.7.1),
through its own default RPC endpoint for that network, pubnet included.
A target asking for stellar:pubnet could therefore have a mainnet
transfer signed by the payer key.

The network is now read the way the SDK reads it (none means testnet),
and a challenge for any network but the run's is refused before
anything is signed, as ERROR (configuration). The check runs twice: on
the unpaid read, and on the exact challenge about to be signed, since
mppx requests the target again and pays whatever that answer carries.
A network that is not stellar:testnet or stellar:pubnet fails.

The payment also goes through the run's RPC endpoint instead of the
SDK's default, and the SDK's client cannot reach an http endpoint, so
an http one is refused before anything is sent rather than reported as
the target's failure. And it is made once: mppx paid up to three times
(maxPaymentRetries, default 3) when a target kept answering 402.

Tested offline against the official charge server in process; each
rule was broken on purpose and a test failed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The check catalogue, the security policy, the scope boundary, the agent
skill and the MCP tool description now say that a target cannot choose
the network: MPP-01 refuses a challenge for any network but the run's
before anything is signed. The --rpc-url rows say the payment uses the
endpoint too, https only. The changelog records the fix and what the
previous behaviour was, read from the SDK's source.

Evidence for 2026-10-08: an honest testnet target passes with the
settlement read back, a target asking for stellar:pubnet gets no
verdict and no credential, and each rule broken on purpose fails a test.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The command's one-line description still said Stellar testnet wallets,
while its subcommands take --network for Base Sepolia, Ethereum Sepolia
and Solana devnet, where they manage the x402 payer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The README described 0.6.0: Stellar only, thirteen checks, four fixtures,
five subcommands, and a passing run of seven checks. It now says what 0.7.0
does: x402 on Stellar testnet, Base Sepolia, Ethereum Sepolia and Solana
devnet, MPP on Stellar, sixteen checks, the eight fixtures and what each
needs in .env, wasit serve and wallet --network, and example output from a
0.7.0 run, a pass and a failure with its Fix line.

The CLI and MCP captures of 0.6.0 at the top are gone, and with them the
paragraph about them: the release video covers that, and the files stay in
docs/media for the evidence that links them. The link to the channel-mode
note pointed at an anchor that never existed; it now opens the section the
note is in. The roadmap item about a third-party run was already done, as
the Status table says; it gives way to BNB Smart Chain testnet payments.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The hero, the page description, the docs overview and the legal pages
called Wasit a tester for x402 and MPP on Stellar, and the stack strip said
it trusts one chain. Since 0.7.0 the x402 payment checks also pay on Base
Sepolia, Ethereum Sepolia and Solana devnet. The hero now says x402 on
Stellar, Base, Ethereum and Solana testnets and MPP on Stellar, settlement
read from the chain's own record of the transfer; the ticker lists the four
chains; the stack strip trusts only the chain, with the x402 chains named
in Stellar's cell. The terms page's description of the service changes, so
its date does too.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
All three packages move to 0.7.0, the CLI and the MCP server depending on
core ^0.7.0, and the CHANGELOG's Unreleased section becomes the dated 0.7.0
entry, opening with a summary and what can change on upgrade.

SECURITY.md's count of advisories in a clean install was out of date. On
the 0.7.0 tarballs it is nine packages, eight high and one moderate (the
CLI alone eight), because axios advisories published since 0.6.0 now match
axios 1.18.0, which @stellar/stellar-sdk 16.3.1 pins; no 16.x release moves
past it, and @x402/stellar 2.28.0 requires ^16.3.0. It also says that 0.7.0
has no advisory of its own, while earlier versions have MPP-01's network
issue. The evidence index names 0.7.0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Part 2 of the 2026-10-08 file: the release commit's packages installed as
a user gets them, every suite against every fixture with each settlement
read back from its chain by hand, and wasit serve's lying modes on Stellar
testnet and Base Sepolia. The Permit2 suite's first run failed at the
public facilitator's broadcast, the intermittent failure recorded on
2026-10-06; its second run passed and is the settlement read back.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
wasit Ready Ready Preview Oct 8, 2026 6:53am UTC

@dzakwannajmi
dzakwannajmi merged commit 0584d04 into main Oct 8, 2026
5 checks passed
@dzakwannajmi
dzakwannajmi deleted the 0.7.0/7-evidence-site-release branch October 8, 2026 06:55

This branch was successfully deployed

1 active deployment
Preview — 0cf2310d Deployed Oct 8, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant