[Snyk] Upgrade stellar-sdk from 10.4.1 to 12.0.0 #17
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.
![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)
Snyk has created this PR to upgrade stellar-sdk from 10.4.1 to 12.0.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 18 versions ahead of your current version.
The recommended version was released on 24 days ago.
Release notes
Package name: stellar-sdk
Added
ContractClient
: generate a class from the contract specification where each Rust contract method gets a matching method in this class. Each method returns anAssembledTransaction
that can be used to modify, simulate, decode results, and possibly sign, & submit the transaction.AssembledTransaction
: used to wrap a transaction-under-construction and provide high-level interfaces to the most common workflows, while still providing access to low-level transaction manipulation.SentTransaction
: transaction sent to the Soroban network, in two steps - initial submission and waiting for it to finalize to get the result (retried with exponential backoff)Fixed
@ stellar/js-xdr
which should broaden compatibility to pre-ES2016 environments (#932, #930).SorobanRpc.Server
will no longer use array-based passing to invoke JSON-RPC methods (#924).Full Changelog: v11.2.2...v11.3.0
Fixed
@ stellar/stellar-base
has been upgraded to its latest major version (#918, see v11.0.0 for release notes).Full Changelog: v11.2.1...v11.2.2
Fixed
stellar-base@v10.0.2
for release notes, #913).Added
diagnosticEventsXdr
field on theSorobanRpc.Server.sendTransaction
method. The raw field will be present when using the_sendTransaction
method, while the normal method will have an already-parseddiagnosticEvents: xdr.DiagnosticEvent[]
field, instead (#905).SorobanRpc.Api.EventResponse
so that developers can type-check individual events (#904).Updated
Added
SorobanRpc.Server.simulateTransaction
now supports an optionaladdlResources
parameter to allow users to specify additional resources that they want to include in a simulation (#896).ContractSpec
now has ajsonSchema()
method to generate a JSON Schema for a particular contract specification (#889).Fixed
stellar-base
to v10.0.1 which included a small patch (#897).New Contributors
Full Changelog: v11.0.1...v11.1.0
This is a hotfix on the major v11 release, see that for the full release notes.
Fixed
SorobanRpc.Server.getEvents
uses the correct type for the start ledger (#890).This is the stable Protocol 20 release.
v11.0.0: Protocol 20, Soroban!
Breaking Changes
@ stellar/stellar-sdk
.soroban-client
library (stellar/js-soroban-client) has been merged into this package, causing significant breaking changes in the module structure (#860):TransactionBuilder
) are still in the top level, Horizon-specific interactions are in theHorizon
namespace (i.e.Server
is nowHorizon.Server
), and new Soroban RPC interactions are in theSorobanRpc
namespace.SorobanRpc.Server.prepareTransaction
andSorobanRpc.assembleTransaction
methods no longer need an optionalnetworkPassphrase
parameter, because it is implicitly part of the transaction already (#870).DepositLiquidityEffect
->LiquidityPoolDeposited
WithdrawLiquidityEffect
->LiquidityPoolWithdrew
LiquidityPoolTradeEffect
->LiquidityPoolTrade
LiquidityPoolCreatedEffect
->LiquidityPoolCreated
LiquidityPoolRevokedEffect
->LiquidityPoolRevoked
LiquidityPoolRemovedEffect
->LiquidityPoolRemoved
Added
ContractCredited
occurs when a Stellar asset moves into its corresponding Stellar Asset Contract instanceContractDebited
occurs when a Stellar asset moves out of its corresponding Stellar Asset Contract instanceServerApi.AssetRecord
) contain two new fields to support the Protocol 20 (Soroban) release (#841):num_contracts
- the integer quantity of contracts that hold this assetcontracts_amount
- the total units of that asset held by contractsinvokeHostFunction
: seeHorizon.InvokeHostFunctionOperationResponse
bumpFootprintExpiration
: seeHorizon.BumpFootprintExpirationOperationResponse
restoreFootprint
: seeHorizon.RestoreFootprintOperationResponse
Updated
stellar-base
has been updated to its corresponding overhaul (#818).lodash
: #822,es6-promise
: #823, polyfills: #825,detect-node
: #831).stellar-base
library has been upgraded to support the latest Protocol 20 XDR schema and all Soroban functionality (#861).Fixed
ClaimableBalanceClawedBack
is now definedtype EffectRecord
now has all of the effect typesPaymentCallBuilder
was incorrectly indicating that it would return a collection ofPayment
records, while in reality it can return a handful of "payment-like" records (#885).New Contributors
Full Changelog: v10.4.1...v11.0.0
Fixed
stellar-base
library has been upgraded tobeta.4
which contains a bugfix for large sequence numbers (#877).SorobanRpc.Server.getTransaction()
method will now return the full response when encountering aFAILED
transaction result (#872).SorobanRpc.Server.getEvents()
method will correctly parse the event value (which is anxdr.ScVal
rather than anxdr.DiagnosticEvent
, see the modifiedSorobanRpc.Api.EventResponse.value
; #876).Full Changelog: v10.4.1...v11.0.0-beta.5
v11.0.0-beta.5
Breaking Changes
soroban-client
library (stellar/js-soroban-client) has been merged into this package, causing significant breaking changes in the module structure (#860):TransactionBuilder
) are still in the top level, Horizon-specific interactions are in theHorizon
namespace (i.e.Server
is nowHorizon.Server
), and new Soroban RPC interactions are in theSorobanRpc
namespace.SorobanRpc.Server.prepareTransaction
andSorobanRpc.assembleTransaction
methods no longer need an optionalnetworkPassphrase
parameter, because it is implicitly part of the transaction already (#870).Full Changelog: v10.4.1...v11.0.0-beta.5
Fixed
stellar-base
dependency has been pinned to a specific version to avoid incorrect semver resolution (#867).Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: