From fb8c8cfd8e5f7c373d933aa25373d22c6d0b4849 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Sep 2026 09:16:35 +0000 Subject: [PATCH 1/3] chore(deps): bump the noble-scure-crypto group across 1 directory with 5 updates Bumps the noble-scure-crypto group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@noble/curves](https://github.com/paulmillr/noble-curves) | `2.2.0` | `2.4.0` | | [@noble/hashes](https://github.com/paulmillr/noble-hashes) | `2.2.0` | `2.4.0` | | [@scure/base](https://github.com/paulmillr/scure-base) | `2.2.0` | `2.4.0` | | [@scure/bip32](https://github.com/paulmillr/scure-bip32) | `2.2.0` | `2.4.0` | | [@scure/bip39](https://github.com/paulmillr/scure-bip39) | `2.2.0` | `2.4.0` | Updates `@noble/curves` from 2.2.0 to 2.4.0 - [Release notes](https://github.com/paulmillr/noble-curves/releases) - [Changelog](https://github.com/paulmillr/noble-curves/blob/main/CHANGELOG.md) - [Commits](https://github.com/paulmillr/noble-curves/compare/2.2.0...2.4.0) Updates `@noble/hashes` from 2.2.0 to 2.4.0 - [Release notes](https://github.com/paulmillr/noble-hashes/releases) - [Changelog](https://github.com/paulmillr/noble-hashes/blob/main/CHANGELOG.md) - [Commits](https://github.com/paulmillr/noble-hashes/compare/2.2.0...2.4.0) Updates `@scure/base` from 2.2.0 to 2.4.0 - [Release notes](https://github.com/paulmillr/scure-base/releases) - [Changelog](https://github.com/paulmillr/scure-base/blob/main/CHANGELOG.md) - [Commits](https://github.com/paulmillr/scure-base/compare/2.2.0...2.4.0) Updates `@scure/bip32` from 2.2.0 to 2.4.0 - [Release notes](https://github.com/paulmillr/scure-bip32/releases) - [Changelog](https://github.com/paulmillr/scure-bip32/blob/main/CHANGELOG.md) - [Commits](https://github.com/paulmillr/scure-bip32/compare/2.2.0...2.4.0) Updates `@scure/bip39` from 2.2.0 to 2.4.0 - [Release notes](https://github.com/paulmillr/scure-bip39/releases) - [Changelog](https://github.com/paulmillr/scure-bip39/blob/main/CHANGELOG.md) - [Commits](https://github.com/paulmillr/scure-bip39/compare/2.2.0...2.4.0) --- updated-dependencies: - dependency-name: "@noble/curves" dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: noble-scure-crypto - dependency-name: "@noble/hashes" dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: noble-scure-crypto - dependency-name: "@scure/base" dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: noble-scure-crypto - dependency-name: "@scure/bip32" dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: noble-scure-crypto - dependency-name: "@scure/bip39" dependency-version: 2.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: noble-scure-crypto ... Signed-off-by: dependabot[bot] --- pnpm-lock.yaml | 89 +++++++++++++++++++++++++++----------------------- 1 file changed, 48 insertions(+), 41 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 5ec80489..2c82d463 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -244,19 +244,19 @@ importers: dependencies: '@noble/curves': specifier: ^2.0.1 - version: 2.2.0 + version: 2.4.0 '@noble/hashes': specifier: ^2.2.0 - version: 2.2.0 + version: 2.4.0 '@scure/base': specifier: ^2.0.0 - version: 2.2.0 + version: 2.4.0 '@scure/bip32': specifier: ^2.0.1 - version: 2.2.0 + version: 2.4.0 '@scure/bip39': specifier: ^2.0.1 - version: 2.2.0 + version: 2.4.0 effect: specifier: ^3.21.1 version: 3.21.2 @@ -299,7 +299,7 @@ importers: version: link:../scalus-uplc '@noble/hashes': specifier: ^2.2.0 - version: 2.2.0 + version: 2.4.0 dockerode: specifier: ^5.0.0 version: 5.0.1 @@ -1392,16 +1392,16 @@ packages: '@nicolo-ribaudo/chokidar-2@2.1.8-no-fsevents.3': resolution: {integrity: sha512-s88O1aVtXftvp5bCPB7WnmXc5IwOZZ7YPuwNPt+GtOOXpPvad1LfbmjYv+qII7zP6RU2QGnqve27dnLycEnyEQ==} - '@noble/curves@2.2.0': - resolution: {integrity: sha512-T/BoHgFXirb0ENSPBquzX0rcjXeM6Lo892a2jlYJkqk83LqZx0l1Of7DzlKJ6jkpvMrkHSnAcgb5JegL8SeIkQ==} + '@noble/curves@2.4.0': + resolution: {integrity: sha512-P4/62zrgfH33CneE3Dn4WhJVA22YUU0eR51wKIan4NVRvwsA0YnPTwWGpNbpuacSujmSFLvyzpyuR30+fbq2Ew==} engines: {node: '>= 20.19.0'} '@noble/hashes@1.8.0': resolution: {integrity: sha512-jCs9ldd7NwzpgXDIf6P3+NrHh9/sD6CQdxHyjQI+h/6rDNo88ypBxxz45UDuZHz9r3tNz7N/VInSVoVdtXEI4A==} engines: {node: ^14.21.3 || >=16} - '@noble/hashes@2.2.0': - resolution: {integrity: sha512-IYqDGiTXab6FniAgnSdZwgWbomxpy9FtYvLKs7wCUs2a8RkITG+DFGO1DM9cr+E3/RgADRpFjrKVaJ1z6sjtEg==} + '@noble/hashes@2.4.0': + resolution: {integrity: sha512-X5XaVWZIBCT7HHZGm5I7ZQXDwLG+bGXuSrMQAW+7Zvl87h1kmc1ZB1VSRJcpUfoUrGQp4Fkoxm5kZ+Ms+aW+eA==} engines: {node: '>= 20.19.0'} '@nodelib/fs.scandir@2.1.5': @@ -2298,14 +2298,14 @@ packages: '@rtsao/scc@1.1.0': resolution: {integrity: sha512-zt6OdqaDoOnJ1ZYsCYGt9YmWzDXl4vQdKTyJev62gFhRGKdx7mcT54V9KIjg+d2wi9EXsPvAPKe7i7WjfVWB8g==} - '@scure/base@2.2.0': - resolution: {integrity: sha512-b8XEupJibegiXV+tDUseI8oLQc8ei3d/4Jkb2RpbHh3MfE054ov3uIz2dhFkB3FI8iwYkEh0gGCApkrYggkPNg==} + '@scure/base@2.4.0': + resolution: {integrity: sha512-thZ1TuJwFwBblOhgsjDKvvGirBxNp+wSvY/DR6tJBJOTDhdAAcHJ8Vbr2eFnqaxeca4+t0i9KBf+uHYGWwZORg==} - '@scure/bip32@2.2.0': - resolution: {integrity: sha512-zFr7t2F+a9+5tB7QbarF2HQNYrgjCNaoLAupZdKkrFMYMozJf5zqH2WJCQibMzm1qQ0QogrxVGO3qXfQDYMaQg==} + '@scure/bip32@2.4.0': + resolution: {integrity: sha512-i3DS0CptAocyvqE4n3SUkpzeQK4vJMFwWLofTwRiiKo2aWojBOfyMCgfKw9HVpO6fSY5AK86sHS/Uzn8kK9Few==} - '@scure/bip39@2.2.0': - resolution: {integrity: sha512-T/Bj/YvYMNkIPq6EENO6/rcs2e7qTNuyoUXf0KBFDmp0ZDu0H2X4Lq6yC3i0c8PcWkov5EbW+yQZZbdMmk154A==} + '@scure/bip39@2.4.0': + resolution: {integrity: sha512-82dxFbZUYboyOf0AXiydsQrFQ5Q4h9mX+O2UkE91ROYmsc0BKMGZLwDmy96Jpa2+vrtoxomjUhy1RPIgH/r2nA==} '@shikijs/core@3.23.0': resolution: {integrity: sha512-NSWQz0riNb67xthdm5br6lAkvpDJRTgB36fxlo37ZzM2yq0PQFFzbd8psqC2XMPgCzo1fW6cVi18+ArJ44wqgA==} @@ -4514,6 +4514,10 @@ packages: resolution: {integrity: sha512-evOr8xfXKxE6qSR0hSXL2r3sd7ALj8+7jQEUvPYcm5sgZFdJ+AYzT6yNmJenvIYQBgIGwfwz08sL8zoL7yq2BA==} engines: {node: '>= 0.4'} + is-core-module@2.17.0: + resolution: {integrity: sha512-J/vG0zBCbIKOQFfufSwyXdMrsohyJIUNkrnmo6WZGzoM7tr/lsbfW5b2BvisL6zsyMzK9UxV9L6c7AoFbyXHOA==} + engines: {node: '>= 0.4'} + is-data-view@1.0.2: resolution: {integrity: sha512-RKtWF8pGmS87i2D6gqQu/l7EYRlVdfzemCJN/P3UOs//x1QE7mfhvzHIApBTRf7axvT6DMGwSwBXYCT0nfB9xw==} engines: {node: '>= 0.4'} @@ -6242,8 +6246,8 @@ packages: resolution: {integrity: sha512-BaXgOuIxz8n8pIq3e7Atg/7s+DpiYrxn4vdot3w9KbnBhcRQq6o3xemQdIfynqSeXeDrF32x+WvfzmOjPiY9lg==} engines: {node: '>= 0.4'} - typed-array-byte-offset@1.0.4: - resolution: {integrity: sha512-bTlAFB/FBYMcuX81gbL4OcpH5PmlFHqlCCpAl8AlEzMz5k53oNDvN8p1PNOWLEmI2x4orp3raOFB51tv9X+MFQ==} + typed-array-byte-offset@1.0.5: + resolution: {integrity: sha512-0FHJvLPqZ7KJzp17O13jfsAjsqazgrxBu2zEK95PmUz8lv2+GjRuxUInCr2Rk9Dms3ihN21zJ929ZO43yJ95QQ==} engines: {node: '>= 0.4'} typed-array-length@1.0.8: @@ -6482,8 +6486,8 @@ packages: resolution: {integrity: sha512-K4jVyjnBdgvc86Y6BkaLZEN933SwYOuBFkdmBu9ZfkcAbdVbpITnDmjvZ/aQjRXQrv5EPkTnD1s39GiiqbngCw==} engines: {node: '>= 0.4'} - which-typed-array@1.1.22: - resolution: {integrity: sha512-fvO4ExWMFsqyhG3AiPAObMuY1lxaqgYcxbc49CNdWDDECOJNgQyvsOWVwbZc+qf3rzRtxojBK+CMEv0Ld5CYpw==} + which-typed-array@1.1.24: + resolution: {integrity: sha512-wk4Mf4pR5mRP7eYuuTBCIQ9d0ud2Fv2jRLQpfgnRjbOxAFHmjKFValgTpitVKzJJS8ajnYQV2Du1SZ8j6b/EUQ==} engines: {node: '>= 0.4'} which@2.0.2: @@ -7681,13 +7685,13 @@ snapshots: '@nicolo-ribaudo/chokidar-2@2.1.8-no-fsevents.3': optional: true - '@noble/curves@2.2.0': + '@noble/curves@2.4.0': dependencies: - '@noble/hashes': 2.2.0 + '@noble/hashes': 2.4.0 '@noble/hashes@1.8.0': {} - '@noble/hashes@2.2.0': {} + '@noble/hashes@2.4.0': {} '@nodelib/fs.scandir@2.1.5': dependencies: @@ -8474,18 +8478,17 @@ snapshots: '@rtsao/scc@1.1.0': optional: true - '@scure/base@2.2.0': {} + '@scure/base@2.4.0': {} - '@scure/bip32@2.2.0': + '@scure/bip32@2.4.0': dependencies: - '@noble/curves': 2.2.0 - '@noble/hashes': 2.2.0 - '@scure/base': 2.2.0 + '@noble/curves': 2.4.0 + '@noble/hashes': 2.4.0 + '@scure/base': 2.4.0 - '@scure/bip39@2.2.0': + '@scure/bip39@2.4.0': dependencies: - '@noble/hashes': 2.2.0 - '@scure/base': 2.2.0 + '@noble/hashes': 2.4.0 '@shikijs/core@3.23.0': dependencies: @@ -10095,10 +10098,10 @@ snapshots: string.prototype.trimstart: 1.0.8 typed-array-buffer: 1.0.3 typed-array-byte-length: 1.0.3 - typed-array-byte-offset: 1.0.4 + typed-array-byte-offset: 1.0.5 typed-array-length: 1.0.8 unbox-primitive: 1.1.0 - which-typed-array: 1.1.22 + which-typed-array: 1.1.24 optional: true es-define-property@1.0.1: @@ -10205,7 +10208,7 @@ snapshots: eslint-import-resolver-node@0.3.10: dependencies: debug: 3.2.7 - is-core-module: 2.16.2 + is-core-module: 2.17.0 resolve: 2.0.0-next.7 transitivePeerDependencies: - supports-color @@ -10270,7 +10273,7 @@ snapshots: eslint-import-resolver-node: 0.3.10 eslint-module-utils: 2.14.0(@typescript-eslint/parser@8.69.0(eslint@10.10.0(jiti@2.7.0))(typescript@6.0.3))(eslint-import-resolver-node@0.3.10)(eslint-import-resolver-typescript@4.4.5(eslint-plugin-import-x@4.17.1(@typescript-eslint/utils@8.69.0(eslint@10.10.0(jiti@2.7.0))(typescript@6.0.3))(eslint-import-resolver-node@0.3.10)(eslint@10.10.0(jiti@2.7.0)))(eslint-plugin-import@2.32.0)(eslint@10.10.0(jiti@2.7.0)))(eslint@10.10.0(jiti@2.7.0)) hasown: 2.0.4 - is-core-module: 2.16.2 + is-core-module: 2.17.0 is-glob: 4.0.3 minimatch: 3.1.5 object.fromentries: 2.0.8 @@ -11067,6 +11070,11 @@ snapshots: dependencies: hasown: 2.0.3 + is-core-module@2.17.0: + dependencies: + hasown: 2.0.4 + optional: true + is-data-view@1.0.2: dependencies: call-bound: 1.0.4 @@ -11184,7 +11192,7 @@ snapshots: is-typed-array@1.1.15: dependencies: - which-typed-array: 1.1.22 + which-typed-array: 1.1.24 optional: true is-unicode-supported@0.1.0: {} @@ -12677,7 +12685,7 @@ snapshots: resolve@2.0.0-next.7: dependencies: es-errors: 1.3.0 - is-core-module: 2.16.2 + is-core-module: 2.17.0 node-exports-info: 1.6.2 object-keys: 1.1.1 path-parse: 1.0.7 @@ -13197,13 +13205,12 @@ snapshots: is-typed-array: 1.1.15 optional: true - typed-array-byte-offset@1.0.4: + typed-array-byte-offset@1.0.5: dependencies: available-typed-arrays: 1.0.7 call-bind: 1.0.9 for-each: 0.3.5 gopd: 1.2.0 - has-proto: 1.2.0 is-typed-array: 1.1.15 reflect.getprototypeof: 1.0.10 optional: true @@ -13449,7 +13456,7 @@ snapshots: isarray: 2.0.5 which-boxed-primitive: 1.1.1 which-collection: 1.0.2 - which-typed-array: 1.1.22 + which-typed-array: 1.1.24 optional: true which-collection@1.0.2: @@ -13460,7 +13467,7 @@ snapshots: is-weakset: 2.0.4 optional: true - which-typed-array@1.1.22: + which-typed-array@1.1.24: dependencies: available-typed-arrays: 1.0.7 call-bind: 1.0.9 From c4b658c3ac0ba5ac21e90da77f0363fc2b19266c Mon Sep 17 00:00:00 2001 From: solidsnakedev Date: Thu, 1 Oct 2026 14:24:27 -0600 Subject: [PATCH 2/3] fix(bech32): decode strings longer than 90 characters --- packages/evolution/src/Bech32.ts | 2 +- packages/evolution/test/Bech32.test.ts | 16 ++++++++++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 packages/evolution/test/Bech32.test.ts diff --git a/packages/evolution/src/Bech32.ts b/packages/evolution/src/Bech32.ts index 18103b69..83aa8a7c 100644 --- a/packages/evolution/src/Bech32.ts +++ b/packages/evolution/src/Bech32.ts @@ -9,7 +9,7 @@ export const FromBytes = (prefix: string = "addr") => strict: true, encode: (_, __, ast, toA) => Effect.try({ - try: () => bech32.decodeToBytes(toA).bytes, + try: () => bech32.decodeToBytes(toA, false).bytes, catch: () => new ParseResult.Type(ast, toA, ` ${toA} is not a valid Bech32 address`) }), decode: (_, __, ___, fromI) => { diff --git a/packages/evolution/test/Bech32.test.ts b/packages/evolution/test/Bech32.test.ts new file mode 100644 index 00000000..a0b4aaaa --- /dev/null +++ b/packages/evolution/test/Bech32.test.ts @@ -0,0 +1,16 @@ +import { Schema } from "effect" +import { describe, expect, it } from "vitest" + +import * as Bech32 from "../src/Bech32.js" + +// A base address is 108 characters, longer than the 90-character BIP-173 default limit +const BASE_ADDRESS = + "addr_test1qpw0djgj0x59ngrjvqthn7enhvruxnsavsw5th63la3mjel3tkc974sr23jmlzgq5zda4gtv8k9cy38756r9y3qgmkqqjz6aa7" + +describe("Bech32", () => { + it("decodes a base address longer than 90 characters", () => { + const bytes = Schema.encodeSync(Bech32.FromBytes("addr_test"))(BASE_ADDRESS) + expect(bytes.length).toBe(57) + expect(Schema.decodeSync(Bech32.FromBytes("addr_test"))(bytes)).toBe(BASE_ADDRESS) + }) +}) From ebc96cee577efcb23718e9f4d5b000976cf349b3 Mon Sep 17 00:00:00 2001 From: solidsnakedev Date: Thu, 1 Oct 2026 14:24:27 -0600 Subject: [PATCH 3/3] release: changeset for bech32 long strings --- .changeset/bech32-long-strings.md | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 .changeset/bech32-long-strings.md diff --git a/.changeset/bech32-long-strings.md b/.changeset/bech32-long-strings.md new file mode 100644 index 00000000..3a772f47 --- /dev/null +++ b/.changeset/bech32-long-strings.md @@ -0,0 +1,5 @@ +--- +"@evolution-sdk/evolution": patch +--- + +`Bech32.FromBytes` failed on strings longer than 90 characters, such as base addresses, when `@scure/base` 2.4 or later was installed. That version made `bech32.decodeToBytes` enforce the 90-character BIP-173 limit by default, and the SDK called it without a limit. It now passes no limit, as every other bech32 decode in the SDK already does.