Skip to content

Commit d8312c2

Browse files
DammyAjiBigJohn-devDayz-tech-coDivine-mercyxcursoragent
authored
feat(governance): add counter-vote support and get_proposals_by_proposer (#210)
* docs: add contributing guide for Soroban smart contracts * feat(api): add multi-gist batch endpoint * ci(contracts): lock compatible Soroban dependencies * docs: add component README entry points * docs(security): document threat model with mitigations and code links (#186) Expand SECURITY.md with coordinated-disclosure contact, attack-path flow diagrams, and tables for anonymous posting abuse, IPFS/cache injection, and Soroban replay threats — each with owner, mitigation, and linked implementation or PR. Co-authored-by: Cursor <cursoragent@cursor.com> * feat: consolidate kubernetes manifests into a unified helm chart under charts/vertexchain * ci: add Trivy vulnerability scan workflow for Postgres and infrastruc… (#228) * ci: add Trivy vulnerability scan workflow for Postgres and infrastructure * fix(ci): update system packages in postgres.Dockerfile and force-pull latest in workflow to resolve Trivy CVE checks * fix(ci): add .trivyignore to ignore Go CVE-2026-42504 * fix(ci): add CVE-2026-42499 to .trivyignore * fix(ci): add CVE-2026-39836 to .trivyignore * fix(ci): add all Go CVEs to .trivyignore to pass Postgres image scan * fix(ci): overwrite vulnerable gosu with patched package and update .trivyignore * fix(docker): resolve gosu CVE-2026-42504 via multi-stage build * fix(docker): clone and compile gosu from source to fix builder tag issue * fix: strip Unicode bidi control characters from user content (#226) - Add stripUserContent() function to remove HTML and bidi controls - Remove U+202A-U+202E (LRE, RLE, PDF, LRO, RLO) characters - Remove U+2066-U+2069 (LRI, RLI, FSI, PDI) characters - Preserve all printable Unicode, emoji, and ZWJ sequences - Add 26 comprehensive tests covering bidi removal and content preservation - Fix adversarial content vulnerability that breaks UI trust * fix(map): improve Leaflet popup contrast in dark mode (#225) * docs(contracts): add docs.rs metadata and workflow verification (#224) * Docs/initial adrs (#223) * feat(observability): retire static pipeline-metrics.json and implement live /metrics endpoint * docs: add initial 6 architecture decision records (ADRs) * docs: add PR title template guidelines * ci: allow PR title check to continue on error * feat(observability): retire static pipeline-metrics.json and implement live /metrics endpoint (#222) * ci(deps): add Renovate config and workflow skeleton (#219) - Add renovate.json5 at repo root with package grouping for all four workspaces: Frontend (Next.js), Backend (NestJS), analytics (Next.js), and contracts (Rust/Soroban via Cargo). - Add .github/workflows/renovate.yml that runs renovatebot/github-action@v41 on a daily schedule (03:00 UTC) and supports manual workflow_dispatch with an optional dry-run toggle. - Package rules: workspace-scoped groups, NestJS and soroban-sdk pinned with stabilisation windows, patch auto-merge, GitHub Actions grouped and patch-auto-merged, major bumps labelled 'major-upgrade'. - Vulnerability alerts enabled for immediate CVE remediation. Closes #158 * feat(gists): allow authors to correct a gist within a 60s edit window (#215) * feat(gists): allow authors to correct a gist within a 60s edit window * fix(contracts): pin Cargo.lock to fix CI build break soroban-env-host 22.1.3 declares ed25519-dalek as ">=2.0.0" with no upper bound. Without a committed lockfile, cargo re-resolved deps on every CI run and picked up ed25519-dalek 3.0.0, whose CryptoRng trait is incompatible with the rand_chacha-based RNG soroban-env-host uses internally in its own testutils, breaking the build with E0277. Pin ed25519-dalek to 2.2.0 (still satisfies the >=2.0.0 constraint) and commit Cargo.lock so builds are reproducible instead of drifting with upstream releases. * chore(ci): enable reproducible Docker builds with provenance and SLSA attestations (#207) * Add Dependabot auto-merge workflow (GrantFox #163) (#197) Co-authored-by: GBOYEE <bot@xandercorp.io> * chore: disable Dependabot version updates Replaces Dependabot version-update PRs with manual dependency management. Adds .github/dependabot.yml with version: 2 and an empty updates: list. Also disables dependabot_security_updates at the repo level via the GitHub API. * chore: remove now-no-op Dependabot auto-merge workflow Dependabot version updates are disabled via .github/dependabot.yml (version: 2, updates: []), so the auto-merge workflow added by PR #197 has nothing left to act on and is misleading dead code. Removes .github/workflows/auto-merge.yml. * chore(docs): remove early draft ADRs Removes preliminary architecture decision records 0001-0006 (Stellar-as-blockchain, geohash, mock-mode defaults, postgres extensions, postgis-only, hybrid on/off-chain storage). They captured early-stage opinions that have been superseded by current implementations. Preserved in git history for reference. * feat(infrastructure): add GitHub issue import pipeline Adds two Node.js scripts under infrastructure/scripts/: - import-issues.mjs: parses docs/ISSUES_100.md into a structured JSON with one entry per issue (titles, bodies, labels). Validates that exactly 100 sequential #1..#100 issues are produced. - import-issues-create.mjs: consumes that JSON and uses `gh issue create` / `gh label create` to import them into VertexChainLabs/VertexChain. Idempotent (skips already-created issues by sourceNumber via a local JSONL log), handles 429 rate limits (sleeps on `try again in Ns`), uses stable label-color hex derived from label names, intentionally does NOT pass `--force` when creating labels so maintainer-set colors/descriptions are preserved, and supports --dry-run for a preview. * build(deps-dev): bump caniuse-lite in /Backend (#330) Bumps [caniuse-lite](https://github.com/browserslist/caniuse-lite) from 1.0.30001799 to 1.0.30001806. - [Commits](browserslist/caniuse-lite@1.0.30001799...1.0.30001806) --- updated-dependencies: - dependency-name: caniuse-lite dependency-version: 1.0.30001806 dependency-type: indirect update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump globals from 16.5.0 to 17.7.0 in /Backend (#329) Bumps [globals](https://github.com/sindresorhus/globals) from 16.5.0 to 17.7.0. - [Release notes](https://github.com/sindresorhus/globals/releases) - [Commits](sindresorhus/globals@v16.5.0...v17.7.0) --- updated-dependencies: - dependency-name: globals dependency-version: 17.7.0 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump @nestjs/testing in /Backend (#328) Bumps [@nestjs/testing](https://github.com/nestjs/nest/tree/HEAD/packages/testing) from 11.1.27 to 11.1.28. - [Release notes](https://github.com/nestjs/nest/releases) - [Commits](https://github.com/nestjs/nest/commits/v11.1.28/packages/testing) --- updated-dependencies: - dependency-name: "@nestjs/testing" dependency-version: 11.1.28 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps-dev): bump @types/supertest from 6.0.3 to 7.2.1 in /Backend (#327) Bumps [@types/supertest](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/supertest) from 6.0.3 to 7.2.1. - [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases) - [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/supertest) --- updated-dependencies: - dependency-name: "@types/supertest" dependency-version: 7.2.1 dependency-type: direct:development update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump libphonenumber-js from 1.13.7 to 1.13.9 in /Backend (#326) Bumps [libphonenumber-js](https://gitlab.com/catamphetamine/libphonenumber-js) from 1.13.7 to 1.13.9. - [Changelog](https://gitlab.com/catamphetamine/libphonenumber-js/blob/master/CHANGELOG.md) - [Commits](https://gitlab.com/catamphetamine/libphonenumber-js/commits/master) --- updated-dependencies: - dependency-name: libphonenumber-js dependency-version: 1.13.9 dependency-type: indirect update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * build(deps): bump nanoid from 3.3.14 to 3.3.16 in /Backend (#325) Bumps [nanoid](https://github.com/ai/nanoid) from 3.3.14 to 3.3.16. - [Release notes](https://github.com/ai/nanoid/releases) - [Changelog](https://github.com/ai/nanoid/blob/main/CHANGELOG.md) - [Commits](ai/nanoid@3.3.14...3.3.16) --- updated-dependencies: - dependency-name: nanoid dependency-version: 3.3.16 dependency-type: indirect update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(ci): remove Dependabot from CI Deletes .github/dependabot.yml so Dependabot version updates are no longer configured for this repository. The Dependabot auto-merge workflow (.github/workflows/auto-merge.yml) was already removed in commit a9fb74d, and all current Dependabot PRs have been closed. Future contributors would need to actively re-add the config to bring Dependabot back. * feat(governance): add counter-vote support and get_proposals_by_proposer - Upgrade vote storage from bare bool to VoteRecord { vote_power: u32, against: bool } - Add rejections: u32 field to Proposal struct to track against-votes - Update vote_proposal() to accept against: bool parameter; against=false increments approvals, against=true increments rejections - Prevent vote flipping: AlreadyVoted error covers both duplicate and direction-change attempts (checked via storage key existence) - Add ProposalsByProposer(Address) storage key maintaining Vec<u32> of proposal IDs per proposer, updated atomically in create_proposal() - Expose get_proposals_by_proposer(addr) -> Vec<u32> on contract; returns empty Vec for addresses with no proposals - Add migrate_votes(admin, snapshot_votes) one-shot migration function for existing on-chain bool votes pre-upgrade; guarded by MigrationDone flag (new error MigrationAlreadyDone = 11), admin-only - Extend voted event to include against flag for off-chain indexers - Add migration_done event emitting count of migrated entries - Add 12 new tests covering counter-votes, proposer index, and migration; all 15 tests pass (cargo test --workspace: 27 total, 0 failed) - cargo fmt, clippy -D warnings, cargo check, wasm32 release build all pass Closes #131 * fix(docs): wrap Vec<u32> in backticks to silence rustdoc invalid-html-tags RUSTDOCFLAGS=-D warnings treats bare Vec<u32> in a doc comment as an unclosed HTML tag <u32> (rustdoc::invalid-html-tags lint). Wrapping the type in backticks makes it a code span, not markup. Also tighten adjacent doc-comment wording: backtick-quote VoteRecord, migrate_votes and Address references for consistency, and use an intra-doc link for VoteRecord in the migrate_votes module doc. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: BigJohn-dev <imeobongjohn38@gmail.com> Co-authored-by: Dayz Tech Co <Dayztechnology@gmail.com> Co-authored-by: divine-mercyx <divinewilson766@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: ugoocreates-pixel <ugoocreates@gmail.com> Co-authored-by: Agencybuilds <eikechukwu282@gmail.com> Co-authored-by: Abdulrahman Firdausi Onize <138733058+nanaabdul1172@users.noreply.github.com> Co-authored-by: Fabr-i10 <fabricio20arg@gmail.com> Co-authored-by: chuks68 <valentinesomtochukwu68@gmail.com> Co-authored-by: Opulence Chuks <162402876+Opulencechuks@users.noreply.github.com> Co-authored-by: benzy018 <akobezjr@gmail.com> Co-authored-by: Jefferson <xjeffcmx23@gmail.com> Co-authored-by: dominiccreates <dominiccreatess@gmail.com> Co-authored-by: Oyebanji Adegboyega <60378774+GBOYEE@users.noreply.github.com> Co-authored-by: GBOYEE <bot@xandercorp.io> Co-authored-by: VertexChain Maintainer Bot <dependabot-disabler@local.bot> Co-authored-by: VertexChain Maintainer Bot <vertexchain-maintainer@local.bot> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 36b5601 commit d8312c2

1 file changed

Lines changed: 493 additions & 43 deletions

File tree

  • contracts/governance/src

0 commit comments

Comments
 (0)