Skip to content

FE release 2026-05-05 - #4040

Merged
trajan0x merged 58 commits into
fe-releasefrom
master
May 5, 2026
Merged

trajan0x merged 58 commits into
fe-releasefrom
master

Conversation

@ChiTimesChi

@ChiTimesChi ChiTimesChi commented May 4, 2026 •

Copy link
Copy Markdown
Collaborator

Summary by CodeRabbit

  • Bug Fixes

    • Expanded cross-chain bridge support to more networks (Aurora, Canto, Cronos, Moonbeam, Moonriver, Blast, Harmony)
    • RPC route now validates chain IDs to prevent invalid requests
  • Chores

    • Version bumps across SDK Router, REST API, Synapse Interface, Widget packages
    • Updated package dependencies for compatibility
  • Tests

    • Flaky/integration tests marked to skip by default to stabilize CI

784a6e4: synapse-interface preview link
a053040: synapse-interface preview link

trajan0x and others added 30 commits March 5, 2026 23:47
 - @synapsecns/bridge-docs@0.6.15
 - @synapsecns/explorer-ui@0.5.21
 - @synapsecns/synapse-interface@0.43.39
* feat(sdk-router): pause synapse bridge modules in sdk

* test(sdk-router): remove paused bridge module coverage

* test(rest-api): remove flaky live route coverage
 - @synapsecns/rest-api@1.13.27
 - @synapsecns/sdk-router@0.20.8
 - @synapsecns/synapse-interface@0.43.40
 - @synapsecns/widget@0.9.51
 - @synapsecns/rest-api@1.13.28
 - @synapsecns/sdk-router@0.20.9
 - @synapsecns/synapse-interface@0.43.41
 - @synapsecns/widget@0.9.52
* docs: add synapse-interface ETA spec

* feat(synapse-interface): compact bridge eta labels

* fix(synapse-interface): start countdown after confirm

* fix(synapse-interface): restore eta remaining translations

* fix(synapse-interface): rerun transactions listener on account resolve

* docs: remove synapse-interface ETA spec

* fix(synapse-interface): restore master transaction ETA behavior

* Use floored unix seconds for current time
 - @synapsecns/synapse-interface@0.43.42
* docs: add RFQ and Gas.zip bridgeV2-only spec

* feat(sdk-router): make synapserfq legacy routing v2-only

* feat(sdk-router): make gaszip legacy routing v2-only

* test(sdk-router): cover v2-only rfq and gaszip routing

* refactor(sdk-router): align v2-only module stubs

* chore: remove rfq gaszip bridge v2 spec

* chore: fix lint
* build: add new chains to config

* deploy: new chains
 - @synapsecns/contracts-rfq@0.19.4
 - @synapsecns/rest-api@1.13.29
 - @synapsecns/sdk-router@0.21.0
 - @synapsecns/synapse-interface@0.43.43
 - @synapsecns/widget@0.9.53
* chore: migrate npm publishing from npmjs.org to GitHub Packages

Our npm publish token has been lost, so this migrates all @synapsecns
package publishing to GitHub Packages (npm.pkg.github.com). Updates the
Lerna publish workflow to authenticate with GITHUB_TOKEN instead of
NPM_TOKEN, adds the registry to publishConfig in all 6 public packages,
and adds a blog post documenting the change for consumers.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* docs: update READMEs and docs to reference GitHub Packages registry

Replace npm badges with GitHub Packages links, add .npmrc setup
instructions before install commands in all published package READMEs
and docs site pages.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: replace npmjs.org with plain English to fix spellcheck

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
 - @synapsecns/bridge-docs@0.6.16
 - @synapsecns/contracts-adapter@1.0.5
 - @synapsecns/contracts-core@1.0.36
 - @synapsecns/contracts-rfq@0.19.5
 - @synapsecns/coverage-aggregator@1.0.7
 - @synapsecns/explorer-ui@0.5.22
 - @synapsecns/rest-api@1.13.30
 - @synapsecns/sdk-router@0.21.1
 - @synapsecns/solidity-devops@0.4.12
 - @synapsecns/synapse-constants@1.8.12
 - @synapsecns/synapse-interface@0.43.44
 - @synapsecns/widget@0.9.54
…3985)

Blast API shut down after Oct 31, 2025. Replace all blastapi.io RPC
endpoint references in docs, tests, and example code with Chainstack.

Closes #3806

Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Swap CodeClimate maintainability badge in README for Qlty badge
- Remove .codeclimate.yml and add .qlty/qlty.toml with equivalent
  config (same exclude patterns, markdownlint/stylelint/tflint plugins)

Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: correct Qlty badge URL in README

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: pin Foundry version and narrow typechain glob

Latest Foundry produces non-ABI JSON in artifacts/ that typechain can't
parse. Pin to nightly-2025-02-27 and narrow the glob from
'artifacts/**/*json' to 'artifacts/*.sol/*.json' so only actual contract
ABIs are processed.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
nightly-2025-02-27 doesn't exist as a downloadable release. Use the
latest stable release v1.5.1 instead. The typechain glob was already
narrowed in the previous PR to avoid non-ABI artifacts.

Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…3993)

Adds manual trigger capability to the publish workflow so we don't need
a packages/ change to re-run it in the future.

Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
 - @synapsecns/bridge-docs@0.6.17
 - @synapsecns/contracts-core@1.0.37
 - @synapsecns/rest-api@1.13.31
 - @synapsecns/sdk-router@0.21.2
 - @synapsecns/synapse-interface@0.43.45
 - @synapsecns/widget@0.9.55
 - @synapsecns/bridge-docs@0.6.18
 - @synapsecns/explorer-ui@0.5.23
 - @synapsecns/rest-api@1.13.32
 - @synapsecns/synapse-constants@1.8.13
* feat: add deployment salt, disable token setup for now, sanity checks around bridge setting

* fix(solidity-devops): ehterscan V2 key

* build: prepare for deployments

* feat: deploy on 18 chains

* feat(contracts-adapter): add token verification utility

Add utility script to verify ERC20 token deployments across chains:
- Verifies symbol() and decimals() for all tokens in configs/global/tokens.json
- Uses multicall3 for efficient batch verification across 18 chains
- Detects and highlights symbol/decimal mismatches between chains
- Outputs compact JSON report grouping chains by token properties
- Configurable skip list for non-standard tokens (GMX)
- Supports custom RPC base URL via RPC_BASE_URL env variable

Usage: RPC_BASE_URL=<url> npm run verify-tokens

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(contracts-adapter): add block time fetching utility

Add standalone script to fetch and update average block times:
- Fetches average block time for all deployed chains
- Uses RPC_BASE_URL/{chainId} pattern (same as token verification)
- Calculates based on last month of blocks (100K block analysis)
- Updates blockTime field in configs/global/chains.json
- Color-coded console output showing changes
- Rounds to nearest 50ms for consistency

Updated block times based on latest on-chain data:
- BNB: 1500ms → 750ms (50% faster)
- Cronos: 5600ms → 600ms (89% faster)
- Fantom: 1350ms → 3450ms (slower due to network changes)
- Plus updates to 7 other chains

Usage: RPC_BASE_URL=<url> npm run fetch-block-times

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* feat: add tokens to SBA, supported eid check for wiring

* chore: upd config

* feat: config verification script

* feat: isDefaultSendLibrary checks

* fix(contracts-adapter): use per-chain block confirmations for SBA wiring

* feat(contracts-adapter): add DevMultisig fetch utility

* feat(contracts-adapter): add SBA ownership transfer script

* feat(contracts-adapter): add SBA ownership verifier

* chore(contracts-adapter): clean up adapter utility scripts

* refactor(contracts-adapter): simplify ownership verification output

* refactor(contracts-adapter): streamline token verification checks

* refactor(contracts-adapter): split SBA verification into helper stages

* refactor(contracts-adapter): tighten SBA issue aggregation

* Revert "fix(solidity-devops): ehterscan V2 key"

This reverts commit 81ddcdd.

---------

Co-authored-by: Claude <noreply@anthropic.com>
* feat: etherscanV2 support

* feat: optional blockscout key

* chore: trigger sdk-router release

* chore: lint

* Revert "chore: trigger sdk-router release"

This reverts commit 7ac466f.
 - @synapsecns/contracts-adapter@1.0.6
 - @synapsecns/contracts-rfq@0.19.6
 - @synapsecns/solidity-devops@0.5.0
* docs: add widget bridgeV2 migration spec

* feat(widget): migrate bridge flow to bridgeV2

* fix(widget): refresh stale quotes with latest callback

* fix(widget): invalidate bridge v2 quotes across account switches

* chore: remove widget bridge v2 spec
* docs: add spec for pause and chain warning cleanup

* chore(synapse-interface): clear shipped pause artifacts

* refactor(synapse-interface): remove hardcoded chain warnings

* docs(synapse-interface): remove pause cleanup spec
 - @synapsecns/synapse-interface@0.43.46
 - @synapsecns/widget@0.10.0
* docs: add SBA sdk-router spec

* feat(sdk-router): add SynapseBridgeAdapter bridgeV2 support

* test(sdk-router): cover SynapseBridgeAdapter flows

* docs(sdk-router): document SynapseBridgeAdapter behavior

* fix(synapse-interface): prefer SynapseBridgeAdapter quotes

* feat(sdk-router): extend SBA support to dfk harmony and klaytn

* test(sdk-router): cover expanded SBA shared-intent support

* docs(sdk-router): document expanded SBA chain support

* docs: narrow SBA origin swap scope to native wrap

* feat(sdk-router): add SBA native-wrap support

* docs(sdk-router): add SBA token artifact spec

* feat(sdk-router): route SBA through committed token artifact

* docs(sdk-router): document SBA artifact routing

* chore: remove SBA sdk-router specs

* chore: rename SBA bridge module labels

* feat(sdk-router): gate SBA bridge routes by chain

* chore(sdk-router): restore README from master

* test(sdk-router): align sdk coverage suite

* Fix cached SBA ETA routing

* fix(sdk-router): disable Avalanche and Base for SBA

* chore: lint

* fix(synapse-interface): restore bridge quote thunk from master
* fix(synapse-interface): bump next to 14.2.35

* fix(synapse-interface): align node engine and eslint config

* Revert "fix(synapse-interface): align node engine and eslint config"

This reverts commit db4c67d.

* fix(rest-api): configure npm auth for github packages
 - @synapsecns/rest-api@1.13.33
 - @synapsecns/sdk-router@0.22.0
 - @synapsecns/synapse-interface@0.43.47
 - @synapsecns/widget@0.10.1
ChiTimesChi and others added 8 commits April 28, 2026 17:05
Chore: master catchup with fe-release
fix(sdk-router): apply SBA enablement to destination only
 - @synapsecns/rest-api@1.13.37
 - @synapsecns/sdk-router@0.23.1
 - @synapsecns/synapse-interface@0.44.0
 - @synapsecns/widget-example@0.2.2
 - @synapsecns/widget@0.11.2
* fix(sdk-router): use chain-specific SBA metadata for Cronos

* feat(sdk-router): expand SBA destination and intent chain support

* feat(sdk-router): add SwapQuoterV2 addresses for new intent chains

* fix(sdk-router): comment not fully enabled chains
 - @synapsecns/rest-api@1.13.38
 - @synapsecns/sdk-router@0.23.2
 - @synapsecns/synapse-interface@0.44.1
 - @synapsecns/widget-example@0.2.3
 - @synapsecns/widget@0.11.3
@vercel

vercel Bot commented May 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
sanguine Error Error May 5, 2026 0:40am

@coderabbitai

coderabbitai Bot commented May 4, 2026 •

Copy link
Copy Markdown
Contributor
📝 Walkthrough

Walkthrough

Adds SBA (Synapse Bridge Adapter) support for additional chains, updates sdk-router to v0.23.2 and propagates dependency/version bumps across packages, adjusts bridge eligibility to be destination-gated, extends chain/address/metadata entries, updates tests (skips some flaky suites), and adds minor tooling/changelog/version changes.

Changes

Multi-Chain SBA Support & Release Propagation

Layer / File(s) Summary
Spellcheck / Repo config
cspell.json
Added "hypercall" to the allowed words list.
Package releases & test toggles
packages/rest-api/package.json, packages/rest-api/CHANGELOG.md
Bumped @synapsecns/rest-api to 1.13.38; replaced live Jest test scripts with placeholder echoes.
SDK-Router release
packages/sdk-router/package.json, packages/sdk-router/CHANGELOG.md
Bumped @synapsecns/sdk-router to 0.23.2 and added changelog entry (SBA support on more chains).
Swap quoter exceptions
packages/sdk-router/src/constants/addresses.ts
Expanded SWAP_QUOTER_V2_EXCEPTION_MAP with additional SupportedChainId → address entries.
Intents support list
packages/sdk-router/src/constants/chainIds.ts
Extended INTENTS_SUPPORTED_CHAIN_IDS to include AURORA, CANTO, CRONOS, FANTOM, MOONBEAM, MOONRIVER.
SBA chain metadata
packages/sdk-router/src/sba/metadata.ts
Added Cronos-specific deployment address constant and extended SBA_CHAIN_METADATA with entries for CRONOS, MOONBEAM, MOONRIVER, BLAST, AURORA, HARMONY (lzEid and originBlockConfirmations).
Bridge eligibility logic
packages/sdk-router/src/sba/synapseBridgeAdapterModuleSet.ts
Replaced bidirectional supported-set gating with destination-only SBA_BRIDGE_ENABLED_DESTINATION_CHAINS; getBridgeTokenCandidates now gates solely on toChainId.
Tests — behavior & skips
packages/sdk-router/src/rfq/api.integration.test.ts, packages/sdk-router/src/sba/synapseBridgeAdapterModuleSet.test.ts, packages/sdk-router/src/sdk.test.ts
Skipped flaky RFQ/Swap suites, adapted SBA eligibility tests to destination-only logic, added Canto to shared-intent-path tests, and added bridgeV2 integration coverage for ETH→Optimism scenario.
Dependent package bumps & changelogs
packages/synapse-interface/package.json, packages/synapse-interface/CHANGELOG.md, packages/widget/package.json, packages/widget/CHANGELOG.md, packages/widget-example/package.json, packages/widget-example/CHANGELOG.md
Bumped versions and updated @synapsecns/sdk-router dependency to ^0.23.2 across dependents; added changelog entries.
RPC handler refactor & validation
packages/synapse-interface/pages/api/rpc/[chainId].ts
Refactored isDomainAllowed and API handler to arrow-const forms; added pathname-based safeChainId numeric validation returning 400 on invalid input; exported handler as default.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

Suggested reviewers

  • aureliusbtc
  • trajan0x
  • Defi-Moses
  • abtestingalpha

Poem

🐰 I nibble code and hop with glee,
New chains now join our bridged marquee,
Destination-first — a clever tweak,
Cronos, Canto, Moonbeam speak! ✨

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Title check ❓ Inconclusive The title 'FE release 2026-05-05' is vague and does not clearly describe the main technical changes, using only a date reference without meaningful information about what was changed. Consider using a more descriptive title such as 'Validate RPC chain ID and release FE updates' to clearly communicate the primary changes and improvements included in this release.
✅ Passed checks (4 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch master

Warning

Review ran into problems

🔥 Problems

Git: Failed to clone repository. Please run the @coderabbitai full review command to re-trigger a full review. If the issue persists, set path_filters to include or exclude specific files.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@codecov

codecov Bot commented May 4, 2026 •

Copy link
Copy Markdown

Bundle Report

Changes will increase total bundle size by 196.48kB (0.58%) ⬆️. This is within the configured threshold ✅

Detailed changes
Bundle name Size Change
sdk-router-@synapsecns/sdk-router-esm 460.88kB 35.87kB (8.44%) ⬆️
sdk-router-@synapsecns/sdk-router-cjs 210.17kB 25.12kB (13.57%) ⬆️
synapse-interface-server-cjs 2.27MB 18.6kB (0.83%) ⬆️
synapse-interface-edge-server-array-push 92.8kB 92.67kB (70740.46%) ⬆️
synapse-interface-client-array-push 8.02MB 24.23kB (0.3%) ⬆️

Affected Assets, Files, and Routes:

view changes for bundle: synapse-interface-client-array-push

Assets Changed:

Asset Name Size Change Total Size Change (%)
static/chunks/pages/_app-*.js 18.91kB 2.39MB 0.8%
static/chunks/main-*.js 5.52kB 119.26kB 4.85%
static/chunks/pages/index-*.js -29 bytes 66.04kB -0.04%
static/chunks/7808-*.js -81 bytes 51.27kB -0.16%
static/chunks/4097-*.js 223 bytes 31.8kB 0.71%
static/chunks/1348-*.js 223 bytes 15.11kB 1.5%
static/chunks/5784-*.js -42 bytes 12.56kB -0.33%
static/chunks/3230-*.js -498 bytes 11.7kB -4.08%
static/Kbjbygu8qn7w9TcbxEhnt/_buildManifest.js (New) 6.67kB 6.67kB 100.0% 🚀
static/Kbjbygu8qn7w9TcbxEhnt/_ssgManifest.js (New) 77 bytes 77 bytes 100.0% 🚀
static/6D-IFsN1RecTR1NNnzbhX/_buildManifest.js (Deleted) -6.67kB 0 bytes -100.0% 🗑️
static/6D-IFsN1RecTR1NNnzbhX/_ssgManifest.js (Deleted) -77 bytes 0 bytes -100.0% 🗑️
view changes for bundle: sdk-router-@synapsecns/sdk-router-cjs

Assets Changed:

Asset Name Size Change Total Size Change (%)
sdk-router.cjs.production.min.js 25.12kB 210.17kB 13.57% ⚠️

Files in sdk-router.cjs.production.min.js:

  • ./src/sba/metadata.ts → Total Size: 3.56kB

  • ./src/constants/chainIds.ts → Total Size: 7.19kB

  • ./src/sba/synapseBridgeAdapterModuleSet.ts → Total Size: 10.41kB

  • ./src/constants/addresses.ts → Total Size: 9.58kB

view changes for bundle: synapse-interface-server-cjs

Assets Changed:

Asset Name Size Change Total Size Change (%)
6492.js 5.48kB 554.52kB 1.0%
6814.js (New) 474.75kB 474.75kB 100.0% 🚀
../pages/index.js -23 bytes 76.43kB -0.03%
2007.js (New) 58.09kB 58.09kB 100.0% 🚀
1269.js (New) 53.05kB 53.05kB 100.0% 🚀
4248.js (New) 41.71kB 41.71kB 100.0% 🚀
980.js (New) 28.21kB 28.21kB 100.0% 🚀
../pages/swap.js -7 bytes 24.22kB -0.03%
6859.js 2 bytes 24.15kB 0.01%
6093.js (New) 24.06kB 24.06kB 100.0% 🚀
../pages/landing/sections/SecuritySection.js 1 bytes 21.37kB 0.0%
3938.js (New) 20.57kB 20.57kB 100.0% 🚀
8275.js -798 bytes 18.91kB -4.05%
8252.js -819 bytes 18.0kB -4.35%
../pages/landing/sections/UseCasesSection.js 1 bytes 17.24kB 0.01%
2186.js -742 bytes 16.9kB -4.21%
4714.js -701 bytes 16.31kB -4.12%
8010.js -736 bytes 15.92kB -4.42%
7797.js (New) 15.72kB 15.72kB 100.0% 🚀
2115.js (New) 15.27kB 15.27kB 100.0% 🚀
8580.js -647 bytes 14.41kB -4.3%
5675.js 234 bytes 13.81kB 1.72%
../pages/state-managed-bridge.js -1 bytes 13.77kB -0.01%
52.js -612 bytes 13.48kB -4.34%
1715.js (New) 12.51kB 12.51kB 100.0% 🚀
../pages/landing/sections/ExplorerSection.js -1 bytes 12.32kB -0.01%
../pages/stake/StakeCardTitle.js -1 bytes 11.77kB -0.01%
../pages/returntomonke.js 2 bytes 11.76kB 0.02%
2595.js (New) 11.71kB 11.71kB 100.0% 🚀
../pages/lifi.js 1 bytes 11.47kB 0.01%
../pages/landing/sections/IntegrationSection.js -1 bytes 11.42kB -0.01%
../pages/landing/sections/ResourcesSection.js -1 bytes 11.01kB -0.01%
3773.js (New) 10.7kB 10.7kB 100.0% 🚀
../pages/_error.js -3 bytes 10.32kB -0.03%
../pages/pool/poolManagement.js -1 bytes 10.03kB -0.01%
4071.js (New) 9.84kB 9.84kB 100.0% 🚀
4567.js (New) 9.77kB 9.77kB 100.0% 🚀
../pages/pool/PoolInfoSection.js -3 bytes 9.59kB -0.03%
../pages/pool/NoPoolBody.js -1 bytes 9.54kB -0.01%
../pages/landing/sections/BridgeSection.js -2 bytes 9.21kB -0.02%
../pages/pool/components/LiquidityManagementTabs.js -1 bytes 9.1kB -0.01%
9192.js (New) 9.07kB 9.07kB 100.0% 🚀
../pages/pool/poolManagement/WithdrawButton.js -3 bytes 8.83kB -0.03%
../pages/returntomonke/PfpGeneratorCard.js 1 bytes 8.38kB 0.01%
../pages/stake/[routerIndex].js 2 bytes 8.24kB 0.02%
../pages/stake.js 4 bytes 8.09kB 0.05%
../pages/stake/StakeCard.js 1 bytes 7.82kB 0.01%
../pages/landing/sections/HeroSection.js -1 bytes 7.68kB -0.01%
../pages/pool/PoolInfoSection/CurrencyReservesCard.js -1 bytes 7.57kB -0.01%
../pages/returntomonke/ImageUploader.js 1 bytes 7.35kB 0.01%
8559.js -1 bytes 7.31kB -0.01%
../pages/pool/PoolInfoSection/InfoSectionCard.js -1 bytes 6.28kB -0.02%
../pages/pool/components/ReceivedTokenSection.js -1 bytes 5.82kB -0.02%
../pages/pool/components/PriceImpactDisplay.js -1 bytes 5.78kB -0.02%
../pages/pool/components/PoolTitle.js -1 bytes 5.34kB -0.02%
../pages/pool/PoolInfoSection/InfoSection.js -1 bytes 5.24kB -0.02%
../pages/pool/components/AugmentWithUnits.js -1 bytes 5.06kB -0.02%
../pages/pools/PoolCards.js -1 bytes 4.93kB -0.02%
../pages/bridge.js -1 bytes 4.87kB -0.02%
../pages/landing/sections/HowItWorksSection.js -2 bytes 4.67kB -0.04%
../pages/pools/PoolCard.js -1 bytes 4.43kB -0.02%
1846.js (New) 3.21kB 3.21kB 100.0% 🚀
../pages/_app.js -1 bytes 3.08kB -0.03%
../pages/pool/[poolId].js.nft.json 2 bytes 1.26kB 0.16%
../pages/index.js.nft.json 1 bytes 1.1kB 0.09%
../pages/swap.js.nft.json 1 bytes 991 bytes 0.1%
../pages/stake/[routerIndex].js.nft.json 2 bytes 919 bytes 0.22%
../pages/pools.js.nft.json 1 bytes 842 bytes 0.12%
../pages/pool/PoolBody.js.nft.json 1 bytes 814 bytes 0.12%
../pages/stake.js.nft.json 2 bytes 803 bytes 0.25%
../pages/pool/poolManagement/Withdraw.js.nft.json 1 bytes 756 bytes 0.13%
../pages/pool/poolManagement.js.nft.json 1 bytes 722 bytes 0.14%
../pages/landing.js.nft.json 1 bytes 694 bytes 0.14%
../pages/returntomonke.js.nft.json 1 bytes 621 bytes 0.16%
../pages/state-managed-bridge.js.nft.json 1 bytes 611 bytes 0.16%
../pages/pool/poolManagement/Deposit.js.nft.json 1 bytes 532 bytes 0.19%
../pages/pool/poolManagement/DepositButton.js.nft.json 1 bytes 532 bytes 0.19%
../pages/stake/StakeCard.js.nft.json 1 bytes 422 bytes 0.24%
../pages/lifi.js.nft.json 2 bytes 354 bytes 0.57%
9645.js (Deleted) -455.69kB 0 bytes -100.0% 🗑️
4130.js (Deleted) -58.2kB 0 bytes -100.0% 🗑️
1802.js (Deleted) -53.05kB 0 bytes -100.0% 🗑️
7607.js (Deleted) -41.51kB 0 bytes -100.0% 🗑️
8979.js (Deleted) -28.22kB 0 bytes -100.0% 🗑️
2640.js (Deleted) -24.06kB 0 bytes -100.0% 🗑️
3678.js (Deleted) -20.57kB 0 bytes -100.0% 🗑️
1653.js (Deleted) -15.72kB 0 bytes -100.0% 🗑️
1536.js (Deleted) -15.26kB 0 bytes -100.0% 🗑️
9515.js (Deleted) -12.55kB 0 bytes -100.0% 🗑️
335.js (Deleted) -11.84kB 0 bytes -100.0% 🗑️
7690.js (Deleted) -11.72kB 0 bytes -100.0% 🗑️
2070.js (Deleted) -9.84kB 0 bytes -100.0% 🗑️
5443.js (Deleted) -9.76kB 0 bytes -100.0% 🗑️
682.js (Deleted) -9.07kB 0 bytes -100.0% 🗑️
7077.js (Deleted) -3.21kB 0 bytes -100.0% 🗑️
view changes for bundle: sdk-router-@synapsecns/sdk-router-esm

Assets Changed:

Asset Name Size Change Total Size Change (%)
sdk-router.esm.js 35.87kB 460.88kB 8.44% ⚠️

Files in sdk-router.esm.js:

  • ./src/sba/synapseBridgeAdapterModuleSet.ts → Total Size: 10.29kB

  • ./src/constants/chainIds.ts → Total Size: 6.47kB

  • ./src/constants/addresses.ts → Total Size: 9.2kB

  • ./src/sba/metadata.ts → Total Size: 3.42kB

view changes for bundle: synapse-interface-edge-server-array-push

Assets Changed:

Asset Name Size Change Total Size Change (%)
pages/api/rpc/[chainId].js (New) 90.31kB 90.31kB 100.0% 🚀
edge-runtime-webpack.js (New) 1.49kB 1.49kB 100.0% 🚀
middleware-manifest.json 878 bytes 961 bytes 1057.83% ⚠️

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
packages/sdk-router/src/sdk.test.ts (1)

389-406: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

describe.skip on 'Swap' removes swap-quote and populated-transaction coverage.

This .skip was added in this PR (not pre-existing). If it is intentional (e.g., the live Arbitrum RPC is unreliable in the release CI pipeline), consider adding a brief comment explaining the reason and tracking restoration via a TODO. If it was added accidentally, removing .skip restores the previously-passing coverage.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/sdk-router/src/sdk.test.ts` around lines 389 - 406, The test block
for 'Swap' is skipped via describe.skip which removes swap-quote and
populated-transaction coverage; either remove the .skip on the describe('Swap',
...) block to restore test coverage (so SynapseSDK instantiation and
createSwapQuoteTests run), or if skipping is intentional, add an inline comment
and a TODO above describe.skip('Swap', ...) explaining why (e.g., flaky Arbitrum
RPC in CI) and include a ticket/issue ID and expected restore date so reviewers
know it’s deliberate; update any test metadata accordingly.
🧹 Nitpick comments (1)
packages/sdk-router/src/rfq/api.integration.test.ts (1)

6-6: ⚡ Quick win

Prefer env-gated execution over permanently skipping the suite.

At Line 6, describe.skip removes this integration coverage from all runs. Instead of permanent skip, gate with an explicit env var so it stays off by default but remains runnable in scheduled or manual CI.

Proposed change
 // Live quotes should not run in the default test suite.
-describe.skip('getAllQuotes', () => {
+const describeLive = process.env.RUN_LIVE_QUOTE_TESTS === 'true' ? describe : describe.skip
+describeLive('getAllQuotes', () => {
   it('Integration test', async () => {
     const result = await getAllQuotes()
     // console.log('Current quotes: ' + JSON.stringify(result, null, 2))
     expect(result.length).toBeGreaterThan(0)
   })
 })

Note: This pattern requires corresponding CI workflow configuration to actually invoke the test when needed. The function is already covered by unit tests in api.test.ts, so this is an optional infrastructure improvement.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/sdk-router/src/rfq/api.integration.test.ts` at line 6, The test
suite for getAllQuotes is permanently skipped via describe.skip; change it to be
env-gated so it runs only when an explicit env var is set (e.g.,
RUN_INTEGRATION_TESTS). Replace the direct describe.skip('getAllQuotes', ...)
with an environment-conditional wrapper (for example choose between describe and
describe.skip based on process.env.RUN_INTEGRATION_TESTS) so the suite remains
off by default but can be enabled in CI or locally when needed; keep the suite
name getAllQuotes and existing test bodies unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@packages/rest-api/package.json`:
- Around line 17-18: The package.json currently replaces "test" and
"test:coverage" with no-op echoes which silences real failures; restore and
separate unit vs integration test scripts by adding a "test:unit" script that
runs offline/unit tests (e.g., your existing jest/mocha runner with a unit-only
pattern) and make "test" invoke "test:unit" so CI executes unit tests; add a
"test:integration" (or "test:live") script to run the network-dependent tests
and leave "test:coverage" to run coverage against the unit test suite, and if
you cannot run integration tests in CI add a TODO tracking issue reference in
the repo and mention it in package.json scripts comments or README so this
remains visible.

---

Outside diff comments:
In `@packages/sdk-router/src/sdk.test.ts`:
- Around line 389-406: The test block for 'Swap' is skipped via describe.skip
which removes swap-quote and populated-transaction coverage; either remove the
.skip on the describe('Swap', ...) block to restore test coverage (so SynapseSDK
instantiation and createSwapQuoteTests run), or if skipping is intentional, add
an inline comment and a TODO above describe.skip('Swap', ...) explaining why
(e.g., flaky Arbitrum RPC in CI) and include a ticket/issue ID and expected
restore date so reviewers know it’s deliberate; update any test metadata
accordingly.

---

Nitpick comments:
In `@packages/sdk-router/src/rfq/api.integration.test.ts`:
- Line 6: The test suite for getAllQuotes is permanently skipped via
describe.skip; change it to be env-gated so it runs only when an explicit env
var is set (e.g., RUN_INTEGRATION_TESTS). Replace the direct
describe.skip('getAllQuotes', ...) with an environment-conditional wrapper (for
example choose between describe and describe.skip based on
process.env.RUN_INTEGRATION_TESTS) so the suite remains off by default but can
be enabled in CI or locally when needed; keep the suite name getAllQuotes and
existing test bodies unchanged.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: a40b4e8b-444f-483c-8b98-3ef0851e0312

📥 Commits

Reviewing files that changed from the base of the PR and between db94a84 and 7912887.

📒 Files selected for processing (19)
  • cspell.json
  • packages/rest-api/CHANGELOG.md
  • packages/rest-api/package.json
  • packages/sdk-router/CHANGELOG.md
  • packages/sdk-router/package.json
  • packages/sdk-router/src/constants/addresses.ts
  • packages/sdk-router/src/constants/chainIds.ts
  • packages/sdk-router/src/rfq/api.integration.test.ts
  • packages/sdk-router/src/sba/metadata.ts
  • packages/sdk-router/src/sba/synapseBridgeAdapterModuleSet.test.ts
  • packages/sdk-router/src/sba/synapseBridgeAdapterModuleSet.ts
  • packages/sdk-router/src/sdk.test.ts
  • packages/synapse-interface/CHANGELOG.md
  • packages/synapse-interface/package.json
  • packages/synapse-interface/pages/api/rpc/[chainId].ts
  • packages/widget-example/CHANGELOG.md
  • packages/widget-example/package.json
  • packages/widget/CHANGELOG.md
  • packages/widget/package.json

Comment on lines +17 to +18
"test": "echo 'Live tests are currently disabled due to network issues'",
"test:coverage": "echo 'Live tests are currently disabled due to network issues'"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Both test commands are now no-ops — CI will always pass the test stage

Replacing both test and test:coverage with echo stubs means the CI pipeline reports a clean pass regardless of regressions. Even if the live/network-dependent tests need to be skipped, any pure-unit tests that don't hit the network would be silently dropped as well. Prefer separating unit tests from integration tests so CI at least runs the offline subset.

💡 Suggested approach
- "test": "echo 'Live tests are currently disabled due to network issues'",
- "test:coverage": "echo 'Live tests are currently disabled due to network issues'"
+ "test": "jest --testPathPattern='unit'",
+ "test:integration": "echo 'Live tests are currently disabled due to network issues'",
+ "test:coverage": "jest --coverage --testPathPattern='unit'"

Or, at minimum, add a // TODO tracking issue so this doesn't become permanent.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/rest-api/package.json` around lines 17 - 18, The package.json
currently replaces "test" and "test:coverage" with no-op echoes which silences
real failures; restore and separate unit vs integration test scripts by adding a
"test:unit" script that runs offline/unit tests (e.g., your existing jest/mocha
runner with a unit-only pattern) and make "test" invoke "test:unit" so CI
executes unit tests; add a "test:integration" (or "test:live") script to run the
network-dependent tests and leave "test:coverage" to run coverage against the
unit test suite, and if you cannot run integration tests in CI add a TODO
tracking issue reference in the repo and mention it in package.json scripts
comments or README so this remains visible.

Comment thread packages/synapse-interface/pages/api/rpc/[chainId].ts Fixed
* fix(synapse-interface): validate RPC chain id

* style(synapse-interface): use concise chain id regex
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented May 5, 2026 •

Copy link
Copy Markdown

Deploying sanguine-fe with  Cloudflare Pages  Cloudflare Pages

Latest commit: 0d1beb6
Status: ✅  Deploy successful!
Preview URL: https://8b650661.sanguine-fe.pages.dev
Branch Preview URL: https://master.sanguine-fe.pages.dev

View logs

 - @synapsecns/synapse-interface@0.44.2

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

♻️ Duplicate comments (1)
packages/synapse-interface/pages/api/rpc/[chainId].ts (1)

55-59: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

ChainId validation substantially mitigates the flagged SSRF, but residual risk remains.

The /^\d+$/ guard correctly rejects path traversal, whitespace, and non-numeric input, and new URL(req.url).pathname safely strips query parameters before the split. This is a meaningful improvement over the unvalidated version.

One residual concern: safeChainId is still fully user-controlled (any arbitrary digit string passes), so CodeQL's SSRF finding may continue to fire. Restricting to an explicit allowlist of known chain IDs (or at least an upper digit-length cap, e.g. /^\d{1,10}$/) would fully close the finding and prevent probing non-existent Goldsky endpoints with very large numbers.

🛡️ Proposed tightening: add a digit-length cap
-  if (!safeChainId || !/^\d+$/.test(safeChainId)) {
+  if (!safeChainId || !/^\d{1,10}$/.test(safeChainId)) {

For a full resolution, replace the regex with an allowlist lookup against known supported chain IDs.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/synapse-interface/pages/api/rpc/`[chainId].ts around lines 55 - 59,
The current validation of requestUrl → safeChainId allows any digit string which
can still trigger SSRF warnings; tighten it by replacing the loose /^\d+$/ check
with either an explicit allowlist lookup (e.g., create an allowedChainIds Set
and verify allowedChainIds.has(safeChainId)) or at minimum a digit-length cap
(change the regex to /^\d{1,10}$/) and then return 400 if not allowed; apply
this check where safeChainId is computed (using requestUrl and safeChainId) so
only known/length-capped chain IDs are accepted.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Duplicate comments:
In `@packages/synapse-interface/pages/api/rpc/`[chainId].ts:
- Around line 55-59: The current validation of requestUrl → safeChainId allows
any digit string which can still trigger SSRF warnings; tighten it by replacing
the loose /^\d+$/ check with either an explicit allowlist lookup (e.g., create
an allowedChainIds Set and verify allowedChainIds.has(safeChainId)) or at
minimum a digit-length cap (change the regex to /^\d{1,10}$/) and then return
400 if not allowed; apply this check where safeChainId is computed (using
requestUrl and safeChainId) so only known/length-capped chain IDs are accepted.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 46aa58f9-f07f-436a-a9c9-4d7af4ee787a

📥 Commits

Reviewing files that changed from the base of the PR and between 7912887 and 0d1beb6.

📒 Files selected for processing (3)
  • packages/synapse-interface/CHANGELOG.md
  • packages/synapse-interface/package.json
  • packages/synapse-interface/pages/api/rpc/[chainId].ts
✅ Files skipped from review due to trivial changes (2)
  • packages/synapse-interface/package.json
  • packages/synapse-interface/CHANGELOG.md

@trajan0x
trajan0x merged commit f150b3b into fe-release May 5, 2026
7 of 9 checks passed

This branch had an error being deployed

1 failed and 1 inactive (outdated) deployments
Production — 0d1beb64 Deployed May 5, 2026 by vercel[bot]
github-pages — a3d3b698 Deployed May 5, 2026 by ChiTimesChi via deploy #813
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants