FE release 2026-05-05 - #4040
Conversation
* feat(sdk-router): pause synapse bridge modules in sdk * test(sdk-router): remove paused bridge module coverage * test(rest-api): remove flaky live route coverage
* docs: add synapse-interface ETA spec * feat(synapse-interface): compact bridge eta labels * fix(synapse-interface): start countdown after confirm * fix(synapse-interface): restore eta remaining translations * fix(synapse-interface): rerun transactions listener on account resolve * docs: remove synapse-interface ETA spec * fix(synapse-interface): restore master transaction ETA behavior * Use floored unix seconds for current time
* docs: add RFQ and Gas.zip bridgeV2-only spec * feat(sdk-router): make synapserfq legacy routing v2-only * feat(sdk-router): make gaszip legacy routing v2-only * test(sdk-router): cover v2-only rfq and gaszip routing * refactor(sdk-router): align v2-only module stubs * chore: remove rfq gaszip bridge v2 spec * chore: fix lint
* build: add new chains to config * deploy: new chains
* chore: migrate npm publishing from npmjs.org to GitHub Packages Our npm publish token has been lost, so this migrates all @synapsecns package publishing to GitHub Packages (npm.pkg.github.com). Updates the Lerna publish workflow to authenticate with GITHUB_TOKEN instead of NPM_TOKEN, adds the registry to publishConfig in all 6 public packages, and adds a blog post documenting the change for consumers. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * docs: update READMEs and docs to reference GitHub Packages registry Replace npm badges with GitHub Packages links, add .npmrc setup instructions before install commands in all published package READMEs and docs site pages. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: replace npmjs.org with plain English to fix spellcheck Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- @synapsecns/bridge-docs@0.6.16 - @synapsecns/contracts-adapter@1.0.5 - @synapsecns/contracts-core@1.0.36 - @synapsecns/contracts-rfq@0.19.5 - @synapsecns/coverage-aggregator@1.0.7 - @synapsecns/explorer-ui@0.5.22 - @synapsecns/rest-api@1.13.30 - @synapsecns/sdk-router@0.21.1 - @synapsecns/solidity-devops@0.4.12 - @synapsecns/synapse-constants@1.8.12 - @synapsecns/synapse-interface@0.43.44 - @synapsecns/widget@0.9.54
- Swap CodeClimate maintainability badge in README for Qlty badge - Remove .codeclimate.yml and add .qlty/qlty.toml with equivalent config (same exclude patterns, markdownlint/stylelint/tflint plugins) Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: correct Qlty badge URL in README Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * fix: pin Foundry version and narrow typechain glob Latest Foundry produces non-ABI JSON in artifacts/ that typechain can't parse. Pin to nightly-2025-02-27 and narrow the glob from 'artifacts/**/*json' to 'artifacts/*.sol/*.json' so only actual contract ABIs are processed. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
nightly-2025-02-27 doesn't exist as a downloadable release. Use the latest stable release v1.5.1 instead. The typechain glob was already narrowed in the previous PR to avoid non-ABI artifacts. Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…3993) Adds manual trigger capability to the publish workflow so we don't need a packages/ change to re-run it in the future. Co-authored-by: Trajan0x <trajan0x@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: add deployment salt, disable token setup for now, sanity checks around bridge setting * fix(solidity-devops): ehterscan V2 key * build: prepare for deployments * feat: deploy on 18 chains * feat(contracts-adapter): add token verification utility Add utility script to verify ERC20 token deployments across chains: - Verifies symbol() and decimals() for all tokens in configs/global/tokens.json - Uses multicall3 for efficient batch verification across 18 chains - Detects and highlights symbol/decimal mismatches between chains - Outputs compact JSON report grouping chains by token properties - Configurable skip list for non-standard tokens (GMX) - Supports custom RPC base URL via RPC_BASE_URL env variable Usage: RPC_BASE_URL=<url> npm run verify-tokens 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * feat(contracts-adapter): add block time fetching utility Add standalone script to fetch and update average block times: - Fetches average block time for all deployed chains - Uses RPC_BASE_URL/{chainId} pattern (same as token verification) - Calculates based on last month of blocks (100K block analysis) - Updates blockTime field in configs/global/chains.json - Color-coded console output showing changes - Rounds to nearest 50ms for consistency Updated block times based on latest on-chain data: - BNB: 1500ms → 750ms (50% faster) - Cronos: 5600ms → 600ms (89% faster) - Fantom: 1350ms → 3450ms (slower due to network changes) - Plus updates to 7 other chains Usage: RPC_BASE_URL=<url> npm run fetch-block-times 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com> * feat: add tokens to SBA, supported eid check for wiring * chore: upd config * feat: config verification script * feat: isDefaultSendLibrary checks * fix(contracts-adapter): use per-chain block confirmations for SBA wiring * feat(contracts-adapter): add DevMultisig fetch utility * feat(contracts-adapter): add SBA ownership transfer script * feat(contracts-adapter): add SBA ownership verifier * chore(contracts-adapter): clean up adapter utility scripts * refactor(contracts-adapter): simplify ownership verification output * refactor(contracts-adapter): streamline token verification checks * refactor(contracts-adapter): split SBA verification into helper stages * refactor(contracts-adapter): tighten SBA issue aggregation * Revert "fix(solidity-devops): ehterscan V2 key" This reverts commit 81ddcdd. --------- Co-authored-by: Claude <noreply@anthropic.com>
* feat: etherscanV2 support * feat: optional blockscout key * chore: trigger sdk-router release * chore: lint * Revert "chore: trigger sdk-router release" This reverts commit 7ac466f.
* docs: add widget bridgeV2 migration spec * feat(widget): migrate bridge flow to bridgeV2 * fix(widget): refresh stale quotes with latest callback * fix(widget): invalidate bridge v2 quotes across account switches * chore: remove widget bridge v2 spec
* docs: add spec for pause and chain warning cleanup * chore(synapse-interface): clear shipped pause artifacts * refactor(synapse-interface): remove hardcoded chain warnings * docs(synapse-interface): remove pause cleanup spec
* docs: add SBA sdk-router spec * feat(sdk-router): add SynapseBridgeAdapter bridgeV2 support * test(sdk-router): cover SynapseBridgeAdapter flows * docs(sdk-router): document SynapseBridgeAdapter behavior * fix(synapse-interface): prefer SynapseBridgeAdapter quotes * feat(sdk-router): extend SBA support to dfk harmony and klaytn * test(sdk-router): cover expanded SBA shared-intent support * docs(sdk-router): document expanded SBA chain support * docs: narrow SBA origin swap scope to native wrap * feat(sdk-router): add SBA native-wrap support * docs(sdk-router): add SBA token artifact spec * feat(sdk-router): route SBA through committed token artifact * docs(sdk-router): document SBA artifact routing * chore: remove SBA sdk-router specs * chore: rename SBA bridge module labels * feat(sdk-router): gate SBA bridge routes by chain * chore(sdk-router): restore README from master * test(sdk-router): align sdk coverage suite * Fix cached SBA ETA routing * fix(sdk-router): disable Avalanche and Base for SBA * chore: lint * fix(synapse-interface): restore bridge quote thunk from master
* fix(synapse-interface): bump next to 14.2.35 * fix(synapse-interface): align node engine and eslint config * Revert "fix(synapse-interface): align node engine and eslint config" This reverts commit db4c67d. * fix(rest-api): configure npm auth for github packages
Chore: master catchup with fe-release
fix(sdk-router): apply SBA enablement to destination only
* fix(sdk-router): use chain-specific SBA metadata for Cronos * feat(sdk-router): expand SBA destination and intent chain support * feat(sdk-router): add SwapQuoterV2 addresses for new intent chains * fix(sdk-router): comment not fully enabled chains
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
📝 WalkthroughWalkthroughAdds SBA (Synapse Bridge Adapter) support for additional chains, updates sdk-router to v0.23.2 and propagates dependency/version bumps across packages, adjusts bridge eligibility to be destination-gated, extends chain/address/metadata entries, updates tests (skips some flaky suites), and adds minor tooling/changelog/version changes. ChangesMulti-Chain SBA Support & Release Propagation
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning Review ran into problems🔥 ProblemsGit: Failed to clone repository. Please run the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bundle ReportChanges will increase total bundle size by 196.48kB (0.58%) ⬆️. This is within the configured threshold ✅ Detailed changes
Affected Assets, Files, and Routes:view changes for bundle: synapse-interface-client-array-pushAssets Changed:
view changes for bundle: sdk-router-@synapsecns/sdk-router-cjsAssets Changed:
Files in
view changes for bundle: synapse-interface-server-cjsAssets Changed:
view changes for bundle: sdk-router-@synapsecns/sdk-router-esmAssets Changed:
Files in
view changes for bundle: synapse-interface-edge-server-array-pushAssets Changed:
|
There was a problem hiding this comment.
Actionable comments posted: 1
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
packages/sdk-router/src/sdk.test.ts (1)
389-406:⚠️ Potential issue | 🟡 Minor | ⚡ Quick win
describe.skipon 'Swap' removes swap-quote and populated-transaction coverage.This
.skipwas added in this PR (not pre-existing). If it is intentional (e.g., the live Arbitrum RPC is unreliable in the release CI pipeline), consider adding a brief comment explaining the reason and tracking restoration via a TODO. If it was added accidentally, removing.skiprestores the previously-passing coverage.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/sdk-router/src/sdk.test.ts` around lines 389 - 406, The test block for 'Swap' is skipped via describe.skip which removes swap-quote and populated-transaction coverage; either remove the .skip on the describe('Swap', ...) block to restore test coverage (so SynapseSDK instantiation and createSwapQuoteTests run), or if skipping is intentional, add an inline comment and a TODO above describe.skip('Swap', ...) explaining why (e.g., flaky Arbitrum RPC in CI) and include a ticket/issue ID and expected restore date so reviewers know it’s deliberate; update any test metadata accordingly.
🧹 Nitpick comments (1)
packages/sdk-router/src/rfq/api.integration.test.ts (1)
6-6: ⚡ Quick winPrefer env-gated execution over permanently skipping the suite.
At Line 6,
describe.skipremoves this integration coverage from all runs. Instead of permanent skip, gate with an explicit env var so it stays off by default but remains runnable in scheduled or manual CI.Proposed change
// Live quotes should not run in the default test suite. -describe.skip('getAllQuotes', () => { +const describeLive = process.env.RUN_LIVE_QUOTE_TESTS === 'true' ? describe : describe.skip +describeLive('getAllQuotes', () => { it('Integration test', async () => { const result = await getAllQuotes() // console.log('Current quotes: ' + JSON.stringify(result, null, 2)) expect(result.length).toBeGreaterThan(0) }) })Note: This pattern requires corresponding CI workflow configuration to actually invoke the test when needed. The function is already covered by unit tests in
api.test.ts, so this is an optional infrastructure improvement.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/sdk-router/src/rfq/api.integration.test.ts` at line 6, The test suite for getAllQuotes is permanently skipped via describe.skip; change it to be env-gated so it runs only when an explicit env var is set (e.g., RUN_INTEGRATION_TESTS). Replace the direct describe.skip('getAllQuotes', ...) with an environment-conditional wrapper (for example choose between describe and describe.skip based on process.env.RUN_INTEGRATION_TESTS) so the suite remains off by default but can be enabled in CI or locally when needed; keep the suite name getAllQuotes and existing test bodies unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@packages/rest-api/package.json`:
- Around line 17-18: The package.json currently replaces "test" and
"test:coverage" with no-op echoes which silences real failures; restore and
separate unit vs integration test scripts by adding a "test:unit" script that
runs offline/unit tests (e.g., your existing jest/mocha runner with a unit-only
pattern) and make "test" invoke "test:unit" so CI executes unit tests; add a
"test:integration" (or "test:live") script to run the network-dependent tests
and leave "test:coverage" to run coverage against the unit test suite, and if
you cannot run integration tests in CI add a TODO tracking issue reference in
the repo and mention it in package.json scripts comments or README so this
remains visible.
---
Outside diff comments:
In `@packages/sdk-router/src/sdk.test.ts`:
- Around line 389-406: The test block for 'Swap' is skipped via describe.skip
which removes swap-quote and populated-transaction coverage; either remove the
.skip on the describe('Swap', ...) block to restore test coverage (so SynapseSDK
instantiation and createSwapQuoteTests run), or if skipping is intentional, add
an inline comment and a TODO above describe.skip('Swap', ...) explaining why
(e.g., flaky Arbitrum RPC in CI) and include a ticket/issue ID and expected
restore date so reviewers know it’s deliberate; update any test metadata
accordingly.
---
Nitpick comments:
In `@packages/sdk-router/src/rfq/api.integration.test.ts`:
- Line 6: The test suite for getAllQuotes is permanently skipped via
describe.skip; change it to be env-gated so it runs only when an explicit env
var is set (e.g., RUN_INTEGRATION_TESTS). Replace the direct
describe.skip('getAllQuotes', ...) with an environment-conditional wrapper (for
example choose between describe and describe.skip based on
process.env.RUN_INTEGRATION_TESTS) so the suite remains off by default but can
be enabled in CI or locally when needed; keep the suite name getAllQuotes and
existing test bodies unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: a40b4e8b-444f-483c-8b98-3ef0851e0312
📒 Files selected for processing (19)
cspell.jsonpackages/rest-api/CHANGELOG.mdpackages/rest-api/package.jsonpackages/sdk-router/CHANGELOG.mdpackages/sdk-router/package.jsonpackages/sdk-router/src/constants/addresses.tspackages/sdk-router/src/constants/chainIds.tspackages/sdk-router/src/rfq/api.integration.test.tspackages/sdk-router/src/sba/metadata.tspackages/sdk-router/src/sba/synapseBridgeAdapterModuleSet.test.tspackages/sdk-router/src/sba/synapseBridgeAdapterModuleSet.tspackages/sdk-router/src/sdk.test.tspackages/synapse-interface/CHANGELOG.mdpackages/synapse-interface/package.jsonpackages/synapse-interface/pages/api/rpc/[chainId].tspackages/widget-example/CHANGELOG.mdpackages/widget-example/package.jsonpackages/widget/CHANGELOG.mdpackages/widget/package.json
| "test": "echo 'Live tests are currently disabled due to network issues'", | ||
| "test:coverage": "echo 'Live tests are currently disabled due to network issues'" |
There was a problem hiding this comment.
Both test commands are now no-ops — CI will always pass the test stage
Replacing both test and test:coverage with echo stubs means the CI pipeline reports a clean pass regardless of regressions. Even if the live/network-dependent tests need to be skipped, any pure-unit tests that don't hit the network would be silently dropped as well. Prefer separating unit tests from integration tests so CI at least runs the offline subset.
💡 Suggested approach
- "test": "echo 'Live tests are currently disabled due to network issues'",
- "test:coverage": "echo 'Live tests are currently disabled due to network issues'"
+ "test": "jest --testPathPattern='unit'",
+ "test:integration": "echo 'Live tests are currently disabled due to network issues'",
+ "test:coverage": "jest --coverage --testPathPattern='unit'"Or, at minimum, add a // TODO tracking issue so this doesn't become permanent.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@packages/rest-api/package.json` around lines 17 - 18, The package.json
currently replaces "test" and "test:coverage" with no-op echoes which silences
real failures; restore and separate unit vs integration test scripts by adding a
"test:unit" script that runs offline/unit tests (e.g., your existing jest/mocha
runner with a unit-only pattern) and make "test" invoke "test:unit" so CI
executes unit tests; add a "test:integration" (or "test:live") script to run the
network-dependent tests and leave "test:coverage" to run coverage against the
unit test suite, and if you cannot run integration tests in CI add a TODO
tracking issue reference in the repo and mention it in package.json scripts
comments or README so this remains visible.
* fix(synapse-interface): validate RPC chain id * style(synapse-interface): use concise chain id regex
Deploying sanguine-fe with
|
| Latest commit: |
0d1beb6
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://8b650661.sanguine-fe.pages.dev |
| Branch Preview URL: | https://master.sanguine-fe.pages.dev |
There was a problem hiding this comment.
♻️ Duplicate comments (1)
packages/synapse-interface/pages/api/rpc/[chainId].ts (1)
55-59:⚠️ Potential issue | 🟠 Major | ⚡ Quick winChainId validation substantially mitigates the flagged SSRF, but residual risk remains.
The
/^\d+$/guard correctly rejects path traversal, whitespace, and non-numeric input, andnew URL(req.url).pathnamesafely strips query parameters before the split. This is a meaningful improvement over the unvalidated version.One residual concern:
safeChainIdis still fully user-controlled (any arbitrary digit string passes), so CodeQL's SSRF finding may continue to fire. Restricting to an explicit allowlist of known chain IDs (or at least an upper digit-length cap, e.g./^\d{1,10}$/) would fully close the finding and prevent probing non-existent Goldsky endpoints with very large numbers.🛡️ Proposed tightening: add a digit-length cap
- if (!safeChainId || !/^\d+$/.test(safeChainId)) { + if (!safeChainId || !/^\d{1,10}$/.test(safeChainId)) {For a full resolution, replace the regex with an allowlist lookup against known supported chain IDs.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/synapse-interface/pages/api/rpc/`[chainId].ts around lines 55 - 59, The current validation of requestUrl → safeChainId allows any digit string which can still trigger SSRF warnings; tighten it by replacing the loose /^\d+$/ check with either an explicit allowlist lookup (e.g., create an allowedChainIds Set and verify allowedChainIds.has(safeChainId)) or at minimum a digit-length cap (change the regex to /^\d{1,10}$/) and then return 400 if not allowed; apply this check where safeChainId is computed (using requestUrl and safeChainId) so only known/length-capped chain IDs are accepted.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Duplicate comments:
In `@packages/synapse-interface/pages/api/rpc/`[chainId].ts:
- Around line 55-59: The current validation of requestUrl → safeChainId allows
any digit string which can still trigger SSRF warnings; tighten it by replacing
the loose /^\d+$/ check with either an explicit allowlist lookup (e.g., create
an allowedChainIds Set and verify allowedChainIds.has(safeChainId)) or at
minimum a digit-length cap (change the regex to /^\d{1,10}$/) and then return
400 if not allowed; apply this check where safeChainId is computed (using
requestUrl and safeChainId) so only known/length-capped chain IDs are accepted.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 46aa58f9-f07f-436a-a9c9-4d7af4ee787a
📒 Files selected for processing (3)
packages/synapse-interface/CHANGELOG.mdpackages/synapse-interface/package.jsonpackages/synapse-interface/pages/api/rpc/[chainId].ts
✅ Files skipped from review due to trivial changes (2)
- packages/synapse-interface/package.json
- packages/synapse-interface/CHANGELOG.md
Summary by CodeRabbit
Bug Fixes
Chores
Tests
784a6e4: synapse-interface preview link
a053040: synapse-interface preview link