v0.1.18 — Security audit fixes + test fix
What's Changed
Fixed
- 3-round multi-expert security audit — 30 fixes across 16 files (from v0.1.17 → v0.1.18)
- CI test fix —
test_gateway_refuses_production_without_verifiernow provides explicitaddressparam to match gateway's address-before-verifier validation order - Improved onboarding docs, error messages, and production TS example
- MCP server verification via glama.json
Security
- Header injection sanitization for chain/token/address fields
- Atomic wallet file writes with proper permissions
- Gateway rate limiting per IP
- Password strength validation (min 12 chars)
- SSRF protection for target_url
- Explicit X402_MODE requirement to prevent accidental test deployment
Full Changelog: v0.1.17...v0.1.18