EnvarPay 0.1.0a5 — security and payment recovery fixes
Pre-release
Pre-release
Security and original-payment recovery update.
- Require Starlette >=1.3.1 to address CVE-2026-48818 and CVE-2026-54283.
- Refuse recovery of an unresolved payment after the operator switches to a different network/asset.
- If an error response omitted the transaction hash, query the original approved seller instead of getting stuck on the local response; never sign or settle again.
- Includes the merged agent/role setup and configuration guides from 0.1.0a4 source.
120 tests passed on Starlette 1.7.0; Python 3.11/3.13 CI passed. Existing signed payloads and budget reservations are preserved. Real production payment enablement and platform rollout are separate acceptance steps.