Releases: molpha/sdk
Release list
v0.5.0
Minor Changes
-
d586e89: rename job IDs to feed IDs and unify the EVM verifier address
Feed terminology replaces job IDs across the public API, and feed derivation now
includes the quorum threshold:deriveJobId/deriveJobIdString→deriveFeedId/deriveFeedIdString
(now requiressignaturesRequired)jobIdoptions and params →feedId(requestSignedData,requestAndSubmit,
Solana client helpers, gateway auth message fields)- Solana account/PDA helpers updated for the feed-id layout
EVM verifier constants collapse to a single CREATE2 address shared by every
supported chain:MOLPHA_VERIFIER_*per-network constants,MOLPHA_VERIFIER_ADDRESSES, and
getMolphaVerifierAddress→MOLPHA_VERIFIER_ADDRESS
Patch Changes
-
f1e3cef: update dependencies
-
60f56af: Update idl
-
330f0f0: Authenticate private API node encryption keys before encrypting secrets.
MolphaGateway.requestSignedData({ encrypt })now fails closed unless selected
gateway node keys are verified or callers explicitly opt into unsafe development
behavior withallowUnverifiedNodeKeysForPrivateApi: true.MolphaSDKwires the
default verifier to Solana registry index accounts, comparing on-chain
secp256k1 key coordinates with selected gateway node keys before encryption. -
5aa17fe: update gateway url
v0.1.0
v0.4.2
Patch Changes
-
1131c0b: fix audit vulnerabilities in transitive dependencies via pnpm overrides
Force patched versions of vulnerable transitive dependencies:
ws→>=8.21.0(DoS via tiny fragments, GHSA-96hv-2xvq-fx4p)js-yaml→>=4.2.0(quadratic-complexity DoS, GHSA-h67p-54hq-rp68)esbuild→>=0.28.1(arbitrary file read on Windows dev server, GHSA-g7r4-m6w7-qqqr)
The
bigint-bufferadvisory (GHSA-3gc7-fjrx-p6mg, via@solana/spl-token) has
no patched release available and is ignored throughpnpm.auditConfig.ignoreGhsas.
v0.4.1
Patch Changes
-
dc65759: update the default gateway endpoint to
https://gateway.molpha.ioDEFAULT_GATEWAY_ENDPOINTnow points at the production Molpha gateway instead of the
previous dev IP address.
v0.4.0
Minor Changes
-
113b5d3: add a cached-context "short" flow to
MolphaGateway.requestSignedDataIntroduce
RoundContext(registryVersion,nodes,jobConfig) and a
gateway.prepareContext(jobId)helper that fetches these slow-changing round
inputs once. Pass them back viarequestSignedData({ ..., context })(also
accepted byrequestAndSubmit) to skip the prelude and run rounds as a single
gateway POST.contextis partial, so any omitted field is still fetched. The
default full flow now also fetches the registry version, node set, and job
config in parallel. -
d916cd6: rename the gateway round APIs to reflect that they request signed data
The gateway never executes anything on-chain — it returns a threshold-signed
data update. The methods and types are renamed accordingly:MolphaGateway.execute(...)→MolphaGateway.requestSignedData(...)MolphaSDK.executeAndSubmit(...)→MolphaSDK.requestAndSubmit(...)ExecuteOptions→RequestSignedDataOptionsExecuteContext→RoundContext
The gateway HTTP route (
POST /v1/jobs/{id}/execute) is unchanged.
Patch Changes
-
a1c15a5: wire wallet auth into
MolphaSDK.gateway.requestSignedDataMolphaSDKnow passes the wallet's gateway signer toMolphaGatewayas its
default, sosdk.gateway.requestSignedData({ jobId, apiConfig })authenticates
without an explicitsigner. Per-callsignerstill overrides the default.
StandaloneMolphaGatewayaccepts an optional thirddefaultSignerconstructor
argument; omitting it keeps the all-zero devauthSigbehavior.
v0.3.2
Patch Changes
- 9211268: ci: verify dev snapshot pipeline increments above latest
v0.3.1
Patch Changes
-
a1c15a5: wire wallet auth into
MolphaSDK.gateway.executeMolphaSDKnow passes the wallet's gateway signer toMolphaGatewayas its
default, sosdk.gateway.execute({ jobId, apiConfig })authenticates without
an explicitsigner. Per-callsignerstill overrides the default.
StandaloneMolphaGatewayaccepts an optional thirddefaultSignerconstructor
argument; omitting it keeps the all-zero devauthSigbehavior.
v0.3.0
Minor Changes
-
b381ffe: add EVM verifier address constants and tuple helpers
Export deployed Molpha verifier addresses for Ethereum Sepolia, Arbitrum Sepolia,
Avalanche Fuji, and BSC testnet, plus framework-agnostic helpers to convert
DataUpdateResultintoverify(DataUpdate, SchnorrSignature)contract arguments
for use with ethers or viem. -
113b5d3: add a cached-context "short" flow to
MolphaGateway.executeIntroduce
ExecuteContext(registryVersion,nodes,jobConfig) and a
gateway.prepareContext(jobId)helper that fetches these slow-changing round
inputs once. Pass them back viaexecute({ ..., context })(also accepted by
executeAndSubmit) to skip the prelude and run rounds as a single gateway POST.
contextis partial, so any omitted field is still fetched. The default full
flow now also fetches the registry version, node set, and job config in
parallel.
Patch Changes
-
b381ffe: improve gateway execution reliability and align API config hash defaults
canonicalizeAPIConfignow defaultsvalueTransformto an empty string instead ofmultiply:1e6, so API config hashing reflects explicit transforms only. Gateway execution now retries job-config fetches on transient404responses for newly created jobs, and gateway errors include backend-provided details for easier debugging of400,503, and other non-OK responses. -
113b5d3: add Starknet verifier address helpers and calldata builders
Expose the deployed Starknet Sepolia verifier address and helpers to convert a
gatewayDataUpdateResultinto Starknet verifierDataUpdateand
SchnorrSignaturecalldata structs.
v0.2.0
Minor Changes
-
d843e36: add
readPlan,readSubscription, andreadJobonMolphaSolanaClientOn-chain read helpers for plan, subscription, and job accounts (nullable, like
readFeed).getPlannow delegates toreadPlanand throws when missing. -
4e48226: make subscription payment explicit on
subscribe/extendSubscriptionsubscribeandextendSubscriptionnow require amaxPriceUsdcconfirmation
(USDC base units) so callers explicitly acknowledge the on-chain USDC charge.
The SDK reads the live plan price and aborts before sending the transaction if
it exceeds the confirmed maximum, and returns the amount charged aspricePaid.
AddedgetPlan(plan)to fetch the current price/terms for display beforehand.
Patch Changes
-
8f90138: require maxPriceUsdc confirmation for subscribe/extend
-
48878d9: align
deriveApiConfigHashwith node hashing (keccak256(JSON.stringify(canonicalApiConfig)))API config hashing now matches node-side verification by hashing the canonicalized
config JSON string directly (with SDK defaults applied), instead of JCS. -
41b0816: simplify sdk init, add api-config hasher