Skip to content

fix: harden wallet and agent security paths#75

Merged
nullxnothing merged 1 commit intomainfrom
fix/security-pr-cleanup-v2
Apr 13, 2026
Merged

fix: harden wallet and agent security paths#75
nullxnothing merged 1 commit intomainfrom
fix/security-pr-cleanup-v2

Conversation

@nullxnothing
Copy link
Copy Markdown
Owner

Consolidates corrected versions of the stale security PRs into one fresh branch from current main.\n\nIncluded fixes:\n- Stop returning exported private keys to the renderer; copy to clipboard only.\n- Use static own-property agent column mapping for agents:update.\n- Wrap default-wallet and email account deletion changes in DB transactions.\n- Validate environment variable names before writing .env files.\n- Correct PumpFun slippage basis-point conversion.\n- Zero temporary CSV key buffers after keypair creation.\n- Always clean recovery key material/abort controller after recovery runs.\n- Use random temp file names and restrictive mode for agent context/prompt temp files.\n- Ignore generated Anchor deploy keypairs.\n\nValidation:\n- pnpm run typecheck\n- pnpm test -- test/panels/AppSurfaces.dom.test.tsx\n- pnpm test

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant