wallet-cli-4.12.0
Notice
Non-mandatory upgrade
New Features
Change
-
Chain governance and super-representative operation come to the TypeScript CLI.
proposal list/showread chain-parameter proposals and are open to anyone, whileproposal create/approve/deleterequire a registered witness; proposals are expressed in named chain parameters rather than raw numeric keys, and a created proposal's id is resolved from a snapshot taken before submission instead of guessed from the list afterwards.witness create/update/set-brokerageregister and operate a super representative. Contract governance follows the same path:contract clear-abi,contract set-origin-energy-limit,contract set-user-resource-percent, andcontract create2for deterministic deployment addresses. Every write goes through the shared transaction pipeline, so--dry-run,--build-only,--sign-only,--permission-id, and multi-sig behave exactly as they do for transfers. (#972, #975) -
TRC10 issuance and the protocol-level Bancor exchange are now first-class commands.
asset issue/update/participate/unfreeze/info/listcover the life of a TRC10 token (transfers continue to go throughtx send), andexchange create/inject/withdraw/trade/show/listdrive TRON's on-chain exchange. These reads are fetched and parsed losslessly, so an int64total_supplyorfrozen_amountabove 2^53 is reported exactly as a decimal string rather than rounded — sampling 1,400 mainnet assets found 252 above that bound. Reads are bound to the id asked for and to the protocol's precision range, and issuance still refuses a supply above 2^53 because java-tron cannot parse a numeric string into that field on the non-visible broadcast path. (#972, #975) -
Web3 keystore import and export, with an audit log for what left the machine.
import keystorereads a standard Web3 v3 keystore file: the file is read and structurally validated before either password is asked for, so a mistyped path costs no typing, and both passwords — the file's own and the local master password — remain hidden-TTY-only.backup --keystorewrites an account out in the same format, andbackup --recordslists the export audit log, which is preserved rather than overwritten when its contents cannot be read. The codec refuses adklenbelow 32, which would leave the MAC's key slice empty and let any password appear to open the file, and compares the MAC as bytes so an uppercase-hex file is accepted instead of being reported as a wrong password. (#975) -
The TypeScript CLI now ships as a standalone executable, with no Node.js install required.
npm run build:standalonecompiles a single self-contained binary, and a GitHub Actions workflow builds and verifies one per platform — Linux x64/arm64, macOS x64/arm64, and Windows x64 — each built on its native runner so the embedded Ledger HID addon matches, checked against a glibc 2.35 baseline on Linux, and smoke-tested before publication. A companion CI workflow runs the architecture check, type-check, tests, and bundle build on every pull request. With this release the TypeScript CLI covers the same TRON feature surface as the Java REPL; the two now differ in how you drive them, not in what they can do. (#977)
Bug Fixes
Change
-
A broadcast receipt quoted the node's transaction id instead of deriving its own. A TRON txID is the sha256 of the transaction body — derivable from the bytes that were signed, as
--sign-onlyalready did — but the broadcast path returned whatever the node echoed back. A dishonest node therefore chose which transaction--waitpolled for and which id the receipt named, so a receipt could end up describing someone else's confirmed transaction. The derived id now wins across all three broadcast paths (the pipeline,tx broadcast --file, and the multi-sig relay); a disagreement is reported as a warning rather than an error, because the transaction has already been sent. (#975) -
Amounts in a
--waitreceipt lost precision above 2^53./wallet/gettransactioninfobyidwas still fetched through TronWeb's plainJSON.parse, so realized int64 quantities —unfreeze_amount,withdraw_amount, and the exchange amounts — were already rounded float64 values before the CLI saw them. This endpoint now follows the same lossless fetch and parse asgetAccount,getBlock,listwitnesses, andlistproposals. (#975) -
account activate --addressaccepted anything non-empty. The address was typed as a plain non-empty string rather than a TRON address, so a malformed value was only rejected once the node saw it. It is now validated locally, like every other address-taking command. Two documentation errors were corrected alongside it:contract deploy --build-onlydocumentedunsigned/unsignedHexwhile the command emitstx/hex, and the pagination inventory listedproposal show, which returns a single proposal, while omittingproposal list, which paginates. (#975)
Integrity Check
All jar files available in this release are signed via this GPG key:
- PUB: 1254 F859 D2B1 BD9F 66E7 107D F859 BCB4 4A28 290B
- UID: build@tron.network
From the download listings below you should see links to the downloadable jar files as well as sig signature files. To verify the authenticity of any jar file, grab the jar and sig files with the same prefix name and then execute the verification process: GPG signature verification