Skip to content

@wasit-dev/cli@0.3.0

Choose a tag to compare

@dzakwannajmi dzakwannajmi released this 06 Sep 05:29
· 70 commits to main since this release

Running wasit with no arguments in a terminal now opens an interactive dashboard. Adds wasit wallet for setting up the testnet keys the check runners read from .env.

Install

npm install -g @wasit-dev/cli@0.3.0
wasit

What changed in this package

  • Interactive dashboard. A menu over the three check runners, a catalogue browser and a wallet screen, driven by arrow keys. A run shows a live elapsed timer and per-check progress, ends with total and average timing, and saves to wasit-<protocol>-<timestamp>.json with s — the same shape --json prints. A misconfigured run gets its own error screen rather than a red line under an otherwise-empty checklist. Piped or in CI, wasit still prints help, so nothing that scripts it today changes behaviour.
  • wasit wallet — status, create, fund. There is deliberately no --network flag: Friendbot, the printed USDC issuer and the whole idea of a disposable generated key only make sense on testnet. XLM funding via Friendbot is fully automatic. USDC is not, and the command says so rather than pretending otherwise — the trustline is opened for you, but a balance needs one visit to Circle's faucet or a configured WASIT_USDC_DISTRIBUTOR_SECRET, because no scriptable testnet USDC faucet exists for Stellar.
  • wasit wallet status --role mpp-channel is now rejected up front. COMMITMENT_SECRET_HEX is a raw hex seed with no on-chain account, which the help text already said; the command accepted the role anyway and then crashed deriving an address for it.
  • A malformed key in .env no longer kills the process. In the dashboard it used to escape as an unhandled rejection and terminate the process from under Ink's renderer, leaving the wallet screen frozen on its spinner. All paths now name the offending variable and exit 2, and never echo the rejected value.
  • .env written from the dashboard is 0600 and atomic (temp file plus rename), so an interrupted write cannot truncate a file holding Stellar secrets, and an existing world-readable .env is tightened on the next write.
  • Friendbot's "this account already exists" response is no longer reported as "Funded: 10,000 XLM."
  • q unmounts Ink instead of calling process.exit, so the terminal gets its cursor back. Ctrl+C still exits 130 immediately, by design.

Compatibility

Node.js >=24. Requires @wasit-dev/core@^0.3.0, installed automatically. Exit codes are unchanged: 0 every check that ran conformed, 1 at least one conformance failure, 2 at least one check produced no verdict. A run with both still exits 1 — a real finding outranks a missing one.

Known issues

Same nested Stellar SDK advisories as @wasit-dev/core — upstream peer ranges, no downstream fix. See SECURITY.md.

Links

CHANGELOG · npm · Full diff