Skip to content

Commit

Permalink
fix!: Ledger nano doesn't work with cheqd transactions [DEV-1651] (#372)
Browse files Browse the repository at this point in the history
* ci: Make workflow cleanup choices easier

* ci: Fix linting error

* ci: Disable cleanup dry-run

* ci: Add automated semantic release using Goreleaser (#357)

Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

* build: Optimise Docker build (#365)

* chore(deps): Bump github.com/spf13/viper from 1.10.1 to 1.12.0 (#360)

Bumps github.com/spf13/viper from 1.10.1 to 1.12.0.

Release notes
Sourced from github.com/spf13/viper's releases.

v1.12.0
This release makes YAML v3 and TOML v2 the default versions used for encoding.
You can switch back to the old versions by adding viper_yaml2 and viper_toml1 to the build tags.
Please note that YAML v2 and TOML v1 are considered deprecated from this release and may be removed in a future release.
Please provide feedback in discussions and report bugs on the issue tracker. Thanks!

What's Changed
Exciting New Features 🎉

Add etcd3 support to remote by @​sagikazarmark in spf13/viper#1356
Make YAML 3 the default by @​sagikazarmark in spf13/viper#1357
Make TOML 2 the default by @​sagikazarmark in spf13/viper#1358

Enhancements 🚀

chore: fix Error log calls in mergeMaps by @​wwade in spf13/viper#1341
Add MustBindEnv by @​meowfaceman in spf13/viper#1301

Dependency Updates ⬆️

build(deps): bump github/codeql-action from 1 to 2 by @​dependabot in spf13/viper#1336
build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0-beta.8 to 2.0.0 by @​dependabot in spf13/viper#1339
build(deps): bump github.com/mitchellh/mapstructure from 1.4.3 to 1.5.0 by @​dependabot in spf13/viper#1332
build(deps): bump github.com/pelletier/go-toml from 1.9.4 to 1.9.5 by @​dependabot in spf13/viper#1335
build(deps): bump github.com/fsnotify/fsnotify from 1.5.1 to 1.5.4 by @​dependabot in spf13/viper#1338
build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0 by @​dependabot in spf13/viper#1344
build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1 by @​dependabot in spf13/viper#1343
build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0 by @​dependabot in spf13/viper#1349

New Contributors

@​meowfaceman made their first contribution in spf13/viper#1301
@​wwade made their first contribution in spf13/viper#1341

Full Changelog: spf13/viper@v1.11.0...v1.12.0
v1.11.0

What's Changed
Exciting New Features 🎉

Experimental yaml v3 library support by @​sagikazarmark in spf13/viper#1273
Experimental toml v2 support by @​sagikazarmark in spf13/viper#1274
Experimental logger by @​sagikazarmark in spf13/viper#1275

Enhancements 🚀

Remove unnecessary operand by @​steviebps in spf13/viper#1213
Improve encoding layer by @​sagikazarmark in spf13/viper#1167
Allow merging configs with different types of leaf values by @​illarion in spf13/viper#1181

Bug Fixes 🐛

Disable race detector on windows by @​sagikazarmark in spf13/viper#1269

... (truncated)

Commits

4322cf2 feat: make toml2 the default
8d02999 feat: make yaml3 the default
7c35aa9 chore(deps): update yaml3
433821f feat: add etcd3 support to remote
2080d43 chore: update crypt
da55858 chore: fix Error log calls in mergeMaps
f50ce90 Add in MustBindEnv.
3b836e5 build(deps): bump github.com/subosito/gotenv from 1.2.0 to 1.3.0
5d65186 build(deps): bump github.com/pelletier/go-toml/v2 from 2.0.0 to 2.0.1
9f85518 build(deps): bump github.com/spf13/cast from 1.4.1 to 1.5.0
Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

* chore(deps): Bump github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25 (#359)

Bumps github.com/lestrrat-go/jwx from 1.2.20 to 1.2.25.

Release notes
Sourced from github.com/lestrrat-go/jwx's releases.

v1.2.25
v1.2.25 23 May 2022
[Bug Fixes][Security]
  * [jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
    where the unpad operation might remove more bytes than necessary ([#744](lestrrat-go/jwx#744))
    This affects all jwx code that is available before v2.0.2 and v1.2.25.

v1.2.24
v1.2.24 05 May 2022
[Security]
  * Upgrade golang.org/x/crypto ([#724](lestrrat-go/jwx#724))

v1.2.23
v1.2.23 13 Apr 2022
[Bug fixes]
  * [jwk] jwk.AutoRefresh had a race condition when `Configure()` was
    called concurrently ([#686](lestrrat-go/jwx#686))
    (It has been patched correctly, but we may come back to revisit
     the design choices in the near future)

v1.2.22
v1.2.22 08 Apr 2022
[Bug fixes]
  * [jws] jws.Verify was ignoring the `b64` header when it was present
    in the protected headers ([#681](lestrrat-go/jwx#681)). Now the following should work:
  jws.Sign(..., jws.WithDetachedPayload(payload))
  // previously payload had to be base64 encoded
  jws.Verify(..., jws.WithDetachedPayload(payload))
(note: v2 branch was not affected)


v1.2.21
v1.2.21 30 Mar 2022
[Bug fixes]
  * [jwk] RSA keys without p and q can now be parsed.




Changelog
Sourced from github.com/lestrrat-go/jwx's changelog.

v1.2.25 23 May 2022
[Bug Fixes][Security]

[jwe] An old bug from at least 7 years ago existed in handling AES-CBC unpadding,
where the unpad operation might remove more bytes than necessary (#744)
This affects all jwx code that is available before v2.0.2 and v1.2.25.

v1.2.24 05 May 2022
[Security]

Upgrade golang.org/x/crypto (#724)

v1.2.23 13 Apr 2022
[Bug fixes]

[jwk] jwk.AutoRefresh had a race condition when Configure() was
called concurrently (#686)
(It has been patched correctly, but we may come back to revisit
the design choices in the near future)

v1.2.22 08 Apr 2022
[Bug fixes]


[jws] jws.Verify was ignoring the b64 header when it was present
in the protected headers (#681). Now the following should work:
jws.Sign(..., jws.WithDetachedPayload(payload))
// previously payload had to be base64 encoded
jws.Verify(..., jws.WithDetachedPayload(payload))
(note: v2 branch was not affected)


v1.2.21 30 Mar 2022
[Bug fixes]

[jwk] RSA keys without p and q can now be parsed.




Commits

ad8c29d merge develop/v1 (#747)
e38f677 Merge develop/v1 (#727)
baba561 Merge branch 'develop/v1' into v1
8ff6c75 Update Changes
ea97e8c Fix race in jwk.AutoRefresh (#686)
f4701e1 Update Changes
e831228 Fix jws.Verify not respecting the b64 header in the protected headers (#683)
b66a2cb backport: Update golangci lint (#679) (#680)
4899c32 reword error
dd9e4c4 Bump github.com/lestrrat-go/httpcc from 1.0.0 to 1.0.1 (#675)
Additional commits viewable in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

* chore(deps): Bump github.com/stretchr/testify from 1.7.1 to 1.8.0 (#362)

Bumps github.com/stretchr/testify from 1.7.1 to 1.8.0.

Commits

181cea6 impr: CallerInfo should print full paths to the terminal (#1201)
cf1284f Allow mock expectations to be ordered (#1106)
66eef0e fix: assert.MapSubset (or just support maps in assert.Subset) (#1178)
2fab6df Add WithinTimeRange method (#1188)
b5ce165 fixing panic in calls to assertion with nil m.mutex (#1212)
c206b2e Mock can be deadlocked by a panic (#1157)
1b73601 suite: correctly set stats on test panic (#1195)
ba1076d Add .Unset method to mock (#982)
c31ea03 Support comparing byte slice (#1202)
48391ba Fix panic in AssertExpectations for mocks without expectations (#1207)
Additional commits viewable in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

* fix!: Ledger nano doesn't work with cheqd transactions

* build: Multi-platform AMD64/ARM64 for Linux (#366)

Signed-off-by: Andrew Nikitin <andrew.nikitin@evernym.com>
Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Andrew Nikitin <andrew.nikitin@evernym.com>
Co-authored-by: Ankur Banerjee <ankurdotb@users.noreply.github.com>
Co-authored-by: Andrew Nikitin <andrew.nikitin@cheqd.io>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
  • Loading branch information
4 people committed Oct 14, 2022
1 parent 8d88081 commit fe6ae43
Show file tree
Hide file tree
Showing 7 changed files with 54 additions and 474 deletions.
5 changes: 3 additions & 2 deletions .github/workflows/codeql.yml
Expand Up @@ -31,14 +31,15 @@ jobs:

- uses: actions/setup-go@v3
with:
go-version: 1.17
go-version-file: ./go.mod

- uses: actions/checkout@v3
with:
fetch-depth: 0 # Required to fetch version

- name: Build
run: make proto-gen build
run: |
make proto-gen build
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
39 changes: 19 additions & 20 deletions go.mod
Expand Up @@ -7,25 +7,25 @@ require (
github.com/btcsuite/btcutil v1.0.3-0.20201208143702-a53e38424cce
github.com/cosmos/cosmos-sdk v0.45.5
github.com/cosmos/ibc-go/v3 v3.1.0
github.com/gabriel-vasile/mimetype v1.4.1
github.com/gabriel-vasile/mimetype v1.4.0
github.com/go-ozzo/ozzo-validation/v4 v4.3.0
github.com/gogo/protobuf v1.3.3
github.com/golang/protobuf v1.5.2
github.com/google/uuid v1.3.0
github.com/gorilla/mux v1.8.0
github.com/grpc-ecosystem/grpc-gateway v1.16.0
github.com/lestrrat-go/jwx v1.2.25
github.com/multiformats/go-multibase v0.1.1
github.com/multiformats/go-multibase v0.0.3
github.com/rakyll/statik v0.1.7
github.com/spf13/cast v1.5.0
github.com/spf13/cobra v1.5.0
github.com/spf13/pflag v1.0.5
github.com/spf13/viper v1.12.0
github.com/stretchr/testify v1.8.0
github.com/tendermint/tendermint v0.34.20
github.com/tendermint/tendermint v0.34.19
github.com/tendermint/tm-db v0.6.6
google.golang.org/genproto v0.0.0-20220519153652-3a47de7e79bd
google.golang.org/grpc v1.48.0
google.golang.org/grpc v1.46.2
)

require (
Expand All @@ -37,7 +37,7 @@ require (
github.com/asaskevich/govalidator v0.0.0-20200108200545-475eaeb16496 // indirect
github.com/beorn7/perks v1.0.1 // indirect
github.com/bgentry/speakeasy v0.1.0 // indirect
github.com/btcsuite/btcd v0.22.1 // indirect
github.com/btcsuite/btcd v0.22.0-beta // indirect
github.com/cespare/xxhash v1.1.0 // indirect
github.com/cespare/xxhash/v2 v2.1.2 // indirect
github.com/coinbase/rosetta-sdk-go v0.7.0 // indirect
Expand All @@ -59,7 +59,7 @@ require (
github.com/felixge/httpsnoop v1.0.1 // indirect
github.com/fsnotify/fsnotify v1.5.4 // indirect
github.com/go-kit/kit v0.12.0 // indirect
github.com/go-kit/log v0.2.1 // indirect
github.com/go-kit/log v0.2.0 // indirect
github.com/go-logfmt/logfmt v0.5.1 // indirect
github.com/go-playground/universal-translator v0.18.0 // indirect
github.com/goccy/go-json v0.9.7 // indirect
Expand All @@ -82,17 +82,16 @@ require (
github.com/inconshreveable/mousetrap v1.0.0 // indirect
github.com/jmhodges/levigo v1.0.0 // indirect
github.com/keybase/go-keychain v0.0.0-20190712205309-48d3d31d256d // indirect
github.com/klauspost/compress v1.15.1 // indirect
github.com/klauspost/compress v1.13.6 // indirect
github.com/leodido/go-urn v1.2.1 // indirect
github.com/lestrrat-go/backoff/v2 v2.0.8 // indirect
github.com/lestrrat-go/blackmagic v1.0.0 // indirect
github.com/lestrrat-go/httpcc v1.0.1 // indirect
github.com/lestrrat-go/iter v1.0.1 // indirect
github.com/lestrrat-go/option v1.0.0 // indirect
github.com/lib/pq v1.10.6 // indirect
github.com/libp2p/go-buffer-pool v0.1.0 // indirect
github.com/lib/pq v1.10.4 // indirect
github.com/libp2p/go-buffer-pool v0.0.2 // indirect
github.com/magiconair/properties v1.8.6 // indirect
github.com/mattn/go-colorable v0.1.12 // indirect
github.com/mattn/go-isatty v0.0.14 // indirect
github.com/matttproud/golang_protobuf_extensions v1.0.1 // indirect
github.com/mimoo/StrobeGo v0.0.0-20181016162300-f8f6d4d2b643 // indirect
Expand All @@ -104,36 +103,36 @@ require (
github.com/multiformats/go-base32 v0.0.3 // indirect
github.com/multiformats/go-base36 v0.1.0 // indirect
github.com/pelletier/go-toml v1.9.5 // indirect
github.com/pelletier/go-toml/v2 v2.0.2 // indirect
github.com/pelletier/go-toml/v2 v2.0.1 // indirect
github.com/petermattis/goid v0.0.0-20180202154549-b0b1615b78e5 // indirect
github.com/pkg/errors v0.9.1 // indirect
github.com/pmezard/go-difflib v1.0.0 // indirect
github.com/prometheus/client_golang v1.12.2 // indirect
github.com/prometheus/client_golang v1.12.1 // indirect
github.com/prometheus/client_model v0.2.0 // indirect
github.com/prometheus/common v0.34.0 // indirect
github.com/prometheus/common v0.32.1 // indirect
github.com/prometheus/procfs v0.7.3 // indirect
github.com/rcrowley/go-metrics v0.0.0-20200313005456-10cdbea86bc0 // indirect
github.com/regen-network/cosmos-proto v0.3.1 // indirect
github.com/rs/cors v1.8.2 // indirect
github.com/rs/zerolog v1.27.0 // indirect
github.com/rs/zerolog v1.23.0 // indirect
github.com/sasha-s/go-deadlock v0.2.1-0.20190427202633-1595213edefa // indirect
github.com/spf13/afero v1.8.2 // indirect
github.com/spf13/jwalterweatherman v1.1.0 // indirect
github.com/subosito/gotenv v1.4.0 // indirect
github.com/subosito/gotenv v1.3.0 // indirect
github.com/syndtr/goleveldb v1.0.1-0.20200815110645-5c35d600f0ca // indirect
github.com/tecbot/gorocksdb v0.0.0-20191217155057-f0fad39f321c // indirect
github.com/tendermint/btcd v0.1.1 // indirect
github.com/tendermint/crypto v0.0.0-20191022145703-50d29ede1e15 // indirect
github.com/tendermint/go-amino v0.16.0 // indirect
github.com/zondax/hid v0.9.0 // indirect
go.etcd.io/bbolt v1.3.6 // indirect
golang.org/x/crypto v0.0.0-20220525230936-793ad666bf5e // indirect
golang.org/x/net v0.0.0-20220624214902-1bab6f366d9e // indirect
golang.org/x/sys v0.0.0-20220615213510-4f61da869c0c // indirect
golang.org/x/term v0.0.0-20220526004731-065cf7ba2467 // indirect
golang.org/x/crypto v0.0.0-20220427172511-eb4f295cb31f // indirect
golang.org/x/net v0.0.0-20220520000938-2e3eb7b945c2 // indirect
golang.org/x/sys v0.0.0-20220520151302-bc2c85ada10a // indirect
golang.org/x/term v0.0.0-20210927222741-03fcf44c2211 // indirect
golang.org/x/text v0.3.7 // indirect
google.golang.org/protobuf v1.28.0 // indirect
gopkg.in/ini.v1 v1.66.6 // indirect
gopkg.in/ini.v1 v1.66.4 // indirect
gopkg.in/yaml.v2 v2.4.0 // indirect
gopkg.in/yaml.v3 v3.0.1 // indirect
nhooyr.io/websocket v1.8.6 // indirect
Expand Down

0 comments on commit fe6ae43

Please sign in to comment.