Release Notes - v0.17.0
このコンテンツはまだ日本語に翻訳されていません。
v0.17.0 - hardware signing, wallet reliability, and release hardening
Section titled “v0.17.0 - hardware signing, wallet reliability, and release hardening”- Date: 2026-09-19
- Version: 0.17.0
- Release comparison: v0.16.0…v0.17.0
Summary
Section titled “Summary”This release introduces optional hardware security module signing, strengthens wallet and storage protections, expands Cardano network compatibility, and makes release artifacts and publishing workflows more predictable.
✨ New Features
Section titled “✨ New Features”- Added an optional PKCS#11 Ed25519 hardware security module signer behind the
pkcs11build tag. Configuration selects the module, token, slot, PIN, and allowed keys; signing remains on the token, and PKCS#11 keys do not support CIP-8. - Standardized address derivation on account stake key index
0while allowing payment key indexes to vary, producing consistent account addresses. - Expanded wallet governance with a read-only action browser at
GET /wallet/governance-actions, including search, pagination, lifecycle statuses, vote tallies, explorer links, and clear loading and error states. - Introduced staking and governance delegation flows that verify pools and DReps through the node, preview and confirm transactions, and withdraw rewards.
- Extended hardware-wallet support with shared air-gapped QR, CBOR, scanner, modal, and fingerprint components for consistent signing flows.
- Enabled an optional CIP-30 and CIP-95 dApp connector through a Manifest V3 extension with per-origin grants, an approval queue, server-sent events, and
BURSA_CONNECTORconfiguration. - Integrated Ledger WebHID wallet onboarding with xpub-only access and on-device signing.
- Persisted idle auto-lock settings of
0,1,5,15, or30minutes throughGET /wallet/settings/auto-lockandPUT /wallet/settings/auto-lock, with a 15-minute fallback. - Provided persistent command-palette access across desktop and mobile applications.
- Offered opt-in wallet activity notifications through
GET /wallet/activityandGET /wallet/settings/notifications, with updates managed throughPUT /wallet/settings/notifications. - Connected Keystone hardware wallets through air-gapped QR onboarding and signing, using QR-only UI transport and extended fingerprint checks.
- Added a read-only stake-pool directory at
GET /wallet/poolswith search, pagination, and live saturation data. - Introduced transaction import, decoding, cosigning, and submission APIs with multisignature-aware threshold checks that prevent incomplete approvals.
- Expanded air-gapped hardware-wallet support with SeedSigner QR-only transport, extended fingerprint recovery, and staking transaction signing.
- Enabled opt-in NFT media through
nftmedia, persisted the setting, retrieved media from IPFS, bounded image validation, and exposed NFT endpoints. - Persisted Lean Storage history-expiry configuration, seeded from
BURSA_LEAN, withGET /wallet/settings/history-expiryandPUT /wallet/settings/history-expiry; changes take effect after restart. - Exposed
bursa.DecodeOpCertfor shared operational-certificate decoding, keeping certificate parsing consistent across callers. - Generated a 24-word BIP39 mnemonic through
GET /wallet/mnemonic/generate; the guided create-wallet flow requires acknowledgement and a three-word recovery-phrase re-entry challenge. - Introduced the
bursa kes-agentdaemon with serve-key and sign modes, framed Unix-socket protocols, control commands, secure-memory KES keys, a durable monotonic period guard, socket hardening, andkes_agentconfiguration. Socket permissions now useservice_socket_modeandcontrol_socket_mode. - Made Receive available during node bootstrap with locally derived addresses and
usage_known; the client suppresses unreliable classifications and returns HTTP503when CIP-30 usage methods are unavailable. - Added a local address book with
GET /wallet/contacts,POST /wallet/contacts, andDELETE /wallet/contactsendpoints, validation limits, corrupt-file fallback, a Contacts screen, and address selection in Send. - Delivered Receive-screen QR codes for the next unused address and individual addresses, with accessible toggles and full-address encoding.
- Published native desktop packages for each architecture: notarized macOS
.pkgfiles, signed Windows.msifiles with an optional WebView2 bootstrapper, and Linux and FreeBSD archives, together with artifact verification, attestation, Make targets, and documented signing environment requirements. - Exposed CIP-26 registry metadata and displayed curated token names, tickers, and decimals from
0through18, while retaining an on-chain fallback when registry metadata cannot override on-chain decimals. - Introduced Android and iOS mobile shells with foreground service support, lifecycle and network resilience, offline-aware polling and retries, mobile build tooling, and OS-specific build requirements.
- Improved browser wallet operation with a startup fallback when Buffer is unavailable, deferred Ledger WebHID loading, recoverable error boundaries, unified Stake tabs, clearer copy controls, a diagnostics proxy, Activity display and CSV export, and preserved delegation drafts.
- Stabilized transaction history with enriched fields,
GET /wallet/transactions/{hash}, Activity filters and details, CSV export, pending and pruned transaction handling, and CSV formula-injection protection. - Expanded extension contracts for CIP-30 and CIP-95 providers, accepted nullable
getCollateralresults, and documented exact HTTP(S) end-to-end origin and address encoding behavior. - Added Settings tabs, Portfolio Send and Receive actions, legacy route compatibility, and a nine-entry navigation structure.
- Enhanced wallet account management with BIP44 multi-account derivation, persistent storage, account APIs, and an account switcher.
- Delivered diagnostics APIs and interface views that export logs.
- Extended wallet support with native CIP-1854 multisig account derivation.
- Offered hardware signer paths for staking, governance, and multisig transactions.
- Refined operator workflows with five-item navigation, Pool Ops mode, and script-wallet handling that omits staking actions when no stake credential exists.
- Enabled Ledger and Trezor CIP-8 hardware message signing with COSE output.
- Improved wallet address derivation by using the selected payment and stake keys and respecting explicit
WithAddressIDvalues over derived defaults. - Introduced device-agnostic Ledger and Trezor hardware signing with device selection, consent checks for Trezor, multi-asset token bundles, and strict encoding validation.
- Added
POST /v1/signsupport fortype=opcert, including KES fields and cold signature responses, with policy and ACL checks and pool-key restrictions. - Delivered Cardanoscan links for Receive, Activity, Staking, and DRep, pool, transaction, and address identifiers; desktop webview links open in the operating system browser only after
httpsorhttpvalidation. - Refined mobile navigation with a responsive drawer and top bar that preserve focus and scroll behavior for keyboard and assistive technology users.
- Extended desktop wallet behavior with system tray minimization, tray status polling, native close and minimize interception, and the Linux runtime dependency required by the embedded webview.
- Introduced optional TPM 2.0 vault-key binding with PCR-bound mode, password fallback, vault format 2 migration, and status, enable, and disable endpoints.
- Preserved progress for each bootstrap phase and download while improving sync status presentation in the UI.
- Expanded stake pool operations with a toolkit,
/wallet/pool/*endpoints, an Operate UI, metadata workflows, and operational-certificate workflows. - Enabled CIP-8 verification and air-gap transaction signing; the flow now requires a signer sidecar and supports vault-backed wallet lifecycle management.
- Implemented CIP-30 extension negotiation with
apiVersion1,getExtensions, optional CIP-95 support, and registration tests for a restrictive content security policy. - Exposed
GET /wallet/rewardsand a Rewards UI with provisional empty history.
⛓️💥 Breaking Changes
Section titled “⛓️💥 Breaking Changes”- Changed HD-derived signing key exports to extended Ed25519-BIP32 envelopes, preserved non-extended pool-cold exports, and added identity, migration, and envelope contract guidance.
- Replaced legacy testnet API network names with the canonical
mainnet,preprod, andpreviewvalues and updated the OpenAPI and Swagger documentation. - Switched Linux and FreeBSD CLI release assets to
tar.gzarchives, published macOS desktop packages for each architecture as.pkgfiles, pinned the macOS runner, and attested the uploaded asset. - Stopped mobile workflows from running automatically on version tags, made mobile builds manual, and aligned macOS installer signing with
APPLE_CERTIFICATE_PASSWORD. - Required a durable KES
guard_fileand preserved the anti-rollback floor across restarts. - Raised the root Go requirement for source builds to
1.26.0or later, updated the Prometheus client to1.24.1, and upgradedgolang.org/x/syncfrom0.22.0to0.23.0. - Corrected pool-cold verification-key derivation, exported canonical
StakePoolVerificationKey_ed25519andStakePoolSigningKey_ed25519envelope types, and continued loading legacy Shelley-suffixed types. - Made
cert op-certemit the canonicalNodeOperationalCertificateCBOR envelope, including the cold verification key. - Reworked native-script signature validation to verify Ed25519 witnesses cryptographically, added
messageandpublic_keysAPI fields, and added the CLI--public-keysflag with mutually exclusive--messageand--message-hexflags. - Returned HTTP
400when clients submitted invalid mnemonics toPOST /wallet. - Raised the
ui/webtest and coverage tooling from the3.xline to Vitest5.0.0, which requires environments that satisfy the upgraded Node.js and Vite engine requirements. - Required UI development environments to meet the Node.js engine requirements introduced by Vite
8.1.5, Vitest4.1.10, andcoverage-v84.1.10. - Changed multisig accounts into first-class vault wallets, migrated legacy
multisig.jsonfiles, requiredvault_passwordforPOST /wallet/multisig, returnedWalletView, replacedDELETE /wallet/multisig/{id}withDELETE /wallet/{id}, and integrated multisig wallets with Send. - Moved the DRep directory to the node’s paginated endpoint, added retired, expired, and predefined semantics plus metadata URL, metadata and voting-power display, broader identifier search, and CIP-129 validation, and changed the
/wallet/drepsrow schema. - Rejected trailing CBOR bytes in key and operational-certificate decoders; extended Ed25519 and cardano-cli VRF envelopes now validate the embedded public identity against the derived identity and return the derived identity.
- Protected non-loopback legacy API exposure with TLS and bearer JWT or JWKS authentication. The API now binds to
127.0.0.1by default and supports YAMLapi.addressandAPI_LISTEN_ADDRESSoverrides,api.jwt_secret,api.jwks_url, optional issuer and audience claims, TLS certificate and key settings, protected sensitive routes, no-cache secret responses, POST-only/api/wallet/create, request-size limits, and updated Swagger and OpenAPI descriptions. - Removed unemitted
TxSummary.kindunion values and deadImportTransactionwarning handling. - Made CLI metadata hashes reflect exact file bytes rather than JCS serialization, and rejected pool margin values that are NaN, infinite, negative, or greater than
1. - Standardized mnemonic derivation to use bytes and returned
ErrInvalidMnemonicfor invalid mnemonics. - Enforced monotonic operational-certificate issue counters through
off,warn, andenforcemodes with durable SQLite persistence. - Advanced Cardano compatibility to
gouroboros0.205.5; changedNativeScriptNofK.Ntoint64, exposedPoolMetadataHash, and moved the UI to themodernc.org/sqlitedriver. - Derived the wallet network from
/statusand removed the network selector fromAddWallet; clients now use the node’s reported network. - Corrected air-gap operational-certificate signing payloads to use
OpCertSignableBytes.
🔐 Security and Reliability
Section titled “🔐 Security and Reliability”- Updated
github.com/blinklabs-io/gouroborosfrom0.186.0to0.189.1and refreshed related modules, bringing upstream corrections for local state queries, Leios fetch, Conway withdrawals, Byron EBB handling, and chain synchronization shutdown. - Improved Docker Hub and GHCR publishing with
docker/login-action4.6.0, scoped Buildx configuration to the publishing step, and clarified Docker Hub OIDC errors. - Migrated memory locking from
syscall.Mlockandsyscall.Munlocktox/sys/unixfor BSD builds and added cross compilation checks for darwin/arm64, FreeBSD amd64/arm64, Linux amd64/arm64, and Windows amd64/arm64. - Coordinated
ch-go0.65.0withclickhouse-go/v22.32.0in the UI to avoid compress API incompatibility and addressGO-2025-3603. - Refined the SQLite layer through
modernc.org/sqlite1.58.0from1.57.0, with defensive DSN handling, changed virtual table registration behavior, related module updates, and SQLite durability fixes. - Bounded BC-UR camera decoding by part, total bytes, part count, sequence, frame, and elapsed time; terminal errors stop processing and clean up camera resources.
- Stabilized Docker manifest publishing for multiple architectures by composing versioned manifests from published architecture tags before applying floating aliases, preserving attestation digests, and adding contract tests.
- Advanced
github.com/blinklabs-io/gouroborosfrom0.193.0to0.193.3with peer discovery, consensus, ledger, governance, and local state query fixes. - Improved null-origin Shelley header decoding compatibility by upgrading
github.com/blinklabs-io/gouroborosfrom0.197.0to0.202.2. - Hardened Windows SQLite URI and path handling and file permissions, bounded script validation and UI request bodies, improved vault durability error reporting, protected wallet files, strengthened multisig migration, bounded activity and notifier lifetimes, and corrected connector unpair errors.
- Blocked plaintext software keys on listeners not bound to loopback addresses unless operators explicitly enable
allow_insecure_file_backendandSIGNER_ALLOW_INSECURE_FILE_BACKEND, and documented the required signer packaging and operating specifications. - Corrected SSH, ACME, and x509roots behavior by updating
golang.org/x/cryptofrom0.54.0to0.55.0. - Enforced a 30-second read limit for signer requests and rejected malformed signatures before reading request bodies.
- Refined SQLite date and time handling with the documented
_texttotimebehavior through themodernc.org/sqlite1.54.0update. - Secured the UI by pinning its vulnerable TOML dependency to
3.0.0. - Resolved Byron delegation signature and validity interval problems by updating
github.com/blinklabs-io/gouroborosfrom0.192.2to0.193.0. - Applied operation-aware signer policies with allowed certificate and voter lists, policies that can remove permissions for individual callers, and an external HTTP policy check that denies access when unavailable.
- Rejected detached transaction requests after 10 seconds and returned HTTP
503when the outcome remained unknown. - Validated SQLite-compatible DSN shorthand parameters across every parameter through the
modernc.org/sqlite1.55.0update. - Handled malformed native scripts safely and sorted decoded withdrawals deterministically.
- Protected wallet and vault routes from same-origin abuse and DNS rebinding.
- Enabled same-origin EventSource requests without an
Originheader while retaining loopback and cross-origin protections. - Refined dust-change transaction building after the Apollo
2.0.0and Shai upgrades: each transaction now makes one completion attempt, and Apollo absorbs sub-minimum pure-ADA change into fees. - Added retry handling for dust changes and checked
MaxTxSizebefore approval; later transaction construction adopted the single-attempt behavior above. - Enforced owner-only secret-key permissions and returned
ErrInsecureFileModefor insecure file modes. - Strengthened Byron body validation through the
github.com/blinklabs-io/gouroboros0.190.0upgrade. - Updated cryptographic libraries from
0.53.0to0.54.0and refreshed relatedx/*modules with current security and platform corrections. - Corrected DRep registration derivation to use the
retiredvalue instead of stale registration fields. - Bounded PKCS#11 signing waits by processing one signing request at a time, with a default 30-second timeout and cancellation handling.
- Hardened YAML merge processing by upgrading
js-yamlfrom4.3.1to4.3.2with resource limits. - Improved ledger, address, and block validation and KES handling through the
gouroboros0.190.0to0.192.2upgrade. - Refreshed terminal and system libraries by upgrading
golang.org/x/termfrom0.45.0to0.46.0andgolang.org/x/sysfrom0.47.0to0.48.0. - Secured CI checkout steps by disabling credential persistence after repository checkout.
- Verified signed macOS packages and added a manual exercise workflow for the verification path.
- Advanced
fxamacker/cborfrom2.9.2to2.9.3for the latest parser corrections. - Restored DRep-state wire compatibility and strengthened transaction-submission CBOR behavior by upgrading
github.com/blinklabs-io/gouroborosfrom0.183.0to0.186.0; the upstream Leios test network is now named Musashi. - Preserved the exact original transaction-body CBOR during UI signing, including non-canonical and indefinite-length bodies, while updating UI dependencies to Dingo
0.70.2, gouroboros0.202.2, and plutigo0.4.0. - Expanded Apollo to
2.1.1, carriedbody_set_tag_policythrough hardware-signing APIs and adapters, mapped SDKtagCborSets, supplied Trezor required signers, and retried Apollo dust-change non-convergence with bounded UTxO forcing. - Coordinated API and metrics server shutdown on cancellation with a 10-second shutdown window while preserving serving errors that race cancellation.
- Resolved YAML duplicate-key complexity through
js-yaml4.3.1. - Upgraded UI
pion/stunfrom3.1.2to3.1.5with DTLS and transport updates plus stronger handling for malformed STUN messages. - Pinned UI npm overrides to
protobufjs7.6.5anduuid11.1.1to clear runtime advisories. - Enhanced UI
pion/dtls/v3from3.1.2to3.1.4with Firefox compatibility and handshake robustness fixes. - Expanded Cardano compatibility by updating the root
github.com/blinklabs-io/gouroborosdependency from0.189.1to0.189.4; the release adds stake-address information queries,prototype2026-w30compatibility, Conway zero-withdrawal corrections, and Leios pool-registration CBOR handling. - Enforced signer caller policies from
signer.caller_policiesandsigner.policy_hook_urlat runtime; invalid caller policies now stop startup, and policy-hook errors deny signing. - Bounded signer replay-cache storage with fixed SHA-256 keys, entry and byte limits, collision-resistant caller and nonce separation, and fail-closed behavior when the cache is full.
- Rejected imported native-multisig submissions when the threshold is zero or unrecognized; valid submissions now require a threshold greater than zero and
signed_count >= threshold. - Updated UI
google.golang.org/grpcfrom1.82.1through1.83.1with xDS RBAC and buffering corrections. - Hardened imported native-script validation by matching witness scripts to the payment outputs being spent and rejecting unbound or decoy scripts while retaining shared payment and mint script cases.
- Refined UI
quic-gofrom0.59.0to0.59.1with stricter HTTP/3 trailer validation. - Resolved SQLite rollback corruption with
modernc.org/sqlite1.56.0. - Aligned UI networking with
google.golang.org/grpc1.83.2andgolang.org/x/net0.58.0. - Modernized the
keyfuncdependency for authentication key handling. - Strengthened the
jwksetdependency used for JSON Web Key Set processing. - Secured secret management workflows with
sops3.13.3. - Clarified bootstrap phases with readable status messages and added a
NodeNotReadyretry interface. - Configured PostgreSQL as a shared watermark and counter store through
type=postgres, DSN and DSNEnv resolution;/readyznow waits for required dependencies. - Validated the release against validator
10.30.4. - Rejected KES issue-counter overflow, validated VRF and KES key material and pool certificate inputs, and prevented secret-key loading from unsafe or oversized files or symlinks and reparse points.
- Matched request IDs across Keystone and SeedSigner air-gapped QR flows and failed closed when
crypto.randomUUIDwas unavailable. - Authenticated GCP-persisted legacy wallet operations with bearer JWT administrator authorization and required
API_JWT_ADMIN_SUBJECTS. - Aggregated concurrent wallet output errors deterministically, hardened Bech32, CBOR, and minimum-fee handling, and removed legacy wallet request password fields from API and OpenAPI schemas.
- Advanced
github.com/blinklabs-io/gouroborosfrom0.202.2to0.202.8with the related compatibility fixes. - Prevented
FakeEventSourcefrom delivering messages after close and clarified howuseAsynccaptures operation state. - Updated
golang.org/x/cryptofrom0.55.0to0.57.0and refreshed indirectx/*modules with security and platform updates.
Additional Changes
Section titled “Additional Changes”- Updated
actions/setup-javafrom5.4.0to5.5.0in the Windows signing workflow. - Expanded test coverage for key, certificate, address, CLI, version, and logging capabilities without changing runtime behavior.
- Refreshed
actions/setup-nodeto7.0.0in mobile, publishing, and UI workflows. - Raised
PostCSSinui/extensionfrom8.5.22to8.5.25. - Enhanced Google API integrations by updating
google.golang.org/apifrom0.293.0to0.295.0. - Improved
ui/extensiontest tooling by updating Vitest from4.1.10to4.1.11. - Completed the Windows signing workflow update to
actions/setup-java5.6.0from5.5.0. - Moved the Docker build stage to Go image
1.26.7-1from1.26.3-1. - Documented
AGENTS.mdguidance for meaningful code comments and comments on exported APIs. - Updated Docker publishing to use
docker/login-action4.5.1for Docker Hub and GHCR releases, including DHI.io OIDC support. - Restored UI builds by correcting an unreachable
shairevision. - Switched multi-architecture publishing to
docker buildx imagetools. - Narrowed the pre-beta CI scope to desktop by disabling mobile artifact builds and browser-extension validation, and refreshed nested UI dependencies.
- Repaired Linux and macOS webview wallet builds and added webview CI coverage.
- Aligned the UI Dingo and Go toolchain with related dependency updates, including Go
1.26.7. - Expanded nilaway coverage to the UI module and hardened nil checks.
- Advanced
google.golang.org/apifrom0.286.0to0.290.0. - Modernized browserslist and its browser database.
- Adjusted
ui/webdependencies by upgrading PostCSS andnanoid. - Refreshed
ui/web’sbrace-expansiondependency. - Elevated
google.golang.org/apifrom0.295.0to0.297.0. - Updated OpenTelemetry Go from
1.44.0to1.45.0, including logging and OTLP endpoint compatibility changes. - Upgraded
docker/metadata-actionfor container publishing. - Strengthened
ui/extensionby upgrading itsbrace-expansiondependency. - Refined
ui/webYAML parsing by upgradingjs-yaml. - Aligned the UI
grpcdependency with the release’s updated interfaces. - Completed the Windows signing workflow update by upgrading
actions/setup-javafrom5.7.0to6.0.0. - Modernized artifact uploads by upgrading
actions/upload-artifactfrom5.0.0to7.0.1; self-hosted runners must meet the newer action requirements. - Removed duplicate extension forwarding tests.
- Adjusted the Windows signing workflow by upgrading
actions/setup-javafrom5.3.0to5.4.0. - Advanced the Windows signing workflow by upgrading
actions/setup-javafrom5.6.0to5.7.0. - Refreshed indirect
ui/webbrace-expansiondependencies. - Elevated
google.golang.org/apifrom0.291.0to0.292.0. - Updated the
ui/webip-addressdependency from10.2.0to10.4.0. - Expanded WebTransport dependency support through the release’s dependency upgrades.
- Refined Google API dependencies by updating root
google.golang.org/apifrom0.292.0to0.293.0and refreshing related Google auth, enterprise-certificate-proxy, and genproto modules. - Standardized CI on Go
1.26.xby removing Go1.25.x; updated Vitest 5 mocks to class-based constructors and explicitNotificationPermissiontyping. - Pinned the UI module to a published Bursa pseudo-version instead of a local
../replacement, and improved connector subscription test cleanup. - Upgraded binary, Docker image, and manifest attestations to
actions/attest4.2.0, including upstream digest and checksum compatibility fixes. - Corrected Google API universe-domain transport through regenerated clients and updated
google.golang.org/apifrom0.290.0to0.291.0. - Modernized publishing workflows by updating
docker/login-actionfrom4.2.0to4.4.0. - Advanced publish attestations from
actions/attest4.1.0to4.1.1. - Expanded frontend capability coverage for router, password, drawer, wallet switching, migration, and operate/SPO flows.
- Verified Vite output at
ui/web/dist, addedwebui-embedand restore Make targets, embedded the real UI in binary, package, mobile, and Windows builds, and failed builds that retain placeholder UI. - Completed the publish attestation update to
actions/attest4.2.2. - Updated test suites from
github.com/stretchr/testify1.11.1to1.12.0. - Refreshed the UI extension
brace-expansiondependency from1.1.16to1.1.18, including its nested dependency from5.0.8to5.0.9. - Addressed a development dependency advisory by updating UI
nanoidfrom3.3.16to3.3.18. - Elevated
actions/setup-gofrom6.5.0to7.0.0across CI workflows. - Migrated wallet messaging with clearer stopped-node errors and disabled-Send reasons, and removed upstream tracker references from user-facing notes.
- Improved Google Secret Manager integration by updating
cloud.google.com/go/secretmanagerfrom1.20.0to1.21.0. - Upgraded
docker/build-push-actionfrom7.2.0to7.3.0across CI, mobile, and publishing workflows. - Replaced the UI’s Apollo implementation with Salvionied Apollo v2 and updated the related context, dispatcher, and dependency APIs.
- Enhanced lint workflows by updating
golangci/golangci-lint-actionfrom9.2.1to9.3.0. - Bounded Linux apt retries and timeouts in webview CI.
- Raised the Android emulator runner to
2.38.0. - Modernized UI linting with ESLint 9 flat configuration, an ESM package, and the
eslint .command. - Pinned the nested UI Bursa dependency to the current main commit and refreshed its transitive dependencies.
- Completed mobile build cleanup for Android API 35 timeouts, added an iOS Application Support migration marker, and introduced mobile contract CI.
- Published signed Android APK and AAB artifacts for tags; required Android keystore secrets, derived version codes from tags, attested artifacts, and ran arm64 emulator wallet smoke tests.
- Clarified full-node wallet setup in
ui/README.mdand linked it from the root README. - Separated iOS app and framework modules by setting
PRODUCT_MODULE_NAME=BursaAppand linking-lresolv. - Removed the UI
gouroborosreplacement override and aligned the Dingo, gouroboros, and plutigo dependency stack. - Advanced Docker Buildx setup from
4.2.0to4.3.0. - Pinned Android Build Tools to
35.0.0. - Disabled Android release jobs by default; set
BURSA_ANDROID_ENABLED=trueto enable them. - Updated
actions/checkoutfrom7.0.0to7.0.1. - Refreshed the Windows signing workflow by upgrading
actions/setup-javafrom6.0.0to6.0.1. - Specified
[email protected]as the contact address in the Trezor manifest. - Exported the shared
ExtractTxBodyCborhelper without changing transaction behavior. - Refined test dependencies by updating
github.com/stretchr/testifyfrom1.12.0to1.12.1and refreshing YAML support. - Modernized artifact downloads by upgrading
actions/download-artifactfrom7.0.0to8.0.1, including digest verification and decompression behavior.
Docs authored by Doc Holiday