Pinned upstream dependency review required
| Dependency |
Pinned |
Latest upstream |
Status |
| Node LTS |
26.10.0 |
24.21.0 |
review required |
| pnpm |
12.5.1 |
12.6.0 |
review required |
| Rust stable |
1.98.1 |
1.98.1 |
current |
| rustup |
1.29.1 |
1.29.1 |
current |
| Dash Evo SDK |
4.1.1 |
4.1.1 |
current |
| wasm-bindgen |
0.2.128 |
0.2.129 |
review required |
| Dash Orchard tag |
dashified-0.14.1 |
dashified-0.14.1 |
current |
| Dash Orchard commit |
38ac9c19a2df7bf3eeadc22ab23053e8fd538828 |
38ac9c19a2df7bf3eeadc22ab23053e8fd538828 |
current |
| Dash note-encryption reviewed source |
9f7e93d42cef839d02b9d75918117941d453f8cb |
9f7e93d42cef839d02b9d75918117941d453f8cb |
current |
| blahaj |
0.6.0 |
0.6.0 |
current |
| Codex32 |
0.1.0 |
0.1.0 |
current |
| SSKR |
0.12.0 |
0.12.0 |
current |
| Gordian Envelope |
0.43.0 |
0.43.0 |
current |
| Blockchain Commons components |
0.31.1 |
0.31.1 |
current |
| qr |
0.7.0 |
0.7.0 |
current |
| uqr |
0.1.3 |
0.1.3 |
current |
| Playwright |
1.63.0 |
1.63.0 |
current |
| SLIP-39 reference source |
17fcce14736afe498871d3018e4fa9330443471a |
17fcce14736afe498871d3018e4fa9330443471a |
current |
| SeedSigner SeedQR source |
b225ae77e9251a813cf2bd61e7874629d6f3cb10 |
cfaf443a5f19e3a3e2b2c7be7572ae3924142c0e |
review required |
Package rows compare exact local pins with their registries; source rows compare the reviewed commit with the repository default-branch head.
The dashpay/zcash_note_encryption row compares the pinned revision with the dedicated repository default-branch head. A differing head triggers review only when the GitHub compare includes src/, Cargo.toml, Cargo.lock, or build.rs; documentation and CI-only commits do not create a cryptographic update alert. A response at GitHub's 300-file limit fails closed for review. This checker never updates cryptographic dependencies.
Note-encryption comparison: main head matches the audited pin.
Pinned upstream changes require a reviewed dependency pull request.
Pinned upstream dependency review required
26.10.024.21.012.5.112.6.01.98.11.98.11.29.11.29.14.1.14.1.10.2.1280.2.129dashified-0.14.1dashified-0.14.138ac9c19a2df7bf3eeadc22ab23053e8fd53882838ac9c19a2df7bf3eeadc22ab23053e8fd5388289f7e93d42cef839d02b9d75918117941d453f8cb9f7e93d42cef839d02b9d75918117941d453f8cb0.6.00.6.00.1.00.1.00.12.00.12.00.43.00.43.00.31.10.31.10.7.00.7.00.1.30.1.31.63.01.63.017fcce14736afe498871d3018e4fa9330443471a17fcce14736afe498871d3018e4fa9330443471ab225ae77e9251a813cf2bd61e7874629d6f3cb10cfaf443a5f19e3a3e2b2c7be7572ae3924142c0ePackage rows compare exact local pins with their registries; source rows compare the reviewed commit with the repository default-branch head.
The
dashpay/zcash_note_encryptionrow compares the pinned revision with the dedicated repository default-branch head. A differing head triggers review only when the GitHub compare includessrc/,Cargo.toml,Cargo.lock, orbuild.rs; documentation and CI-only commits do not create a cryptographic update alert. A response at GitHub's 300-file limit fails closed for review. This checker never updates cryptographic dependencies.Note-encryption comparison: main head matches the audited pin.
Pinned upstream changes require a reviewed dependency pull request.