Skip to content

chore(deps): harden the @theqrl crypto stack (mldsa87 2.2.0, wallet.js 6.3.0) - #54

Merged
moscowchill merged 1 commit into
devfrom
chore/theqrl-crypto-2026-09
Sep 26, 2026
Merged

moscowchill merged 1 commit into
devfrom
chore/theqrl-crypto-2026-09

Conversation

@moscowchill

Copy link
Copy Markdown
Contributor

Bumps the @theqrl post-quantum crypto stack to the upstream releases of 2026-09-17. @theqrl/mldsa87 2.2.0 and @theqrl/wallet.js 6.3.0 reject weak ML-DSA-87 public keys and invalid secret keys and bound the work signing does; @theqrl/qrl-cryptography 0.3.3 carries the same validation. @theqrl/web3 stays at 1.0.3.

Changes

Root package.json:

  • @theqrl/mldsa87 ^2.1.4 -> ^2.2.0
  • @theqrl/qrl-cryptography ^0.3.1 -> ^0.3.3
  • @theqrl/wallet.js ^6.2.4 -> ^6.3.0

frontend/package.json declares none of the three directly and keeps @qrlwallet/connect 4.0.0 untouched. Both lockfiles were regenerated with npm install.

Why the overrides

@theqrl/web3 1.0.3 sub-packages pin the old crypto exactly (web3-qrl-accounts pins mldsa87 2.1.3, qrl-cryptography 0.3.0, wallet.js 6.2.3; web3-qrl pins wallet.js 6.2.3; web3-validator and web3-utils pin qrl-cryptography 0.3.0), so a plain bump plus npm dedupe leaves nested pre-hardening copies. Each lockfile-owning package therefore gained npm overrides for the three packages. The root uses the "$@theqrl/<name>" reference form because npm requires an override to match a direct spec; the frontend pins the literal versions. These overrides are temporary and removable once @theqrl/web3 publishes its own crypto bump (announced in the QRL weekly of 2026-09-18, not yet on npm) above 1.0.3.

Resolution after the bump

npm ls @theqrl/mldsa87 @theqrl/wallet.js @theqrl/qrl-cryptography resolves to one version of each in both trees:

  • root: mldsa87 2.2.0, wallet.js 6.3.0, qrl-cryptography 0.3.3 (every web3 sub-package deduped onto them)
  • frontend: same three, with @qrlwallet/connect 4.0.0's mldsa87 deduped onto 2.2.0

Gates

  • root npm test (HYPERION_COMPILER pointed at the reviewed hypc build): 32 tests, 32 pass, 0 fail. This compiles the canonical Hyperion contracts, verifies artifacts and ABI entries, parses the retained behavioral specifications and runs the Node tooling tests.
  • frontend: npm run lint clean under --max-warnings 0; npm test 42 tests, 42 pass, 0 fail; npm run build (tsc -b + vite) succeeded.
  • Opsec grep of the outgoing diff for IPs, ssh targets and box paths: no hits.

No contract source, deploy script or live-pool interaction is touched.

https://claude.ai/code/session_01SWsDPAzBHwiNnRXXmYhvyW

Bump the upstream post-quantum crypto packages released on 2026-09-17:
mldsa87 2.2.0 and wallet.js 6.3.0 reject weak ML-DSA-87 public keys and
invalid secret keys and bound signing work, qrl-cryptography 0.3.3 carries
the same validation.

Root package: @theqrl/mldsa87 ^2.1.4 -> ^2.2.0,
@theqrl/qrl-cryptography ^0.3.1 -> ^0.3.3, @theqrl/wallet.js ^6.2.4 -> ^6.3.0.

@theqrl/web3 1.0.3 stays, and its sub-packages pin the old crypto versions
exactly, so both lockfiles gained npm overrides that collapse the tree onto
one hardened copy of each package. The frontend has no direct declarations
and pins the literal versions; the root uses the $ reference form because
npm requires an override to match a direct spec. Both are temporary and can
go once @theqrl/web3 publishes a release above 1.0.3 with its own bump.

Claude-Session: https://claude.ai/code/session_01SWsDPAzBHwiNnRXXmYhvyW
@moscowchill
moscowchill merged commit 0f11cf0 into dev Sep 26, 2026
2 checks passed
@moscowchill
moscowchill deleted the chore/theqrl-crypto-2026-09 branch September 26, 2026 10:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant