Skip to content

chore(main): release 1.28.0 - #16

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main
Open

chore(main): release 1.28.0#16
github-actions[bot] wants to merge 1 commit into
mainfrom
release-please--branches--main

Conversation

@github-actions

@github-actions github-actions Bot commented May 11, 2026

Copy link
Copy Markdown

🤖 I have created a release beep boop

1.28.0 (2026-08-14)

Features

  • auth: server-validated Thanos sessions (/auth/me) (0ca8f24)
  • auth: server-validated Thanos sessions (/auth/me) (0062367)
  • auth: Sign in with Thanos (SIWE) (eb59117)
  • auth: Sign in with Thanos (SIWE) (6eb422f)
  • bridge: add external EVM destinations (Sepolia, Base, BNB) (c77836e)
  • bridge: decode wallet/contract errors into actionable messages (ff899c3)
  • bridge: decode wallet/contract errors into actionable messages (18c10cb)
  • bridge: external EVM destinations (Sepolia, Base, BNB) (e9c09dd)
  • bridge: MultX cross-chain bridge UI + API proxy (dac1f34)
  • dnns: resolve .litho names in explorer search (93747d4)
  • explorer: footer credits LITHO Foundation with litho.foundation link (4a92662)
  • explorer: NFT collections support + tx-value/hero UI fixes (1646a22)
  • explorer: show Lithosphere (litho1) address format (22cb533)
  • explorer: show Lithosphere (litho1) format for addresses (0c8df98)
  • explorer: show Lithosphere bech32 addresses ahead of EVM (3945369)
  • explorer: show Lithosphere bech32 addresses ahead of EVM (5fb6a25)
  • explorer: Thanos sign-in also connects the wallet (#58) (f3a6ff7)
  • explorer: Thanos sign-in connects directly, sign-out disconnects wallet (#59) (912c768)
  • explorer: wallet menu links + Litho symbol balance (62d1c65)
  • faucet: fail closed for underfunded assets (ef50928)
  • faucet: fail closed for underfunded assets (c83910f)
  • faucet: gate claims behind Thanos sign-in (99e2362)
  • faucet: gate claims behind Thanos sign-in (db2de58)
  • infra: add mainnet progression monitoring (da6b5cf)
  • infra: gate 33-validator onboarding (273e7b4)
  • infra: prepare encrypted validator backups (ae77262)
  • infra: restrict mainnet monitor access (fc2e93c)
  • makalu: harden Thanos wallet discovery (#83) (6ded419)
  • monitoring: alert when faucet wallet balance is low (cec562b)
  • monitoring: alert when faucet wallet balance is low (abfcba3)
  • multx: add VPS-only remote signer quorum (5b5d230)
  • multx: consolidate source and mainnet infrastructure (5db05ad)
  • multx: consolidate source and mainnet infrastructure (f32e576)
  • multx: gate paused v0.5 testnet redeployments (5570c95)
  • multx: gate paused v05 testnet redeployments (0898f2f)
  • sdk: implement layered @lithosphere/blockchain-core + @lithosphere/sdk (4701d55)
  • toolchain: scaffold lithc Rust toolchain (e0dbcf6)

Bug Fixes

  • api,explorer: live-RPC balance for unindexed addrs; hide Sign In when connected (195d225)
  • api,explorer: live-RPC balance for unindexed wallets; hide Sign In when connected (1140376)
  • api: count current token holders, not historical participants (7fe3447)
  • api: dedupe /tokens by lower(address) (casing duplicates) (16a47a0)
  • api: dedupe /tokens by lower(address) to drop casing duplicates (318f2a6)
  • api: exclude NFT contracts from /tokens list (c147a4e)
  • api: exclude NFT contracts from /tokens list (0b157bf)
  • api: prevent infinite proxy loop for unmatched /api/* routes (258e054)
  • api: prevent infinite proxy loop for unmatched /api/* routes (f2b0d7f)
  • api: resolve bech32 contract addresses on /tokens routes (692c717)
  • api: resolve bech32 contract addresses on /tokens routes (ccc4d5b)
  • api: serve /api/version from Express so the deploy health gate passes (bf9fd60)
  • api: serve /api/version from Express so the deploy health gate passes (05c7287)
  • api: stop /stats/summary 500ing on the slow distinct-wallet aggregate (737c90d)
  • api: stop /stats/summary 500ing on the slow distinct-wallet aggregate (bfaa935)
  • bridge: correct BNB dest bridge address (+ coming-soon guard rails) (6c03173)
  • bridge: correct BNB dest bridge address; add coming-soon guard rails (c1e6512)
  • bridge: hard-verify wallet chain after switch before approve/lock (b7a2314)
  • bridge: hard-verify wallet chain after switch before approve/lock (7aacc73)
  • chain-id: rip out stale lithosphere_700777-1 from live surfaces (3a14b0e)
  • ci: build MultX web from consolidated layout (6d89305)
  • ci: build sdk-template's workspace deps before the template itself (08c29ee)
  • ci: invoke pinned promtool entrypoint (452e683)
  • ci: make required status checks reportable on every PR (e403b4f)
  • ci: make required status checks reportable on every PR (a49ccfb)
  • ci: quote Slither step name — colon broke YAML parser (04ba66d)
  • ci: rename duplicate Lint check in ci-contracts (56f3f0a)
  • ci: rename duplicate Lint check in ci-contracts (d62545e)
  • ci: rename duplicate Test check in ci-contracts (bf8a319)
  • ci: rename duplicate Test check in ci-contracts (a8b2d83)
  • ci: repair frozen-lockfile install + sync OpenAPI route set (810fb50)
  • ci: repair frozen-lockfile install + sync OpenAPI route set (f84c3a9)
  • ci: repair pre-existing Test + Lint failures exposed once install works (47abf04)
  • deploy: allow current mainnet block heights (d338c9c)
  • deploy: reach indexer /version via docker exec, not host curl (6e02878)
  • explorer: block stat overlap + reliable header balance/sign-in (a3936de)
  • explorer: block stat overlap + reliable header balance/sign-in (c476928)
  • explorer: header balance, sign-in label, and block spacing (345232a)
  • explorer: improve light theme contrast (dd26c56)
  • explorer: Litho-first contract address in token info cards (843a790)
  • explorer: Litho-first contract address in token info cards (9d046dd)
  • explorer: resolve header balance, sign-in label, and block spacing (df6f447)
  • explorer: revert OTel instrumentation to unblock deploys (a9d2a6d)
  • explorer: route Add to Wallet through the connected wallet; fit the header pill (a0ebcec)
  • explorer: route Add to Wallet through the connected wallet; fit the header pill (f3ff1bf)
  • explorer: stop network-switch nag on bridge chains (cf19144)
  • explorer: stop network-switch nag on bridge chains (a31d88c)
  • explorer: use blue mainnet favicon (6b747da)
  • faucet: make health check resilient + diagnosable; document wallet IDs (19596a2)
  • forge: profile selection via FOUNDRY_PROFILE env, not --profile flag (d5c1971)
  • holders: count current native LITHO owners, not historical participants (e90f92d)
  • indexer: bind /version + /health before DB wait (f0aff8f)
  • indexer: populate accounts.evm_address so native holder count is real (90ae439)
  • indexer: populate accounts.evm_address so native holder count is real (620e5fd)
  • indexer: reclassify NFT contracts regardless of prior 'token' tag (f202163)
  • indexer: reclassify NFT contracts regardless of prior 'token' tag (b152ef7)
  • infra: harden mainnet RPC recovery (f2fdf3b)
  • integration: add sslmode=disable to test DATABASE_URL (133c417)
  • makalu: harden DNNS resolution (c5448da)
  • makalu: harden DNNS resolution (f61d3d1)
  • makalu: isolate core deploy from faucet gate (#84) (4fdb3ca)
  • makalu: require explicit Quantt contract settings (c01ec48)
  • makalu: require explicit Quantt contract settings (18f2abf)
  • multx: bind releases to destination domain (6ae4d3a)
  • multx: enforce approved deployment window (6fa03fb)
  • multx: harden mainnet deployment gates (620e300)
  • multx: resolve SDK dependencies in container build (aa22e7e)
  • multx: upgrade signer services to ethers v6 (1ca6e63)
  • sdk: migrate MultX client to ethers v6 (6295f76)
  • show token holders in litho format; name unindexed tokens on tx pages (a70edcb)
  • show token holders in litho format; name unindexed tokens on tx pages (480a855)
  • slither: also convert printers_to_run + detectors_to_exclude to strings (67a4053)
  • slither: filter_paths must be a comma-separated string, not a list (8111e19)
  • thanos: normalize wallet signature return before verify (a3a89de)
  • thanos: normalize wallet signature return before verify (1297a46)
  • thanos: sign SIWE via hex payload to dodge extension BytesLike bug (d3abe97)
  • thanos: sign SIWE via hex payload to dodge extension BytesLike bug (c6abde6)
  • tokens: correct swapped FGPT/MUSA token metadata to match on-chain (e52c76a)
  • wallet: add Kamet to Web3Modal supported chains (e221f28)
  • wallet: whitelist bridge dest chains to stop unsupported-network nag (e3115c7)
  • wallet: whitelist bridge dest chains to stop unsupported-network nag (204e812)
  • web: harden wallet dependency stack (4c94d3f)

Performance

  • api: build DB performance indexes from API startup (fixes slow /txs) (ef1bdf6)
  • api: build DB performance indexes from API startup to fix slow /txs (74a821f)
  • api: cache inconsistent-blocks CTE off /stats/summary hot path (bc8e44a)
  • api: cache inconsistent-blocks CTE off the /stats/summary hot path (76988d1)
  • api: give heavy stats counts a long TTL so /stats/summary stops re-scanning (9b75aae)
  • api: long TTL for heavy stats counts (wallet-addresses, tx-total) (981c08e)
  • api: Redis-backed shared cache for /stats/summary across replicas (bfc2f65)
  • api: Redis-backed shared cache for /stats/summary across replicas (2a831bb)
  • api: remove per-row EVM RPC calls from /txs list; cache stats + token stats (7c58fc2)
  • api: speed up /txs and homepage transaction loading (3e9366b)
  • db: add missing blocks indexes (block_time, proposer) for fast /stats/summary (1b6c60f)
  • db: add missing blocks indexes (block_time, proposer) to fix slow /stats/summary (1405792)
  • indexer: ensure DB performance indexes at startup to fix slow /txs (5298905)
  • indexer: ensure performance indexes at startup to fix slow /txs (b387a46)

Security

  • bump explorer's @coinbase/wallet-sdk to 4.3.7 (was 4.0.3 via web3modal) (e9a1e8e)
  • images: strip bundled npm from api/indexer/explorer runner stages (af4a18d)
  • infra: remove production topology from public config (ce29bda)
  • p10: add pre-construction path check for CodeQL js/request-forgery (a01f4dc)
  • p10: close remaining 12 CodeQL alerts (4 fixed, 8 dismissed) (38649a3)
  • p10: CodeQL SAST for the JS/TS surface (84bbbf0)
  • p10: license allow/deny policy + CI gate (a625789)
  • p10: make sanitizeForLog match CodeQL's recognised sanitizer pattern (5201549)
  • p10: SLSA Build L2 build-provenance attestation on published images (5410d66)
  • p10: triage CodeQL first-scan — fix 8/23 at source (ae2c0c7)
  • p7: flip production Slither from advisory to blocking (1e82620)
  • p7: run Slither against production contracts, not just template (22aa7a6)
  • repo: sanitize legacy operational topology (26db790)

Observability

  • p10: typed audit-trail channel for security-sensitive actions (5f7499b)
  • p9: Cost dashboard — VPS spend visibility for operators (25902f5)
  • p9: explorer instrumentation.ts + /api/version (f8109de)
  • p9: HTTP request metrics + SLO Grafana dashboard (635cbd9)
  • p9: propagate build metadata commit -> image -> running container (20f0233)
  • p9: structured JSON logging + request-id correlation (8bf7fda)
  • p9: sweep helper-level console.* to pino logger in api + indexer (36f2f9b)
  • p9: wire env-gated OpenTelemetry SDK in api + indexer (ebc449d)

Deployment

  • p3: Cosign + SLSA verify pre-check in deploy-simple (7e5e57d)
  • p3: pin base image digests + GHCR retention + artifact catalog (14eb68d)
  • p4: formal approval flow + post-deploy SHA verification (70263ee)
  • p4: rip out unused K8s/ArgoCD/Kustomize boilerplate (6908c08)
  • p7: structured deployment manifest + bytecode verifier + multi-sig runbook (0aa2c90)

Developer Experience

  • p1: local commit-msg hook + line-ending normalization (eeef281)
  • p5: make integration-test — one-command local integration suite (fb84877)
  • p8: GraphQL schema artifact + drift gate (216f26f)
  • p8: OpenAPI REST artifact + drift gate (f32d511)

SDK

  • p8: OpenAPI -> TypeScript type codegen, drift-gated (bd10297)
  • p8: refresh sdk-template scaffold to consume @lithosphere/sdk (ad0bc5b)
  • p8: typed REST runtime client + runnable examples (e7bd86d)

This PR was generated with Release Please. See documentation.

@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 18 times, most recently from 14f9607 to 4b2a3c1 Compare May 12, 2026 08:36
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 10 times, most recently from 2bf6ef9 to f4485fb Compare June 21, 2026 16:01
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch from f4485fb to c71f8c3 Compare June 22, 2026 10:47
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 5 times, most recently from 1f1e383 to e7af4ef Compare June 27, 2026 19:47
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 12 times, most recently from baa3513 to 7014384 Compare July 13, 2026 08:26
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 9 times, most recently from 45f23d2 to e9a8cb2 Compare July 20, 2026 04:54
@github-actions
github-actions Bot force-pushed the release-please--branches--main branch 3 times, most recently from e0d15d0 to 3721359 Compare July 29, 2026 04:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants