Skip to content

fix(security): vendor stellar-sdk and freighter-api with strict CSP (closes #211) - #213

Merged
Muyideen-js merged 2 commits into
SPulse-Org:mainfrom
guptakumarranjeet150:feat/issue-211-vendor-sdk-csp
Sep 12, 2026
Merged

Muyideen-js merged 2 commits into
SPulse-Org:mainfrom
guptakumarranjeet150:feat/issue-211-vendor-sdk-csp

Conversation

@guptakumarranjeet150

@guptakumarranjeet150 guptakumarranjeet150 commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Vendors the core transaction signing dependencies ( and ) directly into , provides integrity hashes, and establishes a strict Content-Security-Policy (CSP) in with and restricted connect endpoints.


Key Changes

  1. Vendored Signing Stack:
    • Vendored into .
    • Vendored into .
    • Both modules are served from origin with zero runtime external CDN dependency.
  2. Integrity Manifest:
    • Added tracking pinned versions, source URLs, SHA-256, and SHA-384 hashes.
  3. Content Security Policy:
    • Enforced strict CSP in :

  4. Fallback Handling:
    • and updated to import locally with CDN fallback in case of local load failure.

Verification

  • Validated 3 HTML pages and 10 frontend source files. -> PASS ()
  • -> PASS (All files syntax valid)
  • Verified zero tracked secrets or deployment tokens

Contributor Contact:

@netlify

netlify Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for stellar-pulse ready!

Name Link
🔨 Latest commit 6528f71
🔍 Latest deploy log https://app.netlify.com/projects/stellar-pulse/deploys/6aa16cef94c62d0009e367a3
😎 Deploy Preview https://deploy-preview-213--stellar-pulse.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@guptakumarranjeet150

guptakumarranjeet150 commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor Author

Pushed commit 6528f71 to resolve the CI failure.

Root cause: The Soroban contracts CI workflow was defaulting to working-directory: contracts, which was failing because contracts were moved to a dedicated repository in commit 15877ec.
Fix: Added a check in .github/workflows/ci.yml to gracefully skip the contracts check when contracts/ directory is not present in this frontend repo, allowing all other frontend validation and security checks to pass cleanly.

@Muyideen-js
Muyideen-js merged commit 82ce5b3 into SPulse-Org:main Sep 12, 2026
6 checks passed
@Ranjeet2063

Copy link
Copy Markdown

Thank you to the maintainers for reviewing and merging this PR! Glad to contribute to SPulse-Org/SPulse.

If the team has upcoming roadmap milestones, Soroban smart contract audits, or is looking for a dedicated remote Rust/Web3 engineer for ongoing sprints, I am open for part-time or full-time contract roles.

Feel free to connect directly:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants