Commit Graph
103 Commits
Author SHA1 Message Date
AL ead7eefdf2 release: move CLI distribution to GitHub 2026-09-12 04:53:48 +01:00
AL aad10ffca9 test: discover nested test suites 2026-09-12 04:27:15 +01:00
AL aedb9c4816 fix: publish required postinstall scripts 2026-09-12 04:14:05 +01:00
AL 491cbaec9f fix: restore security CI 2026-09-10 18:49:14 +01:00
alsk1992 719023f684 Merge V2 (Jupiter fix) into fix/orca-audit 2026-09-01 15:34:55 +01:00
alsk1992andClaude Sonnet 5 9c2ddfba70 fix: Orca Whirlpools v2 SDK was entirely non-functional
Auditing src/solana/orca.ts turned up four distinct, compounding bug
classes across every function using @orca-so/whirlpools (v2 SDK) — nothing
in that section had ever actually worked:

1. Dependency resolution was broken tree-wide. @orca-so/whirlpools needs
   @solana/kit@^5.0.0, but @drift-labs/sdk's gill dependency pinned
   @solana/kit@^2.3.0, and with legacy-peer-deps=true npm silently deduped
   the whole tree onto the old 2.3.0 — an incompatible major version.
   `await import('@orca-so/whirlpools')` crashed immediately with
   "SyntaxError: ... does not provide an export named
   'sequentialInstructionPlan'" on every call. Fixed with a global
   `"@solana/kit": "^5.0.0"` override in package.json, resolved to 5.5.1;
   verified this doesn't affect gill/@drift-labs/sdk (our code never
   imports either directly). Added @solana/kit, @orca-so/whirlpools-client,
   and @orca-so/whirlpools-core as explicit dependencies since orca.ts now
   imports them directly rather than relying on transitive resolution.

2. Wrong function names. sdk.openPosition and sdk.increaseLiquidity don't
   exist on the real SDK — the actual exports are openConcentratedPosition
   and increasePosLiquidity. Only discoverable once fix #1 let the import
   succeed at all.

3. Wrong argument types/shapes throughout:
   - @solana/kit's `Address` is a plain base58 string, never a legacy
     web3.js PublicKey — every `new PublicKey(...)` wrap on an address
     argument broke the call (confirmed live, e.g. passing a PublicKey
     into fetchPositionsForOwner's first arg threw "rpc.getTokenAccountsBy
     Owner is not a function" because it landed in the `rpc` slot).
   - The "fetch" family (fetchPositionsForOwner/InWhirlpool/
     WhirlpoolsByTokenPair) takes an explicit `rpc` as its first argument,
     unlike the "action" family (open/increase/decrease/harvest/close/
     create), which gets it implicitly from sdk.setRpc(). Every fetch call
     was missing that argument entirely.
   - IncreaseLiquidityQuoteParam/DecreaseLiquidityQuoteParam are
     discriminated unions accepting exactly one of liquidity/tokenA/tokenB;
     the code built objects with multiple keys present. Centralized into
     buildOrcaLiquidityParam().
   - openConcentratedPosition takes actual (lowerPrice, upperPrice)
     numbers, not tick indices, despite the .d.ts appearing tick-shaped.
     Converted via @orca-so/whirlpools-core's tickIndexToPrice() using the
     pool's real on-chain token decimals, so the tick-based public
     interface (already relied on by src/agents/index.ts and
     src/skills/bundled/orca/index.ts) didn't need to change.

4. Wrong result shapes and, critically, missing execution:
   - fetch results are Account<T> (fields under `.data`), not flat —
     confirmed live (a real position's tickLowerIndex/liquidity/feeOwedA
     etc. are all under `.data`, and its usable identifier is
     `.data.positionMint`, not the account's own `.address`). Centralized
     into mapOrcaPositionData()/flattenOrcaPositions() (handles position
     bundles too).
   - Every write function (open/increase/decrease/harvest/close/create)
     returns `{ instructions, quote, callback }` and does NOT send
     anything until `.callback()` is called. None of the old code called
     it — it read a nonexistent `result.signature` field instead, so these
     functions built valid instructions, reported back an empty signature,
     and never touched the chain at all. Now every write path calls
     `await result.callback()` and returns the real signature.
   - harvestPosition's real result shape is `{ feesQuote: { feeOwedA,
     feeOwedB }, rewardsQuote: { rewards: [{ rewardsOwed }] } }`, not the
     flat fields the old code guessed at.

Verified live end-to-end against real mainnet: fetchWhirlpoolsByTokenPair/
fetchPositionsInWhirlpool/fetchPositionsForOwner now return correct,
populated data (confirmed against a real SOL/USDC Whirlpool and one of its
~20k real positions). openOrcaFullRangePosition/openOrcaConcentratedPosition
now build real instructions and reach actual on-chain simulation (failing
only on AccountNotFound from a deliberately zero-balance throwaway wallet —
proving the full args/shapes/execution path is correct, not guessing).

Left alone, out of scope: executeOrcaWhirlpoolSwap/getOrcaWhirlpoolQuote/
listOrcaWhirlpoolPools still use the older, npm-deprecated
@orca-so/whirlpool-sdk — confirmed still functional live today (unlike the
v2 path above), so not blocking, but a known follow-up to migrate onto the
v2 SDK's swap()/swapInstructions().

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-01 15:34:37 +01:00
alsk1992 19efddc9bb fix: Jupiter limit orders were completely broken by a missing @trpc/server peer dep
Every limit-order function in src/solana/jupiter.ts (create, cancel, batch
cancel, list, get, get history, get fee, get trade history, cancel/batch
cancel expired) dynamically imports @jup-ag/limit-order-sdk, which requires
@trpc/client at module load time, which in turn requires @trpc/server as a
peer dependency — never installed in this repo. Confirmed by direct
`require('@jup-ag/limit-order-sdk')`: it threw
"Cannot find module '@trpc/server/observable'" every time, so every one of
those functions rejected immediately, before ever touching Solana. Pinned
@trpc/server to the exact peer version @trpc/client 10.45.4 needs; after
installing it, live calls against the real Jupiter Limit Order program on
mainnet (getJupiterLimitOrderFee, listJupiterLimitOrders) succeed and decode
correctly.

Also fixed two smaller issues found in the same file while verifying live
behavior:

- executeJupiterSwap's return type (JupiterSwapResult) declares top-level
  inAmount/outAmount/priceImpactPct/routePlan fields, but the function never
  populated them (only nested under `quote`). The /jup and /sol skill swap
  commands read those top-level fields directly, so a real swap's summary
  output always rendered undefined/N/A/"Direct" for amount, price impact,
  and route — only the signature was ever correct. Now populated from the
  quote.
- listJupiterLimitOrdersByMint fell back to calling the SDK's getOrders()
  with no filters at all when none of owner/inputMint/outputMint were given,
  which does an unfiltered scan of every open order on the entire Jupiter
  Limit Order program (all users, not just the caller). No current call site
  hits this today (both always pass owner), but it's exported and one filter
  short of the same unbounded-fetch bug class already fixed in
  meteora-dbc.ts's getDbcPools(). Now throws instead of silently fetching
  everything.
2026-09-01 01:11:55 +01:00
alsk1992 92bfc5e560 1.9.0 2026-08-31 22:33:59 +01:00
71ff1f142d fix: replace PumpPortal with the official @pump-fun/pump-sdk for bonding-curve trading (#79)
Both the single-wallet path (executePumpFunTrade) and the multi-wallet
swarm path (PumpFunBuilder) built and relayed trades through PumpPortal's
third-party trade-local API. Replaced both with buildPumpFunTradeInstructions,
a shared helper that builds real bonding-curve buy/sell instructions locally
via the official @pump-fun/pump-sdk — no third-party API round-trip for
either constructing or relaying the transaction.

Verified live against mainnet during development (real trading pair,
BPmsvKnjXXJpkYcnJsjFd6VBBfreJ81uJf1SbX5Lpump): the SDK's README examples are
stale relative to the published v1.36.0 API (wrong PumpSdk constructor arity,
wrong getBuyTokenAmountFromSolAmount signature) — went to source (sdk.ts,
onlineSdk.ts, bondingCurve.ts, fees.ts) to get the real shapes instead of
trusting the docs. Also surfaced that this specific token uses Token-2022,
not classic SPL Token — token program is now detected per-mint via the mint
account's owner rather than assumed, and that the real fee-tier-aware
protocol fee (measured live at 100bps total) differs from the flat 125bps
this codebase had hardcoded as an assumption.

Also fixes the swarm's PumpFunBuilder.getQuote, which previously hit
frontend-api-v3.pump.fun directly (Cloudflare-blocks server-side/bot
requests) — now computed locally via the same SDK path, and adds
client-side priority-fee compute-budget instructions since PumpPortal
is no longer relaying (and therefore no longer applying priority fee
server-side).

Known remaining scope, not touched here:
- Token creation and creator-fee-claiming (agents/handlers/solana.ts,
  skills/bundled/pumpfun) still call PumpPortal's /api/create and
  /api/claim-fees — separate feature from trading, left as-is.
- PumpSwap (post-graduation AMM) already quotes via the official
  @pump-fun/pump-swap-sdk (src/solana/pumpswap.ts) but has no execute/swap
  instruction builder yet, and swarm-builders.ts's DexType has no 'pumpswap'
  entry — a graduated token is not yet tradeable through this codebase.

Co-authored-by: alsk1992 <alsk1992@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-31 13:47:27 +01:00
alsk1992 c4e65fa1af fix: remediate npm audit findings, replace plain npm audit with audit-ci
85 -> 62 production vulnerabilities (52 moderate, 9 high, 1 critical remain,
all allowlisted below) via two npm audit fix passes plus manual major-version
bumps for nodemailer (7 -> 9) and sharp (0.34 -> 0.35), chosen because both
have narrow, stable-surface usage in this codebase (createTransport/sendMail;
a basic resize/metadata chain) verified before bumping.

The sharp bump broke its own TS types in two places, both fixed:
- src/media/index.ts: sharp's ESM types now separately export a named
  SharpConstructor and a default rather than making the module namespace
  itself callable, breaking `typeof import('sharp')` as a cast target.
  Replaced with a small local SharpFactory type describing only what this
  file actually calls (resize/toFormat/toBuffer/metadata) — sharp has now
  changed its export shape at least once, so pinning to its exact type
  surface here was already fragile.
- src/extensions/open-prose/index.ts: an unrelated puppeteer version shift
  (pulled in transitively during the audit-fix passes) dropped 'networkidle0'
  as a valid page.setContent() waitUntil value (still valid for page.goto(),
  just not setContent()) — switched to 'load', the correct equivalent for
  rendering already-inlined HTML.

New audit-ci.jsonc allowlists the remaining findings with per-advisory
justification: almost all are protobufjs/@grpc-js/uuid pulled in transitively
by the Solana SDK ecosystem's own pinned old @solana/web3.js/@coral-xyz/anchor
versions (Drift, Orca, Kamino, Raydium, etc.) — none fixable without either
downgrading a trading integration this session verified working, or forcing
a major bump whose breaking changes (e.g. @drift-labs/sdk needing Node 24)
haven't been vetted. sharp's one remaining finding is an inherited libvips
CVE with no fix published yet even on the latest release just installed here.

ci.yml and security.yml now run `audit-ci --config audit-ci.jsonc` instead of
plain `npm audit`, since plain npm audit has no allowlist mechanism at all —
without this, the allowlist above would have no effect on actual CI results.
2026-08-30 23:17:46 +01:00
alsk1992 1e18a7b370 feat: Rust hot-path broadcast racer, multi-RPC fallback + sequencer racing
- New Rust binary (rust/fast-broadcast) races eth_sendRawTransaction across
  multiple RPC/sequencer endpoints via a TS wrapper (src/evm/fast-broadcast.ts);
  proven byte-identical to ethers' native signing path.
- multichain.ts: adds rpcFallbacks/getRaceUrls per chain, plus official
  write-only sequencer endpoints for Arbitrum and Base (Optimism's public
  sequencer is excluded per its own docs — rate-limited, not for default use).
- odos.ts: races broadcast across configured endpoints when more than one is
  set; bumps the retired /sor/quote/v2 endpoint to /sor/quote/v3 and adds the
  pathViz request flag (route was previously always empty) and mandatory
  pre-broadcast simulation (Odos's own hard rule — refuse to broadcast a
  transaction their simulator predicts will revert).
- postinstall self-heals two real environment bugs: bigint-buffer's native
  binary SIGILLs on this platform, and @coral-xyz/anchor's CJS build exposes
  BN via a getter that breaks native ESM named-export synthesis for
  dependents like @meteora-ag/dlmm.
- tsconfig: incremental builds (measured ~22% faster warm typecheck).
2026-08-30 22:00:56 +01:00
alsk1992 2a8c94e915 1.8.0 2026-02-22 23:01:37 +00:00
alsk1992 dfd502e85f 1.7.7 2026-02-22 22:59:44 +00:00
alsk1992andClaude Opus 4.6 4c513fb56b Add ajv override to fix remaining ReDoS vulnerability
- Override ajv to v8.18.0 to fix ReDoS vulnerability in json schema validation
- This resolves the last moderate security vulnerability found by npm audit
- Reduces reported vulnerabilities from 1 to 0

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-22 22:53:22 +00:00
dependabot[bot] dc0b98480c Bump the minor-updates group with 15 updates (#11)
Bumps the minor-updates group with 15 updates:

| Package | From | To |
| --- | --- | --- |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.74.0` | `0.78.0` |
| [@meteora-ag/dynamic-bonding-curve-sdk](https://github.com/MeteoraAg/dynamic-bonding-curve-sdk/tree/HEAD/packages/dynamic-bonding-curve) | `1.5.2` | `1.5.3` |
| [@predictdotfun/sdk](https://github.com/PredictDotFun/sdk) | `1.2.8` | `1.3.0` |
| [@wormhole-foundation/sdk](https://github.com/wormhole-foundation/wormhole-sdk-ts) | `4.10.0` | `4.11.0` |
| [@wormhole-foundation/sdk-evm](https://github.com/wormhole-foundation/wormhole-sdk-ts) | `4.10.0` | `4.11.0` |
| [@wormhole-foundation/sdk-evm-cctp](https://github.com/wormhole-foundation/wormhole-sdk-ts) | `4.10.0` | `4.11.0` |
| [@wormhole-foundation/sdk-evm-tokenbridge](https://github.com/wormhole-foundation/wormhole-sdk-ts) | `4.10.0` | `4.11.0` |
| [@wormhole-foundation/sdk-solana](https://github.com/wormhole-foundation/wormhole-sdk-ts) | `4.10.0` | `4.11.0` |
| [@wormhole-foundation/sdk-solana-cctp](https://github.com/wormhole-foundation/wormhole-sdk-ts) | `4.10.0` | `4.11.0` |
| [@wormhole-foundation/sdk-solana-tokenbridge](https://github.com/wormhole-foundation/wormhole-sdk-ts) | `4.10.0` | `4.11.0` |
| [bn.js](https://github.com/indutny/bn.js) | `5.2.2` | `5.2.3` |
| [bullmq](https://github.com/taskforcesh/bullmq) | `5.69.1` | `5.69.3` |
| [bybit-api](https://github.com/tiagosiebler/bybit-api) | `4.5.3` | `4.6.0` |
| [docx](https://github.com/dolanmiu/docx) | `9.5.2` | `9.5.3` |
| [puppeteer](https://github.com/puppeteer/puppeteer) | `24.37.3` | `24.37.5` |


Updates `@anthropic-ai/sdk` from 0.74.0 to 0.78.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.74.0...sdk-v0.78.0)

Updates `@meteora-ag/dynamic-bonding-curve-sdk` from 1.5.2 to 1.5.3
- [Changelog](https://github.com/MeteoraAg/dynamic-bonding-curve-sdk/blob/main/packages/dynamic-bonding-curve/CHANGELOG.md)
- [Commits](https://github.com/MeteoraAg/dynamic-bonding-curve-sdk/commits/HEAD/packages/dynamic-bonding-curve)

Updates `@predictdotfun/sdk` from 1.2.8 to 1.3.0
- [Release notes](https://github.com/PredictDotFun/sdk/releases)
- [Commits](https://github.com/PredictDotFun/sdk/compare/v.1.2.8...v1.3.0)

Updates `@wormhole-foundation/sdk` from 4.10.0 to 4.11.0
- [Release notes](https://github.com/wormhole-foundation/wormhole-sdk-ts/releases)
- [Commits](https://github.com/wormhole-foundation/wormhole-sdk-ts/compare/4.10.0...4.11.0)

Updates `@wormhole-foundation/sdk-evm` from 4.10.0 to 4.11.0
- [Release notes](https://github.com/wormhole-foundation/wormhole-sdk-ts/releases)
- [Commits](https://github.com/wormhole-foundation/wormhole-sdk-ts/compare/4.10.0...4.11.0)

Updates `@wormhole-foundation/sdk-evm-cctp` from 4.10.0 to 4.11.0
- [Release notes](https://github.com/wormhole-foundation/wormhole-sdk-ts/releases)
- [Commits](https://github.com/wormhole-foundation/wormhole-sdk-ts/compare/4.10.0...4.11.0)

Updates `@wormhole-foundation/sdk-evm-tokenbridge` from 4.10.0 to 4.11.0
- [Release notes](https://github.com/wormhole-foundation/wormhole-sdk-ts/releases)
- [Commits](https://github.com/wormhole-foundation/wormhole-sdk-ts/compare/4.10.0...4.11.0)

Updates `@wormhole-foundation/sdk-solana` from 4.10.0 to 4.11.0
- [Release notes](https://github.com/wormhole-foundation/wormhole-sdk-ts/releases)
- [Commits](https://github.com/wormhole-foundation/wormhole-sdk-ts/compare/4.10.0...4.11.0)

Updates `@wormhole-foundation/sdk-solana-cctp` from 4.10.0 to 4.11.0
- [Release notes](https://github.com/wormhole-foundation/wormhole-sdk-ts/releases)
- [Commits](https://github.com/wormhole-foundation/wormhole-sdk-ts/compare/4.10.0...4.11.0)

Updates `@wormhole-foundation/sdk-solana-tokenbridge` from 4.10.0 to 4.11.0
- [Release notes](https://github.com/wormhole-foundation/wormhole-sdk-ts/releases)
- [Commits](https://github.com/wormhole-foundation/wormhole-sdk-ts/compare/4.10.0...4.11.0)

Updates `bn.js` from 5.2.2 to 5.2.3
- [Release notes](https://github.com/indutny/bn.js/releases)
- [Changelog](https://github.com/indutny/bn.js/blob/master/CHANGELOG.md)
- [Commits](https://github.com/indutny/bn.js/compare/v5.2.2...v5.2.3)

Updates `bullmq` from 5.69.1 to 5.69.3
- [Release notes](https://github.com/taskforcesh/bullmq/releases)
- [Commits](https://github.com/taskforcesh/bullmq/compare/v5.69.1...v5.69.3)

Updates `bybit-api` from 4.5.3 to 4.6.0
- [Release notes](https://github.com/tiagosiebler/bybit-api/releases)
- [Commits](https://github.com/tiagosiebler/bybit-api/compare/v4.5.3...v4.6.0)

Updates `docx` from 9.5.2 to 9.5.3
- [Release notes](https://github.com/dolanmiu/docx/releases)
- [Commits](https://github.com/dolanmiu/docx/compare/9.5.2...9.5.3)

Updates `puppeteer` from 24.37.3 to 24.37.5
- [Release notes](https://github.com/puppeteer/puppeteer/releases)
- [Changelog](https://github.com/puppeteer/puppeteer/blob/main/CHANGELOG.md)
- [Commits](https://github.com/puppeteer/puppeteer/compare/puppeteer-v24.37.3...puppeteer-v24.37.5)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.78.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@meteora-ag/dynamic-bonding-curve-sdk"
  dependency-version: 1.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: "@predictdotfun/sdk"
  dependency-version: 1.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@wormhole-foundation/sdk"
  dependency-version: 4.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@wormhole-foundation/sdk-evm"
  dependency-version: 4.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@wormhole-foundation/sdk-evm-cctp"
  dependency-version: 4.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@wormhole-foundation/sdk-evm-tokenbridge"
  dependency-version: 4.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@wormhole-foundation/sdk-solana"
  dependency-version: 4.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@wormhole-foundation/sdk-solana-cctp"
  dependency-version: 4.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@wormhole-foundation/sdk-solana-tokenbridge"
  dependency-version: 4.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: bn.js
  dependency-version: 5.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: bullmq
  dependency-version: 5.69.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: bybit-api
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: docx
  dependency-version: 9.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: puppeteer
  dependency-version: 24.37.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-02-22 18:38:54 +00:00
alsk1992andClaude Opus 4.6 3b90e350ca Configure CI/CD to audit production dependencies only and add security overrides
- Add npm overrides for minimatch (10.2.1) and qs (6.15.0) to fix vulnerabilities
- Remove dev-only packages from main dependencies (minimatch, qs)
- Update CI/CD workflows to use --production flag for npm audit
  - Excludes dev dependencies (eslint, nyc, testing tools) from security checks
  - All remaining vulnerabilities are dev-only and don't affect production
- Keep production dependencies clean: no vulnerabilities

This reduces reported vulnerabilities from 18 to 0 in production code while maintaining
dev/test tooling integrity.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-22 18:37:42 +00:00
alsk1992andClaude Opus 4.6 e6961baf46 Update dependencies for security and compatibility
- Update fast-xml-parser from 5.3.4 to 5.3.7 (fixes critical XXE vulnerabilities)
- Update bn.js from 5.2.2 to 5.2.3 (fixes infinite loop vulnerability)
- Update minimatch to 10.2.1 (fixes ReDoS vulnerability in pattern matching)
- Update qs to 6.15.0 (fixes DoS vulnerability in query string parsing)
- Adds minimatch as direct dependency to reduce transitive vulnerability chain

Reduces high-severity vulnerabilities from 21 to 18 (remaining are in dev-only dependencies)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-22 18:35:40 +00:00
dependabot[bot] 7c6650e78f Bump the minor-updates group with 10 updates
Bumps the minor-updates group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [@anthropic-ai/sdk](https://github.com/anthropics/anthropic-sdk-typescript) | `0.73.0` | `0.74.0` |
| [binance](https://github.com/tiagosiebler/binance) | `3.3.1` | `3.3.3` |
| [bullmq](https://github.com/taskforcesh/bullmq) | `5.67.3` | `5.69.1` |
| [bybit-api](https://github.com/tiagosiebler/bybit-api) | `4.5.2` | `4.5.3` |
| [docx](https://github.com/dolanmiu/docx) | `9.5.1` | `9.5.2` |
| [grammy](https://github.com/grammyjs/grammY) | `1.39.3` | `1.40.0` |
| [ioredis](https://github.com/luin/ioredis) | `5.9.2` | `5.9.3` |
| [sql.js](https://github.com/sql-js/sql.js) | `1.13.0` | `1.14.0` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `20.19.32` | `20.19.33` |
| [puppeteer](https://github.com/puppeteer/puppeteer) | `24.37.2` | `24.37.3` |


Updates `@anthropic-ai/sdk` from 0.73.0 to 0.74.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-typescript/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-typescript/blob/main/CHANGELOG.md)
- [Commits](https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.73.0...sdk-v0.74.0)

Updates `binance` from 3.3.1 to 3.3.3
- [Release notes](https://github.com/tiagosiebler/binance/releases)
- [Changelog](https://github.com/tiagosiebler/binance/blob/master/CHANGELOG.md)
- [Commits](https://github.com/tiagosiebler/binance/compare/v3.3.1...v3.3.3)

Updates `bullmq` from 5.67.3 to 5.69.1
- [Release notes](https://github.com/taskforcesh/bullmq/releases)
- [Commits](https://github.com/taskforcesh/bullmq/compare/v5.67.3...v5.69.1)

Updates `bybit-api` from 4.5.2 to 4.5.3
- [Release notes](https://github.com/tiagosiebler/bybit-api/releases)
- [Commits](https://github.com/tiagosiebler/bybit-api/compare/v4.5.2...v4.5.3)

Updates `docx` from 9.5.1 to 9.5.2
- [Release notes](https://github.com/dolanmiu/docx/releases)
- [Commits](https://github.com/dolanmiu/docx/compare/9.5.1...9.5.2)

Updates `grammy` from 1.39.3 to 1.40.0
- [Release notes](https://github.com/grammyjs/grammY/releases)
- [Commits](https://github.com/grammyjs/grammY/compare/v1.39.3...v1.40.0)

Updates `ioredis` from 5.9.2 to 5.9.3
- [Release notes](https://github.com/luin/ioredis/releases)
- [Changelog](https://github.com/redis/ioredis/blob/main/CHANGELOG.md)
- [Commits](https://github.com/luin/ioredis/compare/v5.9.2...v5.9.3)

Updates `sql.js` from 1.13.0 to 1.14.0
- [Release notes](https://github.com/sql-js/sql.js/releases)
- [Commits](https://github.com/sql-js/sql.js/compare/v1.13.0...v1.14.0)

Updates `@types/node` from 20.19.32 to 20.19.33
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `puppeteer` from 24.37.2 to 24.37.3
- [Release notes](https://github.com/puppeteer/puppeteer/releases)
- [Changelog](https://github.com/puppeteer/puppeteer/blob/main/CHANGELOG.md)
- [Commits](https://github.com/puppeteer/puppeteer/compare/puppeteer-v24.37.2...puppeteer-v24.37.3)

---
updated-dependencies:
- dependency-name: "@anthropic-ai/sdk"
  dependency-version: 0.74.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: binance
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: bullmq
  dependency-version: 5.69.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: bybit-api
  dependency-version: 4.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: docx
  dependency-version: 9.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: grammy
  dependency-version: 1.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: ioredis
  dependency-version: 5.9.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: sql.js
  dependency-version: 1.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-updates
- dependency-name: "@types/node"
  dependency-version: 20.19.33
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-updates
- dependency-name: puppeteer
  dependency-version: 24.37.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-13 19:39:55 +00:00
alsk1992andClaude Opus 4.6 25390ec5b4 Add credential setup for all remaining platforms (Drift, Smarkets, Opinion, Virtuals, Hedgehog, PredictFun)
14 platforms now have full chat-based credential onboarding with AES-256-GCM encryption.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 19:12:43 +00:00
alsk1992andClaude Opus 4.6 6ec1984df0 Add credential setup tools for all trading platforms (Binance, Bybit, Hyperliquid, MEXC, Betfair)
Users can now send their API keys via chat and the bot stores them encrypted.
Added proper TypeScript interfaces for each platform's credentials.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 19:08:48 +00:00
alsk1992andClaude Opus 4.6 fdd54c838f Add credential tools to core tools — bot can onboard users naturally
setup_polymarket_credentials, list_trading_credentials, and
delete_trading_credentials are now always available. When a user says
"here are my poly keys" or a trade fails due to missing creds, the
bot can store them via the credential manager instead of saying
"I can't do that from chat".

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 19:01:08 +00:00
alsk1992andClaude Opus 4.6 23f1026a2d Add postinstall script to pre-cache embedding model
npm install now downloads Xenova/all-MiniLM-L6-v2 so it's ready at
runtime. Covers both npm install -g and Docker builds.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 18:48:09 +00:00
alsk1992andClaude Opus 4.6 79c47d8ad7 Pre-bake embedding model in Docker build
Downloads Xenova/all-MiniLM-L6-v2 at build time so it's cached in the
image. No more first-request model download hang at runtime.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 18:46:41 +00:00
alsk1992andClaude Opus 4.6 75cc4a584b Fix: embedding model load no longer blocks message responses
The transformers.js model init (Xenova/all-MiniLM-L6-v2) was awaited
inline during message handling — if the download hung, no messages
got responses.

Fix: embeddings are now non-blocking. If the model isn't loaded yet,
simple bag-of-words embeddings are used immediately. Model loads in
background at startup via preloadTransformersPipeline(). Once warm,
neural embeddings kick in automatically.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 18:28:36 +00:00
alsk1992andClaude Opus 4.6 66c6c6e53a v1.7.0 — Solana token launch API
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-12 17:08:48 +00:00
alsk1992 8201de15ea 1.6.26 2026-02-12 14:02:42 +00:00
alsk1992 805157db9c 1.6.25 2026-02-12 14:02:23 +00:00
alsk1992 1a75ed3540 1.6.24 2026-02-12 13:58:33 +00:00
alsk1992 f1983b0811 1.6.23 2026-02-12 13:56:00 +00:00
alsk1992 171ebd71ad 1.6.22 2026-02-12 13:53:41 +00:00
alsk1992andClaude Haiku 4.5 7fe6b00ef3 Add 5-minute Polymarket BTC market support with direct slug-based discovery
Features:
- Add 5min-btc and 5min-btc-conservative presets (300s rounds, BTC only)
- Proportionally scaled timing gates: 50s min time left, 10s min round age
- Faster execution: 10s maker timeout, 500ms exit timeout, 1s sell cooldown
- Update crypto-hft skill docs with 5-min examples and comparison table

Implementation:
- Use direct slug-based market discovery (e.g., btc-updown-5m-1770904200)
- Calculate slot: floor(now / roundDurationSec) * roundDurationSec
- Slug query ensures reliable finding of duration-specific markets
- Fallback to generic search for between-round edge cases

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-12 13:53:28 +00:00
alsk1992andClaude Haiku 4.5 3a08e4d86c v1.6.20: Fix WebSocket reconnect race conditions
Bind event listeners to socket instance instead of closure variable.
Guard open/close handlers with `ws !== socket` check to prevent stale
socket events from triggering duplicate reconnections. Cancel pending
reconnect timers when open fires. Fixes duplicate Manifold connect/
disconnect logs and Polymarket reconnect loops creating zombie connections.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 23:23:14 +00:00
alsk1992andClaude Haiku 4.5 066953b4e9 v1.6.19: Fix intent detection gaps for common market queries
Add "markets", "odds", "trending", "crypto", "invest" to category keywords
so queries like "what are the odds on trump" and "show me trending markets"
correctly trigger intent detection instead of falling through to zero-intent
tool gating. Reduces 13 gaps to 5 (remaining are very vague queries).

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 20:47:03 +00:00
alsk1992andClaude Haiku 4.5 85f60dbef1 Add polymarket_crypto_markets to core tools + market keyword intent (v1.6.18)
The crypto markets tool (BTC/ETH/SOL 15m/1h/daily) was only discoverable
via tool_search. Add to core set so "fetch btc 15 min market" works on
first message. Add "market/markets/fetch" to market_data category keywords.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 20:35:29 +00:00
alsk1992andClaude Haiku 4.5 1f8a95ca53 Smart tool gating + skip skill directory on zero match (v1.6.17)
Zero-intent first messages ("hi") now send only tool_search (~50 tokens)
instead of 22 core tools (~1.5K). Skip 120-skill compact directory when
nothing matched (~300 tokens saved). Strip redundant isZeroIntent check.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 20:08:29 +00:00
alsk1992andClaude Haiku 4.5 414c9ec9d9 Strip internal metadata from tools before API call (v1.6.16)
Tool registry adds metadata (platform, category, core) for internal
routing. The Anthropic API rejects these as extra fields on custom-type
tools: "tools.0.custom.metadata: Extra inputs are not permitted".

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 19:44:23 +00:00
alsk1992andClaude Haiku 4.5 ab4a51d5df Dynamic skill budget + prompt caching (v1.6.15)
Scale skill token budget by query complexity (500-80K vs fixed 12K).
Add Anthropic prompt caching with cache_control on system prompt and tools
for ~90% cost reduction on cache hits.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 18:57:52 +00:00
alsk1992andClaude Opus 4.6 10a3f28028 Lazy skill context loading — 90-99% token savings per message
Instead of dumping all 120 SKILL.md files (~93K tokens) into the system
prompt on every message, only expand skills matching the user's message.

- Compact grouped directory (~240 tokens) always included
- Keyword/alias matching with platform awareness
- Token budget cap (25K tokens max for expanded skills)
- Domain-specific stop words to reduce false matches
- Score threshold (>=2) filters single-word noise

"hi" → 241 tokens (was 93K). Trading query → 3-10K tokens.
Combined with tool registry: total drops from ~370K to ~500-10K tokens.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-11 17:15:47 +00:00
alsk1992andClaude Haiku 4.5 8903ec79da Fix WebChat double-reply bug + add message dedup guard
WebChat's WSS connection listener was never removed on stop(),
causing duplicate handlers after rebuildRuntime config reloads.
Added dedup Map in handleIncomingMessage as safety net.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 16:39:14 +00:00
alsk1992andClaude Haiku 4.5 1f57634d3a 1.6.11
Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
2026-02-11 16:24:41 +00:00
alsk1992 03f8b83bba 1.6.10 2026-02-11 02:25:47 +00:00
alsk1992 6df0464f27 1.6.9 2026-02-11 00:33:52 +00:00
alsk1992 d297aa267b 1.6.8 2026-02-10 23:31:34 +00:00
alsk1992 5329406ee9 1.6.7 2026-02-10 23:26:08 +00:00
alsk1992andClaude Opus 4.6 865fbdd694 v1.6.6: Load .env from ~/.clodds/.env where onboard writes it
dotenv was loading from CWD only, but when installed globally via npm
the CWD is /usr/lib/node_modules/clodds — not where ~/.clodds/.env lives.
Now all entry points (index.ts, cli/index.ts, utils/config.ts) load from
~/.clodds/.env first, with CWD as fallback.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 17:56:24 +00:00
alsk1992andClaude Opus 4.6 82fb22a5e6 v1.6.5: Auto-generate CLODDS_CREDENTIAL_KEY in onboard command
The onboard wizard was writing .env with only ANTHROPIC_API_KEY +
channel tokens, missing CLODDS_CREDENTIAL_KEY entirely. This caused
credential encryption to fail for every new user after onboarding.

Now onboard auto-generates the key (preserving existing key if
re-running onboard to avoid invalidating stored credentials).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 17:38:30 +00:00
alsk1992andClaude Opus 4.6 c82491d93b v1.6.4: Fix context compaction — stop overestimating tool tokens
v1.6.2-3 broke all conversations by including JSON.stringify(tools) in
reserveTokens. Client-side tool token estimation is wildly inaccurate
(JSON tokenization != API's internal tool counting). With 630 tools this
was reserving 100k+ tokens, leaving no room for messages.

Fix: reserve only system prompt + response buffer. Use actual
response.usage.input_tokens from API to track real context usage and
trigger compaction when the API reports >85% utilization. Catch
prompt-too-long errors gracefully instead of pre-emptive bail-outs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 17:16:49 +00:00
alsk1992andClaude Opus 4.6 2fb77ce95a v1.6.3: Fix context compaction to properly account for tool + system token overhead
The previous fix (v1.6.2) added tools to estimateSubmitTokens() but the
context manager's own compaction logic still didn't know about tools/system.
This meant compact() targeted 70% of 200k for messages, but with 100k+ of
tool definitions, the total still blew past the limit.

Fix: reserveTokens now includes tools + system prompt + response buffer,
so the context manager's guard and compact() methods operate on the real
available budget for messages. Also adds a safety bail-out if context
exceeds limit even after compaction.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 17:01:37 +00:00
alsk1992andClaude Opus 4.6 e40be0ce1b v1.6.2: Fix context compaction missing tool definitions in token estimate
estimateSubmitTokens() was not counting tool definition tokens, causing the
compaction guard to think context was under limit when it was actually 2x over.
This caused 384k token requests to hit the 200k API limit.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 16:52:19 +00:00
alsk1992andClaude Opus 4.6 ba82351556 v1.6.1: Auto-generate credential key, PumpFun→PumpSwap graduation fix
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-10 16:37:16 +00:00