<feed xmlns='http://www.w3.org/2005/Atom'>
<title>digiid-ts/package-lock.json, branch v2.0.4</title>
<subtitle>[MIRROR] A modern TypeScript implementation of the Digi-ID authentication protocol</subtitle>
<id>https://git.zelu.dev/digiid-ts/atom?h=v2.0.4</id>
<link rel='self' href='https://git.zelu.dev/digiid-ts/atom?h=v2.0.4'/>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/'/>
<updated>2026-05-15T16:55:55Z</updated>
<entry>
<title>chore: patch fast-uri security vulnerabilities</title>
<updated>2026-05-15T16:55:55Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel@pzelawski.com</email>
</author>
<published>2026-05-15T16:55:55Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=3f3521cf5dad43dc537e6a56e469ccf73ae41927'/>
<id>urn:sha1:3f3521cf5dad43dc537e6a56e469ccf73ae41927</id>
<content type='text'>
</content>
</entry>
<entry>
<title>chore: bump version to 2.0.3, patch security vulnerabilities in vite and lodash</title>
<updated>2026-04-18T15:03:41Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel@pzelawski.com</email>
</author>
<published>2026-04-18T15:03:41Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=c333c7daecb0bb6a026d26844dbf57c2665051d7'/>
<id>urn:sha1:c333c7daecb0bb6a026d26844dbf57c2665051d7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>fix: resolve Rollup path traversal vulnerability (CVE)</title>
<updated>2026-03-01T12:29:50Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel.zelawski@outlook.com</email>
</author>
<published>2026-03-01T12:29:50Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=49f83b48196fbc260979f4a808328a34992b12c5'/>
<id>urn:sha1:49f83b48196fbc260979f4a808328a34992b12c5</id>
<content type='text'>
- Upgrade rollup from 4.40.0 to 4.59.0 via npm override
- Fix Rollup arbitrary file write vulnerability via path traversal
- Upgrade minimatch to 10.2.3 to fix ReDoS vulnerabilities
- All security vulnerabilities resolved (0 vulnerabilities)
- Tests and build verified working
</content>
</entry>
<entry>
<title>chore: release v2.0.1</title>
<updated>2026-01-23T11:29:59Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel.zelawski@outlook.com</email>
</author>
<published>2026-01-23T11:29:59Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=aee3b086b739c7256c33a8a8ddcf50fa96188cd0'/>
<id>urn:sha1:aee3b086b739c7256c33a8a8ddcf50fa96188cd0</id>
<content type='text'>
- Fixed signature verification by correcting message hash calculation
- Removed extra length byte before DigiBytes message prefix
- Enhanced public key recovery with all 4 recovery IDs
- Resolved all security vulnerabilities (removed elliptic dependency)
- All tests passing
</content>
</entry>
<entry>
<title>chore: update package-lock.json</title>
<updated>2026-01-23T11:22:10Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel.zelawski@outlook.com</email>
</author>
<published>2026-01-23T11:22:10Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=611089aa50e1d7301fa66de1aa205c398862634e'/>
<id>urn:sha1:611089aa50e1d7301fa66de1aa205c398862634e</id>
<content type='text'>
</content>
</entry>
<entry>
<title>fix: correct message hashing for signature verification</title>
<updated>2026-01-23T11:19:10Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel.zelawski@outlook.com</email>
</author>
<published>2026-01-23T11:19:10Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=431497920652a37d2bcb9704a6465a7c474922eb'/>
<id>urn:sha1:431497920652a37d2bcb9704a6465a7c474922eb</id>
<content type='text'>
- Fixed hashMessage function to not add extra length byte before message prefix
- The prefix '\x19DigiByte Signed Message:\n' already contains the length indicator
- Enhanced public key recovery to try all 4 recovery IDs for better compatibility
- Verified with both beta.0 and beta.1 test data
- All tests passing
</content>
</entry>
<entry>
<title>chore: bump to v2.0.0</title>
<updated>2026-01-23T09:54:10Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel.zelawski@outlook.com</email>
</author>
<published>2026-01-23T09:54:10Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=491058ae03ba1f0ae70fe3c684002c9e8e864a53'/>
<id>urn:sha1:491058ae03ba1f0ae70fe3c684002c9e8e864a53</id>
<content type='text'>
</content>
</entry>
<entry>
<title>feat: migrate from bitcoinjs-message to @noble/curves</title>
<updated>2026-01-23T09:51:35Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel.zelawski@outlook.com</email>
</author>
<published>2026-01-23T09:51:35Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=8c32933900e3ed4aa294b6c06403bd406129d349'/>
<id>urn:sha1:8c32933900e3ed4aa294b6c06403bd406129d349</id>
<content type='text'>
BREAKING CHANGE: Replace bitcoinjs-message with @noble/curves for signature verification
- Remove elliptic vulnerability (all versions &lt;= 6.6.1 affected)
- Implement Bitcoin message signing using @noble/curves and @noble/hashes
- Support for Legacy (D/S) and Bech32 (dgb1) addresses
- Update all dev dependencies to latest stable versions
- Remove unnecessary overrides for elliptic and lodash

This is a major version update due to dependency changes, though the public API remains unchanged.
</content>
</entry>
<entry>
<title>chore: bump version to 1.1.1 for security fixes</title>
<updated>2025-12-20T20:00:45Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel.zelawski@outlook.com</email>
</author>
<published>2025-12-20T20:00:45Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=0b3e86989397d526d74c084828f9eb18e7749976'/>
<id>urn:sha1:0b3e86989397d526d74c084828f9eb18e7749976</id>
<content type='text'>
</content>
</entry>
<entry>
<title>fix: resolve security vulnerabilities in dependencies</title>
<updated>2025-12-20T19:49:10Z</updated>
<author>
<name>Pawel Zelawski</name>
<email>pawel.zelawski@outlook.com</email>
</author>
<published>2025-12-20T19:49:10Z</published>
<link rel='alternate' type='text/html' href='https://git.zelu.dev/digiid-ts/commit/?id=a1a01427183425cc985183e299325dbdea553f02'/>
<id>urn:sha1:a1a01427183425cc985183e299325dbdea553f02</id>
<content type='text'>
- Add glob ^10.5.0 override to fix command injection vulnerability (CVE-2024-XXXXX)
- Add brace-expansion ^2.0.2 override to fix ReDoS vulnerability
- Upgrade vite to 6.4.1 and other dependencies via npm audit fix
- All tests passing, build successful, 0 vulnerabilities remaining
</content>
</entry>
</feed>
