2026-08-04 - 2026-09-04
Overview
81 Pull requests merged by 1 user
Merged
#381 fix: give every address a row of its own, so none wraps or is shortened (closes #380)
Merged
#190 milestone 1.0.0: approval-path security, build-integrity guard, e2e harness and filter coverage
Merged
#366 fix: floor the persisted fields a restore dereferences, and make each field's floor an executable claim (closes #362)
Merged
#376 fix: declare toolbar icons and ship real PNGs in both archives (closes #371)
Merged
#367 fix: store an absent explorer decimals as unknown instead of fabricating 18 (closes #349)
Merged
#368 harden: pair every swap amount with the token that supplied it
Merged
#365 harden: say a swap's input token is unknown rather than calling it ETH (closes #357)
Merged
#360 fix: version the stored profile, and give a record that cannot be read a way out (closes #311)
Merged
#356 harden: say a swap's output token is unknown rather than calling it ETH (closes #353)
Merged
#344 harden: make the background physically unable to read the shared state singleton
Merged
#352 fix: always name a swap's output token, by address when no symbol is known (closes #346)
Merged
#345 harden: resolve the swap approval screen's token scale, or refuse to format
Merged
#347 release: package the extension, pin the Chrome extension id, and prove the wallet survives a reinstall (closes #310)
Merged
#339 fix: never render a nonzero approval amount as zero (closes #322)
Merged
#341 build: remove dist/ when a release build fails (closes #333)
Merged
#338 docs: state verify-build's dist/ guarantee at the width it enforces (closes #331)
Merged
#337 fix: make saveState() a read-modify-write merge instead of a full-blob overwrite (closes #304)
Merged
#334 fix: let a user who lost the password delete the wallet, and warn before they can (closes #312)
Merged
#330 fix: verify the build against its own receipt, with the expected mode as an argument (closes #309)
Merged
#327 fix: render a hostile token symbol as text, and put a floor under the CSP (closes #307)
Merged
#319 fix: answer eth_chainId and net_version from loaded state (closes #317)
Merged
#321 fix: show the true token amount on the approval screen, or none at all (closes #306)
Merged
#313 fix: gate the chain switch and remember endpoints per network (closes #308)
Merged
#314 fix: sign the ERC-20 amount the send screen displayed (closes #305)
Merged
#301 feat: vendor and censor the phishing blocklist at build time (closes #219)
Merged
#289 fix: settle a site approval on the port that carries its teardown (closes #275)
Merged
#282 fix: answer the page when a background handler throws (closes #280)
Merged
#299 test: drive the Settings screen in a browser and guard every popup element id (closes #229)
Merged
#286 build: add ESLint to script/lint and containerize linting (closes #152)
Merged
#281 refactor: one shared extension-API module, and drive the dApp flows on Firefox (closes #153)
Merged
#296 fix: one wording for an empty password field on every screen (closes #265)
Merged
#291 build: run the browser e2e suites in CI (closes #259)
Merged
#284 fix: one transaction approval at a time, and honest copy for a nonce collision (closes #271)
Merged
#298 fix: an address holding only unpriced tokens is no longer totalled at $0.00 (closes #261)
Merged
#288 test: assert the #150 and #151 items the harness did not cover (closes #188)
Merged
#292 docs: drop the README limit the EIP-1193 code fix removed (closes #285)
Merged
#272 fix: render the view "Back" lands on after the popup is reopened (closes #268)
Merged
#278 fix: carry EIP-1193 error codes through to the page (closes #274)
Merged
#277 fix: a shared ticker no longer hides one of its two real tokens (closes #276)
Merged
#273 test: drive the EIP-1193 dApp approval round trips in the browser (closes #183)
Merged
#270 fix: judge the symbol a user sees, not the bytes a contract returns (closes #260)
Merged
#256 test: containerized Firefox end-to-end harness (closes #184)
Merged
#269 harden: verify the signed transaction against what the popup displayed (closes #216)
Merged
#266 fix: filter the restored view stack against RESTORABLE_VIEWS (closes #224)
Merged
#264 fix: one wording for a rejected password on every screen (closes #172)
Merged
#267 test: close the empty-array hole in the e2e unstubbed-request guard (closes #187)
Merged
#258 test: drive ConfirmTx in the e2e suite, gate assertion included (closes #238)
Merged
#243 fix: explain a rejected dust threshold instead of snapping back silently (closes #233)
Merged
#205 harden: verify all approval fields and make failed signing retryable (closes #174)
Merged
#240 feat: remove an address from an HD wallet, behind a confirmation (closes #162)
Merged
#257 fix: filter a fake ETH token from the balance list too (closes #235)
Merged
#249 test: cover every verify-build failure mode from make check (closes #227)
Merged
#201 fix: WaitTx timeout no longer overwrites a rendered success screen (closes #155)
Merged
#248 fix: wipe the exported private key from the DOM on leaving the screen (closes #221)
Merged
#247 fix: explain a stored non-master xprv wallet instead of throwing at signing time (closes #234)
Merged
#244 fix: treat an unreported holders_count as unknown, not as zero holders (closes #230)
Merged
#206 fix: run libsodium on WebAssembly under the extension CSP (closes #182)
Merged
#241 docs: describe the bundled token list by selection criterion, not count (closes #239)
Merged
#197 fix: count the network fee in the confirm-screen balance check (closes #154)
Merged
#208 fix: drive background refresh and phishing update from alarms (closes #158)
Merged
#226 fix: add a Settings toggle for known-symbol spoof verification (closes #176)
Merged
#214 fix: move the UTC Timestamps checkbox into the Display well (closes #212)
Merged
#232 fix: enforce the base58 checksum and reject non-master extended keys (closes #210)
Merged
#225 fix: NUL-delimit verify-build's dist walk so no path escapes the check (closes #223)
Merged
#215 feat: password-gated recovery phrase display for HD wallets (closes #161)
Merged
#228 fix: honour a dust threshold of 0 and compare addresses case-insensitively (closes #179)
Merged
#209 test: known-answer coverage for HD derivation and the vault (closes #159)
Merged
#204 chore: repo policy compliance sweep — test rerun, npx, frozen lockfile, docs (closes #166)
Merged
#196 fix: one transaction history row per value movement (closes #177)
Merged
#203 fix: correct verify-build diagnostics and close its vacuous passes (closes #180)
Merged
#200 fix: derive hasWallet from the wallet list on load (closes #195)
Merged
#217 docs: correct three README claims contradicted by the code (closes #213)
Merged
#202 docs: rebuild the README Screen Map from the code (closes #164)
Merged
#199 docs: correct docs/README.md external services and remove competitor names (closes #163)
Merged
#194 fix: repair wallet state on delete (closes #156)
Merged
#192 docs: rewrite TODO.md workflow for the branch-per-issue model on next
Merged
#178 build: assert DEBUG is off in every emitted bundle as a post-build check (closes #170)
Merged
#171 security: decrypt and sign dApp approvals in the popup (closes #157)
Merged
#175 test: cover the address-poisoning filters in transactions.js (closes #160)
Merged
#185 test: containerized Chrome end-to-end harness that drives the real popup (closes #181)
Merged
#169 security: make DEBUG a build-time flag defaulting to off (closes #149)
91 Issues closed from 1 user
Closed
#380 wallet view: addresses wrap and break the layout when a wallet has multiple addresses
Closed
#191 docs: TODO.md describes the old branch-from-main workflow and its Status/Next Step are stale
Closed
#362 fix: malformed allowedSites and fraudContracts entries are dereferenced without a floor
Closed
#371 fix: neither manifest declares icons, so both browsers show a generic puzzle piece
Closed
#349 fix: balances.js fabricates decimals 18 before storage, laundering a guess into both approval paths
Closed
#364 harden: a zero input amount lets a later hop's figure be displayed against an earlier hop's Token In
Closed
#359 harden: a V4 step with a zero amountOutMin leaves an earlier hop's Min. received on screen
Closed
#357 harden: the input side has the same null-means-ETH collapse — an undetermined inputToken is asserted as "ETH (native)"
Closed
#311 fix: stored state has no version and no migration, and a corrupt blob bricks the popup and every dApp call
Closed
#353 harden: a V4 swap with an undetermined output token is asserted to the user as ETH at 18 decimals
Closed
#340 harden: the swap approval screen guesses 18 decimals for any token not in the bundled list
Closed
#320 fix: a cold worker prepares a dApp transaction for the wrong chain, so every non-mainnet dApp send is refused
Closed
#324 harden: the background must stop reading the shared state singleton — one root cause, five sites, and the fixes keep adding new ones
Closed
#346 fix: a swap to a token absent from the bundled list shows no Token Out line at all
Closed
#310 release: there is no packaging, no artifact and no signing — the extension cannot be installed durably on either browser
Closed
#322 fix: a nonzero approval amount still renders as 0.0000 when it is smaller than the 4-decimal display floor
Closed
#333 build: a failed release build leaves the complete INSECURE debug bundle loadable in dist/
Closed
#331 docs: README claims verify-build covers "nothing the build did not write", which is broader than what is enforced
Closed
#304 fix: a second extension page silently deletes a wallet — saveState() is a last-writer-wins full-blob overwrite
Closed
#312 fix: a forgotten password permanently wedges the wallet — cannot delete it, cannot re-import the phrase
Closed
#303 pre-1.0 security review: key handling, DEBUG-mode policy, RPC input validation
Closed
#309 build: make build can produce an INSECURE debug bundle and verify-build certifies it green
Closed
#307 harden: a hostile ERC-20 symbol renders as live HTML in the popup — cross-origin iframe over the wallet UI
Closed
#317 fix: a cold worker answers eth_chainId and net_version from never-loaded state, reporting mainnet to a page whose user is on Sepolia
Closed
#306 fix: the dApp approval screen renders a 5,000-token transfer as "Amount 0.0000"
Closed
#316 fix: the background worker saves state it never loaded, so a chain switch wipes every wallet in storage
Closed
#308 fix: any web page can switch the network and destroy the user's custom RPC endpoint, unprompted and unconnected
Closed
#305 fix: the popup's own ERC-20 send signs an amount it never displayed (indexer decimals vs contract decimals)
Closed
#219 decision: the phishing blocklist URL embeds a competitor's org name, and its documented upstream no longer exists
Closed
#300 every unit conflicts with every other unit in TODO.md, costing a rebase cycle per merge
Closed
#302 DEP0205 module.register() deprecation warning during make build
Closed
#275 fix: approving a site connection races the popup teardown and can be recorded as a rejection
Closed
#280 fix: a throw inside handleRpc hangs the dApp's promise forever with no error
Closed
#229 test: the Settings view has no browser coverage, so a wrong element id takes the whole screen down undetected
Closed
#152 build: add ESLint to script/lint — make check cannot currently catch undefined identifiers
Closed
#153 fix: Firefox target is non-functional — Chrome callback APIs used against the promise-only browser namespace
Closed
#265 fix: the empty-password message diverges on the private key export screen
Closed
#259 build: nothing automatic ever runs the e2e suites, so every browser-level guarantee is manual-only
Closed
#271 fix: two concurrent dApp transactions are populated with the same nonce, and the second fails terminally
Closed
#261 fix: an address holding only unpriced tokens reports its total as $0.00
Closed
#186 decision: agent commits are landing under three different author identities, including yours
Closed
#188 test: assert the DoD items from #150 and #151 that the harness does not yet cover
Closed
#285 docs: README still documents the EIP-1193 code loss that #274 fixed
Closed
#268 fix: Back after reopening the popup lands on a blank screen, because goBack() never re-renders
Closed
#274 fix: EIP-1193 error codes never reach the page — a dApp cannot detect a user rejection
Closed
#276 fix: seven bundled tokens are filtered as spoofs of their own duplicate symbol
Closed
#220 blocked: no Actions runner is picking up jobs — every CI run sits queued forever
Closed
#183 test: drive the EIP-1193 dApp approval round trips in the browser harness
Closed
#260 fix: a whitespace-padded symbol bypasses the spoof filter but still displays as the real one
Closed
#184 test: containerized Firefox end-to-end harness (geckodriver, MV2 temporary add-on)
Closed
#216 harden: approval verification compares against the dApp's request, not against what the popup displayed
Closed
#224 fix: the restored viewStack can contain views the popup may not reopen onto, giving a dead-end screen
Closed
#172 fix: "Wrong password." is a sentence fragment and diverges from the other password prompts
Closed
#187 test: an empty-array POST body escapes the e2e unstubbed-request guard
Closed
#238 test: ConfirmTx has no automated coverage at all — the screen that decides what gets signed
Closed
#233 fix: the dust threshold field rejects input silently, snapping back with no explanation
Closed
#174 harden: approvalVerify does not compare chainId, nonce or fee fields; failed signing leaves an unretryable button
Closed
#162 feat: delete an address from an HD wallet (with confirmation)
Closed
#235 fix: a fake token impersonating ETH is filtered from history and send, but still shows in the balance list
Closed
#227 test: verify-build's failure modes are only ever proven by hand — make the battery a committed target
Closed
#155 fix: WaitTx 60s timeout overwrites an already-rendered success screen
Closed
#221 fix: leaving the private-key export screen leaves the private key in the DOM for the life of the popup
Closed
#234 fix: an already-imported non-master xprv wallet will throw at signing time with no explanation
Closed
#230 fix: an omitted holders_count is coerced to 0, so a legitimate token gets filtered as spam
Closed
#182 fix: libsodium WASM is refused by the extension CSP on every popup load, silently falling back to asm.js
Closed
#239 docs: the bundled token list is described as "top 250" in four places and "roughly 500" in another; it is 512
Closed
#154 fix: gas fee is excluded from the insufficient-balance check, so max-value ETH sends fail at broadcast
Closed
#158 fix: MV3 service worker termination kills the background refresh and the 24h phishing list update
Closed
#176 fix: known-symbol spoof verification has no off switch, contradicting the README's user-configurable promise
Closed
#212 fix: the UTC Timestamps checkbox sits inside the Token Spam Protection well
Closed
#210 fix: isValidXprv accepts a mistyped extended key and silently imports a different wallet
Closed
#223 fix: verify-build's dist walk is line-delimited, so a path with trailing whitespace escapes the unlisted-bundle check
Closed
#161 feat: show wallet's recovery phrase (requires password)
Closed
#179 fix: a dust threshold of 0 silently becomes 100,000 gwei, and isSpoofedSymbol is case-sensitive on the contract address
Closed
#159 test: cover wallet.js key derivation and vault.js encryption — currently zero tests on the crypto core
Closed
#166 chore: repo policy compliance sweep — test rerun pattern, yarn/npx, frozen lockfile, undocumented targets
Closed
#177 fix: every plain ERC-20 transfer produces two rows in transaction history
Closed
#180 fix: verify-build diagnostic overstates the failure, and two robustness gaps in the same script
Closed
#195 fix: loadState reads hasWallet from storage without reconciling it against wallets.length
Closed
#213 docs: three README.md claims are contradicted by the shipped code
Closed
#164 docs: README Screen Map omits three shipped screens and misdescribes four flows
Closed
#163 docs: docs/README.md names competitors and contradicts the code on external services
Closed
#156 fix: deleting the last wallet leaves hasWallet true, resets selection unconditionally, and skips the active-address broadcast
Closed
#189 TOP PRIORITY: consolidate all open PRs onto one next branch, one PR
Closed
#170 build: assert DEBUG is off in every emitted bundle as a post-build check
Closed
#157 security: the user's plaintext password crosses the extension messaging boundary during dApp approvals
Closed
#160 test: the entire address-poisoning defense in transactions.js is untested
Closed
#151 fix: TransactionDetail crashes for every ERC-20 transfer — ReferenceError: addressDotHtml is not defined
Closed
#150 fix: AddToken screen is unreachable — ReferenceError: showView is not defined
Closed
#181 test: containerized Chrome end-to-end harness that drives the real popup
Closed
#149 security: DEBUG hardcoded on — every generated recovery phrase is the public test phrase
152 Issues created by 1 user
Opened
#149 security: DEBUG hardcoded on — every generated recovery phrase is the public test phrase
Opened
#150 fix: AddToken screen is unreachable — ReferenceError: showView is not defined
Opened
#151 fix: TransactionDetail crashes for every ERC-20 transfer — ReferenceError: addressDotHtml is not defined
Opened
#152 build: add ESLint to script/lint — make check cannot currently catch undefined identifiers
Opened
#153 fix: Firefox target is non-functional — Chrome callback APIs used against the promise-only browser namespace
Opened
#154 fix: gas fee is excluded from the insufficient-balance check, so max-value ETH sends fail at broadcast
Opened
#155 fix: WaitTx 60s timeout overwrites an already-rendered success screen
Opened
#156 fix: deleting the last wallet leaves hasWallet true, resets selection unconditionally, and skips the active-address broadcast
Opened
#157 security: the user's plaintext password crosses the extension messaging boundary during dApp approvals
Opened
#158 fix: MV3 service worker termination kills the background refresh and the 24h phishing list update
Opened
#159 test: cover wallet.js key derivation and vault.js encryption — currently zero tests on the crypto core
Opened
#160 test: the entire address-poisoning defense in transactions.js is untested
Opened
#161 feat: show wallet's recovery phrase (requires password)
Opened
#162 feat: delete an address from an HD wallet (with confirmation)
Opened
#163 docs: docs/README.md names competitors and contradicts the code on external services
Opened
#164 docs: README Screen Map omits three shipped screens and misdescribes four flows
Opened
#165 decision: Sepolia support contradicts "Non-Goals for 1.0", and isMetaMask names a competitor in shipped code
Opened
#166 chore: repo policy compliance sweep — test rerun pattern, yarn/npx, frozen lockfile, undocumented targets
Opened
#167 chore: prune 24 stale remote feature branches
Opened
#168 chore: remove dead exports and de-duplicate copy-pasted view helpers
Opened
#170 build: assert DEBUG is off in every emitted bundle as a post-build check
Opened
#172 fix: "Wrong password." is a sentence fragment and diverges from the other password prompts
Opened
#173 decision: no browser in the agent environment, so several 1.0.0 items cannot have their DoD verified
Opened
#174 harden: approvalVerify does not compare chainId, nonce or fee fields; failed signing leaves an unretryable button
Opened
#176 fix: known-symbol spoof verification has no off switch, contradicting the README's user-configurable promise
Opened
#177 fix: every plain ERC-20 transfer produces two rows in transaction history
Opened
#179 fix: a dust threshold of 0 silently becomes 100,000 gwei, and isSpoofedSymbol is case-sensitive on the contract address
Opened
#180 fix: verify-build diagnostic overstates the failure, and two robustness gaps in the same script
Opened
#181 test: containerized Chrome end-to-end harness that drives the real popup
Opened
#182 fix: libsodium WASM is refused by the extension CSP on every popup load, silently falling back to asm.js
Opened
#183 test: drive the EIP-1193 dApp approval round trips in the browser harness
Opened
#184 test: containerized Firefox end-to-end harness (geckodriver, MV2 temporary add-on)
Opened
#186 decision: agent commits are landing under three different author identities, including yours
Opened
#187 test: an empty-array POST body escapes the e2e unstubbed-request guard
Opened
#188 test: assert the DoD items from #150 and #151 that the harness does not yet cover
Opened
#189 TOP PRIORITY: consolidate all open PRs onto one next branch, one PR
Opened
#191 docs: TODO.md describes the old branch-from-main workflow and its Status/Next Step are stale
Opened
#193 decision: RULES.md "Build & Workflow" still says merge to main, contradicting the branch-per-issue-onto-next model
Opened
#195 fix: loadState reads hasWallet from storage without reconciling it against wallets.length
Opened
#198 feat: "send max" affordance — emptying an ETH account now requires manual arithmetic
Opened
#207 decision: a dApp-supplied gas limit is silently dropped, so the popup always re-estimates
Opened
#210 fix: isValidXprv accepts a mistyped extended key and silently imports a different wallet
Opened
#211 decision: RULES.md states three things the code contradicts
Opened
#212 fix: the UTC Timestamps checkbox sits inside the Token Spam Protection well
Opened
#213 docs: three README.md claims are contradicted by the shipped code
Opened
#216 harden: approval verification compares against the dApp's request, not against what the popup displayed
Opened
#218 test: popup reload mid-refresh can fail the e2e run with "loadHomeTxs failed: Failed to fetch"
Opened
#219 decision: the phishing blocklist URL embeds a competitor's org name, and its documented upstream no longer exists
Opened
#220 blocked: no Actions runner is picking up jobs — every CI run sits queued forever
Opened
#221 fix: leaving the private-key export screen leaves the private key in the DOM for the life of the popup
Opened
#222 decision: the per-unit TODO.md entry makes every merge invalidate every open PR
Opened
#223 fix: verify-build's dist walk is line-delimited, so a path with trailing whitespace escapes the unlisted-bundle check
Opened
#224 fix: the restored viewStack can contain views the popup may not reopen onto, giving a dead-end screen
Opened
#227 test: verify-build's failure modes are only ever proven by hand — make the battery a committed target
Opened
#229 test: the Settings view has no browser coverage, so a wrong element id takes the whole screen down undetected
Opened
#230 fix: an omitted holders_count is coerced to 0, so a legitimate token gets filtered as spam
Opened
#231 decision: what should the confirm screen quote as the network fee — estimate, reserve, or both?
Opened
#233 fix: the dust threshold field rejects input silently, snapping back with no explanation
Opened
#234 fix: an already-imported non-master xprv wallet will throw at signing time with no explanation
Opened
#235 fix: a fake token impersonating ETH is filtered from history and send, but still shows in the balance list
Opened
#236 harden: an oversized phishing delta erases the previously stored one, dropping to vendored-only coverage for up to 24h
Opened
#237 chore: script/test-e2e emits DEP0205 module.register() deprecation warning
Opened
#238 test: ConfirmTx has no automated coverage at all — the screen that decides what gets signed
Opened
#239 docs: the bundled token list is described as "top 250" in four places and "roughly 500" in another; it is 512
Opened
#242 tokenList.js header comment says "511 tokens"; the array has 512
Opened
#245 harden: connectedSites is never cleared for a removed address or wallet
Opened
#246 harden: decimals || "18" collapses absent and zero if a backend ever sends numeric 0
Opened
#250 fix: a contract deployment shows a blank recipient on the wait and approval screens
Opened
#251 harden: parseHoldersCount partial-parses a malformed count into a reported low count, hiding the token
Opened
#252 fix: flash messages longer than one line wrap and shift the layout, defeating the reserved-space policy
Opened
#253 test: the private-key export screen has no e2e coverage, unlike the recovery-phrase screen
Opened
#254 test: the defective-wallet UI gates have no coverage — all six can be deleted with the suite still green
Opened
#255 decision: a defective xprv wallet is told to use other software, but we hold the only key and will not export it
Opened
#259 build: nothing automatic ever runs the e2e suites, so every browser-level guarantee is manual-only
Opened
#260 fix: a whitespace-padded symbol bypasses the spoof filter but still displays as the real one
Opened
#261 fix: an address holding only unpriced tokens reports its total as $0.00
Opened
#262 fix: an approval claimed when its window closes is orphaned, leaving the dApp promise unsettled forever
Opened
#263 chore: script/bootstrap can report success while leaving playwright-core unlinked
Opened
#265 fix: the empty-password message diverges on the private key export screen
Opened
#268 fix: Back after reopening the popup lands on a blank screen, because goBack() never re-renders
Opened
#271 fix: two concurrent dApp transactions are populated with the same nonce, and the second fails terminally
Opened
#274 fix: EIP-1193 error codes never reach the page — a dApp cannot detect a user rejection
Opened
#275 fix: approving a site connection races the popup teardown and can be recorded as a rejection
Opened
#276 fix: seven bundled tokens are filtered as spoofs of their own duplicate symbol
Opened
#279 fix: an unsupported method is reported to the page with no EIP-1193 code (4200)
Opened
#280 fix: a throw inside handleRpc hangs the dApp's promise forever with no error
Opened
#283 Uniswap V2_SWAP_EXACT_OUT (command 0x09) is decoded by a function nothing calls
Opened
#285 docs: README still documents the EIP-1193 code loss that #274 fixed
Opened
#287 flake: the Chrome e2e dApp signing prompt loses its page about one run in three under load
Opened
#290 test: make test-e2e is flaky under host load — "the extension opened no approval window within 30000ms"
Opened
#293 docs: the README e2e limits list omits the harness accommodation that neutralizes window.close
Opened
#294 chore: no workflow sets timeout-minutes, so a hung browser can hold the shared runner for the 6h default
Opened
#295 test: four DoD items from #150 and #151 remain uncovered after #188
Opened
#297 fix: the two dApp approval error containers shift 6px when an error appears
Opened
#300 every unit conflicts with every other unit in TODO.md, costing a rebase cycle per merge
Opened
#302 DEP0205 module.register() deprecation warning during make build
Opened
#303 pre-1.0 security review: key handling, DEBUG-mode policy, RPC input validation
Opened
#304 fix: a second extension page silently deletes a wallet — saveState() is a last-writer-wins full-blob overwrite
Opened
#305 fix: the popup's own ERC-20 send signs an amount it never displayed (indexer decimals vs contract decimals)
Opened
#306 fix: the dApp approval screen renders a 5,000-token transfer as "Amount 0.0000"
Opened
#307 harden: a hostile ERC-20 symbol renders as live HTML in the popup — cross-origin iframe over the wallet UI
Opened
#308 fix: any web page can switch the network and destroy the user's custom RPC endpoint, unprompted and unconnected
Opened
#309 build: make build can produce an INSECURE debug bundle and verify-build certifies it green
Opened
#310 release: there is no packaging, no artifact and no signing — the extension cannot be installed durably on either browser
Opened
#311 fix: stored state has no version and no migration, and a corrupt blob bricks the popup and every dApp call
Opened
#312 fix: a forgotten password permanently wedges the wallet — cannot delete it, cannot re-import the phrase
Opened
#315 test: WaitTx's timeout and consecutive-failed-lookup exit branches have no e2e coverage
Opened
#316 fix: the background worker saves state it never loaded, so a chain switch wipes every wallet in storage
Opened
#317 fix: a cold worker answers eth_chainId and net_version from never-loaded state, reporting mainnet to a page whose user is on Sepolia
Opened
#318 test: e2e hygiene — a failing case leaves routeOpts and the popup screen dirty, cascading into unrelated failures
Opened
#320 fix: a cold worker prepares a dApp transaction for the wrong chain, so every non-mainnet dApp send is refused
Opened
#322 fix: a nonzero approval amount still renders as 0.0000 when it is smaller than the 4-decimal display floor
Opened
#323 fix: the approval screen says "Unknown token" for tokens whose symbol is already known
Opened
#324 harden: the background must stop reading the shared state singleton — one root cause, five sites, and the fixes keep adding new ones
Opened
#325 test: guard decimals:0 against the falsy trap, and de-duplicate toDecimals
Opened
#326 chore: eth_chainId and net_version are listed in PROXY_METHODS but intercepted earlier, so both entries are dead
Opened
#328 harden: move the 39 static style attributes onto classes and drop 'unsafe-inline' from style-src
Opened
#329 chore: escaping hygiene left after #307 — a dead un-encoded explorer helper, two inconsistent bare interpolations, a UTF-16 slice
Opened
#331 docs: README claims verify-build covers "nothing the build did not write", which is broader than what is enforced
Opened
#332 fix: make dev is documented as watch mode but has never watched anything
Opened
#333 build: a failed release build leaves the complete INSECURE debug bundle loadable in dist/
Opened
#335 fix: Confirm Delete stays disabled after a successful wallet delete, so a second delete needs a popup reopen
Opened
#336 harden: two latent gaps in the lost-password confirmation — whitespace-only name, and U+200B still untypable
Opened
#340 harden: the swap approval screen guesses 18 decimals for any token not in the bundled list
Opened
#342 chore: rough edges in script/discard-dist-on-failure — status swallowed when stderr is closed, silent SIGINT, and a censored-word failure wipes a good release build
Opened
#343 fix: the send and send-confirm screens render a sub-1e-6 balance and fee as 0.0
Opened
#346 fix: a swap to a token absent from the bundled list shows no Token Out line at all
Opened
#348 decision: who owns the Chrome CRX signing key, and does 1.0 require AMO signing for Firefox
Opened
#349 fix: balances.js fabricates decimals 18 before storage, laundering a guess into both approval paths
Opened
#350 harden: a token scale above ~87 makes the whole swap silently undecodable
Opened
#351 harden: the test recovery phrase ships inside the release artifacts, and the committed-key guard matches only by filename
Opened
#353 harden: a V4 swap with an undetermined output token is asserted to the user as ETH at 18 decimals
Opened
#354 chore: a tracked token's symbol is ignored, so the approval screen says "Unknown token" for a token the user added by hand
Opened
#355 chore: the Tailwind CLI emits a module.register() deprecation warning on every build
Opened
#357 harden: the input side has the same null-means-ETH collapse — an undetermined inputToken is asserted as "ETH (native)"
Opened
#358 chore: V4 struct decodes target the deployed shape, and silently stop describing swaps if periphery adds a field
Opened
#359 harden: a V4 step with a zero amountOutMin leaves an earlier hop's Min. received on screen
Opened
#361 test: the state-recovery screen has no e2e coverage, so its behaviour under the real manifest CSP is unverified
Opened
#362 fix: malformed allowedSites and fraudContracts entries are dereferenced without a floor
Opened
#363 chore: .prettierignore names an AI vendor tool directory
Opened
#364 harden: a zero input amount lets a later hop's figure be displayed against an earlier hop's Token In
Opened
#369 docs: README still says a genuine zero renders 0.0000, and the approval screen's refusal vocabulary is undocumented
Opened
#370 decision: a trailing PERMIT2_PERMIT replaces the swap's input side on the approval screen
Opened
#371 fix: neither manifest declares icons, so both browsers show a generic puzzle piece
Opened
#372 chore: networks.js defines nativeCurrency and nothing reads it, so Sepolia balances and fees all read "ETH"
Opened
#373 fix: a popup already open when storage becomes unreadable keeps rendering the stale profile
Opened
#374 fix: adding a second wallet silently accepts a different password, with nothing saying it is a separate one
Opened
#375 chore: the testnet and debug banners leak the internal view id, e.g. "[TESTNET] (approve-tx)"
Opened
#377 fix: an unknown-scale token reads differently on Send than on the confirmation screen, and the fee error promises a retry that cannot help
Opened
#378 chore: the toolbar icons ship as opaque binaries with no in-tree way to regenerate them
Opened
#379 test: classes of undriven path in the persisted-field contract harness
Opened
#380 wallet view: addresses wrap and break the layout when a wallet has multiple addresses