Releases: OpenZeppelin/compact-contracts
Release list
v0.4.0-alpha.5
What's Changed
- document cft upgrades by @andrew-fleming in #1006
- docs(multisig): drop the non-transferability claim from the issuer example by @0xisk in #1010
- feat(multisig)!: return the send result from ForwarderShielded._deposit by @0xisk in #999
- Fix
burnFromSelfby @andrew-fleming in #993 - fix(token): drop the duplicate receiveShielded on self coins by @0xisk in #1017
- fix(multisig): reject signer sets below the approval width by @0xisk in #1011
- fix(multisig)!: reject a zero-amount send by @0xisk in #980
- test(test-utils): port the replay, contract-info and rejection helpers (Ledger v9) by @0xisk in #1024
- test(multisig): add ForwarderPrivate privacy spec by @0xisk in #1032
- fix(multisig): take Uint<128> issuer burn amounts by @0xisk in #1033
- fix(multisig)!: reject contract recipients in execute by @0xisk in #1034
- docs(changelog): restore the unreleased section headings by @0xisk in #1035
- docs(changelog): add the 0.4.0-alpha.5 section by @0xisk in #1036
- chore(release): bump version to 0.4.0-alpha.5 by @oz-release-app-midnight[bot] in #1037
Full Changelog: v0.4.0-alpha.4...v0.4.0-alpha.5
v0.4.0-alpha.4
What's Changed
- test: spend the deposited coin in the V2 example by @0xisk in #977
- test: run fewer property cases on live by @0xisk in #976
- build(deps-dev): bump @noble/hashes from 2.2.0 to 2.4.0 by @dependabot[bot] in #947
- build(deps-dev): bump @types/node from 26.5.1 to 26.6.2 by @dependabot[bot] in #946
- fix(multisig)!: mirror the module's mint and burn pairs on NativeShieldedTokenIssuer by @0xisk in #974
- test: drop the fixed treasury address on live by @0xisk in #978
- fix(ci): build split filters from vitest 5 names by @0xisk in #975
- test(harness): deploy through compact-deployer by @0xisk in #979
- test(harness): wait up to 180 s for a wallet sync by @0xisk in #981
- test(token): run the NST specs against the deployed address by @0xisk in #996
- fix(harness): anchor the coin tracker before each spec by @0xisk in #995
- build(contracts): bump compact-deployer to 0.3.1 by @0xisk in #998
- add release header to changelog by @andrew-fleming in #991
- ci(live): key PR runs by label so targets run in parallel by @0xisk in #1001
- docs(changelog): add the 0.4.0-alpha.3 and alpha.4 sections by @0xisk in #1004
- test(multisig): give multi-tx NSTI specs a longer timeout by @0xisk in #1008
- chore(release): bump version to 0.4.0-alpha.4 by @oz-release-app-midnight[bot] in #1016
Full Changelog: v0.4.0-alpha.3...v0.4.0-alpha.4
v0.4.0-alpha.3
What's Changed
- fix(token): L-01: Credit Randomness Nonce Can Be Reset By The Recipient by @0xisk in #958
- fix(token): M-04: _approve Permits Recording Approvals for Non-existent Tokens, Breaking Downstream Circuits by @0xisk in #959
- fix(token): M-03: Pruning and Sweeping Authenticate the Account Secret Without The Encryption Secret by @0xisk in #960
- fix(token): M-01: Missing Running Total Balance Check Can Lock Balances Permanently by @0xisk in #961
- fix(token): H-02: Memo Clearing Is Unconditional and Cannot Exclude Unread Credits by @0xisk in #962
- fix(token): M-02: Escrow Owner Memo Encrypted Under Randomness Controlled by Spender by @0xisk in #963
- fix(crypto): H-01: Account Identifiers And Encryption Secrets Share Undomain-Separated Hash by @0xisk in #964
- fix(token): H-03: Missing Contract Commitment Claim When Recipient is a Contract by @0xisk in #965
- chore(release): bump version to 0.4.0-alpha.3 by @oz-release-app-midnight[bot] in #971
Full Changelog: v0.4.0-alpha.2...v0.4.0-alpha.3
v0.4.0-alpha.2
What's Changed
- build(deps-dev): bump @vitest/coverage-v8 from 4.1.11 to 5.0.0 by @dependabot[bot] in #859
- re-add unreleased header to changelog by @andrew-fleming in #871
- bump biome schema by @andrew-fleming in #870
- build(deps-dev): bump @biomejs/biome from 2.5.11 to 2.5.12 by @dependabot[bot] in #856
- build(deps-dev): bump @types/node from 26.4.0 to 26.5.1 by @dependabot[bot] in #872
- Fix constraints and signer callback by @andrew-fleming in #869
- chore(biome): point $schema at the installed package by @0xisk in #875
- docs: rename @circuitInfo tag to @Constraints by @0xisk in #878
- test(integration): CFT composition spec suite by @0xisk in #696
- ci: add live test suite workflow by @0xisk in #681
- build(deps): batch the open Dependabot bumps by @0xisk in #907
- refactor(multisig): turn presets into modules with deployable examples by @0xisk in #885
- improve ledger docs by @andrew-fleming in #874
- Improve proposal module by @andrew-fleming in #780
- build(deps): bump compact-cli to 0.1.1 by @0xisk in #899
- refactor(multisig): configure Signer from EcdsaSignerManager by @0xisk in #925
- Fix preset example bug by @andrew-fleming in #928
- test(crypto): keep mock circuits impure for live by @0xisk in #850
- add evmAbi module, integrate keccak by @andrew-fleming in #906
- refactor(multisig): compose NativeShieldedToken in the V3 preset by @0xisk in #887
- build(deps): batch the open dependabot bumps by @0xisk in #933
- fix(test-utils): match testkit 5 withWallet signature by @0xisk in #934
- fix(live): gate node health on a finalized block by @0xisk in #937
- build(contracts): pin midnight-js/testkit to beta.7 by @0xisk in #939
- docs(multisig): correct issuer privacy notes by @0xisk in #940
- chore(release): bump version to 0.4.0-alpha.2 by @oz-release-app-midnight[bot] in #942
Full Changelog: v0.4.0-alpha.1...v0.4.0-alpha.2
v0.3.0-rc.1
What's Changed
- build(deps): consolidate open Dependabot updates by @0xisk in #707
- refactor(token): rename NST supply to PublicSupply by @0xisk in #710
- build(deps): bump shell-quote from 1.8.4 to 1.10.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in #708
- build: bump simulator to 0.3.1, mutate private state via updatePrivateState by @0xisk in #755
- build(deps): consolidate open dependabot bumps by @0xisk in #757
- improve cft docs by @andrew-fleming in #720
- Remove stale SignerManager by @andrew-fleming in #760
- Improve docs by @andrew-fleming in #763
- Remove isInit guards in Signer by @andrew-fleming in #761
- Fix unshieldedtreasury deposits, add tests, improve doc by @andrew-fleming in #762
- Fix nonce reset with epoch by @andrew-fleming in #819
- fix(token): require token existence in NonFungibleToken _approve by @0xisk in #824
- Require ek in sweep and clearMemos by @andrew-fleming in #830
- Fix balance width by @andrew-fleming in #831
- Fix memo clearing by @andrew-fleming in #821
- Fix escrow owner memo nonce by @andrew-fleming in #825
- Add domain to secretToScalar by @andrew-fleming in #818
- fix(token)!: reject contract mint/burn recipients by @0xisk in #833
- chore(release): bump version to 0.3.0-rc.1 by @oz-release-app-midnight[bot] in #941
Full Changelog: v0.3.0-alpha.1...v0.3.0-rc.1
v0.4.0-alpha.1
What's Changed
- test(integration): drive the integration specs against the live stack by @0xisk in #717
- Consolidate dependabot updates by @andrew-fleming in #781
- build(deps): bump undici from 8.7.0 to 8.10.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in #764
- test: run remaining categories live and unify shielded-key fixtures by @0xisk in #694
- refactor(test-utils): remove createEitherTestUser by @0xisk in #688
- build(deps): batch open Dependabot bumps by @0xisk in #832
- build(toolchain): bump compact toolchain to 0.34.0 by @0xisk in #841
- build(deps-dev): bump @types/node from 26.2.0 to 26.4.0 by @dependabot[bot] in #839
- build(deps-dev): bump @biomejs/biome from 2.5.10 to 2.5.11 by @dependabot[bot] in #838
- feat(multisig): verify sigs with secp256k1 ECDSA by @0xisk in #842
- docs: zkir v3 known issues for the release by @0xisk in #852
- build(deps): batch dependabot actions bumps by @0xisk in #851
- chore(release): bump version to 0.4.0-alpha.1 by @oz-release-app-midnight[bot] in #853
Full Changelog: v0.3.0-alpha.2...v0.4.0-alpha.1
v0.3.0-alpha.2
What's Changed
- build(deps): consolidate open Dependabot updates by @0xisk in #707
- refactor(token): rename NST supply to PublicSupply by @0xisk in #710
- build(deps): bump shell-quote from 1.8.4 to 1.10.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in #708
- build: bump simulator to 0.3.1, mutate private state via updatePrivateState by @0xisk in #755
- build(deps): consolidate open dependabot bumps by @0xisk in #757
- improve cft docs by @andrew-fleming in #720
- Remove stale SignerManager by @andrew-fleming in #760
- Improve docs by @andrew-fleming in #763
- Remove isInit guards in Signer by @andrew-fleming in #761
- Fix unshieldedtreasury deposits, add tests, improve doc by @andrew-fleming in #762
- chore(release): bump version to 0.3.0-alpha.2 by @oz-release-app-midnight[bot] in #774
Full Changelog: v0.3.0-alpha.1...v0.3.0-alpha.2
v0.3.0-alpha.1
What's Changed
- feat(token): native shielded token derived-nonce extension by @0xisk in #639
- Fix multisig partial spends by @andrew-fleming in #661
- feat(token): native shielded token supply extension by @0xisk in #638
- ci(release): automate publishing with an approval gate by @0xisk in #657
- fix: run biome on full tree, not only --changed by @Yonkoo11 in #674
- add ecdhMask by @andrew-fleming in #655
- add ecdhmask changelog entry by @andrew-fleming in #677
- bump biome schema by @andrew-fleming in #678
- build(deps): consolidate open Dependabot updates by @0xisk in #683
- ci(release): adopt npm OIDC trusted publishing by @0xisk in #658
- build(deps-dev): bump fast-check from 4.8.0 to 4.9.0 by @dependabot[bot] in #686
- build(deps-dev): bump @types/node from 26.1.0 to 26.1.1 by @dependabot[bot] in #685
- build: rename dev scripts to compile/lint by @0xisk in #680
- test: live-backend harness for the contract suite (core + multisig) by @0xisk in #673
- chore(linguist): count .compact files on the language bar by @0xisk in #691
- Add Confidential Fungible Token by @andrew-fleming in #653
- chore(release): bump version to 0.3.0-alpha.1 by @oz-release-app-midnight[bot] in #698
New Contributors
- @Yonkoo11 made their first contribution in #674
- @oz-release-app-midnight[bot] made their first contribution in #698
Full Changelog: v0.3.0-alpha...v0.3.0-alpha.1
v0.3.0-alpha
First alpha of the 0.3.0 line. Pre-release, published to npm under the beta dist-tag.
npm install @openzeppelin/compact-contracts@betaThis release adds the native shielded token standard plus the blocklist, allowlist, ElGamal, and multisig modules, and raises the Compact toolchain to 0.31.0 (pragma language_version >= 0.23.0). The toolchain/pragma bump is breaking for consumers building against compiler < 0.31.0.
Added
- Native shielded token standard implementing
MIP-0011(#621) - Blocklist module (#626)
- Allowlist module (#625)
- ElGamal module (#617)
- Multisig contract suite under
contracts/src/multisig/(M-of-N signer registry, proposal manager, shielded/unshielded treasuries, forwarders, and presets). Signature verification is stubbed pending ECDSA + Keccak primitives (#378, #424, #526)
Changed
- Upgrade the Compact toolchain and Midnight dependencies: compiler
0.29.0→0.31.0,@midnight-ntwrk/compact-runtime0.14.0→0.16.0,@midnight-ntwrk/ledger-v77.0.3→@midnight-ntwrk/ledger-v88.1.0,@openzeppelin/compact-simulator^0.0.1→^0.2.0, andpragma language_version>= 0.21.0→>= 0.23.0 - Migrate the unit suites to the async, backend-aware simulator (dry-run + live) (#620, #631)
Fixed
- Resolve zero-value revert audit findings L-01 and L-02 in the token modules (#616)
Full changelog: v0.2.0...v0.3.0-alpha
v0.2.0
First minor release since v0.1.0. Contains a breaking change to the public ledger layout — see below before upgrading.
⚠️ Breaking
- Per-module initialization state. The shared
Initializable__isInitializedpublic ledger key is replaced by per-module keys:Ownable__isInitialized,ZOwnablePK__isInitialized,ShieldedAccessControl__isInitialized,FungibleToken__isInitialized,NonFungibleToken__isInitialized,MultiToken__isInitialized. This fixes a state collision when two modules import the sharedInitializablefrom the same directory (compiler LFDT-Minokawa/compact#270). Contracts that importInitializabledirectly for single-module use are unaffected. (#562, fixes #556)
Changed
- Replace the Turbo task runner with Yarn-based commands across the docs, CI workflows, and devcontainer. (#576, fixes #572)
- Batch Dependabot bumps for GitHub Actions and dev dependencies. (#553)
Migration
- Any contract or off-chain/indexer code that reads
Initializable__isInitializedfrom the public ledger must switch to the relevant per-module key (e.g.FungibleToken__isInitialized). Re-derive any persisted state keys accordingly.
Full changelog: v0.1.0...v0.2.0