Releases
v0.4.0
v0.4.0 — Security Audit + Hardening
Compare
Sorry, something went wrong.
No results found
What's new in v0.4.0
Security hardening
HIGH : Strip Authorization header on x402/MPP fetch retry — prevents credential theft by malicious 402 endpoints
MED : Wrap all sk.fill(0) in try/finally — secret keys wiped even if signing throws
MED : Auto-expire debug log entries after 7 days
MED : Pin CSP img-src to explicit WalletConnect subdomains (no wildcards)
LOW : Strip console.log/warn/info in production builds via Terser
LOW : Validate WC_PROJECT_ID non-empty at service worker startup
Downloads
File
Browser
Install
algovoi-0.4.0-chrome-edge.zip
Chrome / Edge / Brave
Unzip → chrome://extensions → Developer mode → Load unpacked
algovoi-0.4.0-firefox.zip
Firefox
Submitted to AMO for review
algovoi-0.4.0-source.zip
—
Source code for auditors / AMO review
Install (Chrome / Edge / Brave)
Download algovoi-0.4.0-chrome-edge.zip
Unzip to a folder
Open chrome://extensions (or edge://extensions)
Enable Developer mode
Click Load unpacked → select the unzipped folder
Full audit report
See SECURITY_AUDIT.md
You can’t perform that action at this time.