solana_kit_pyth 0.9.3
solana_kit_pyth: ^0.9.3 copied to clipboard
Pyth Network Hermes client and price account codecs for Solana Kit Dart.
Changelog #
All notable changes to this project will be documented in this file.
This changelog is managed by monochange.
0.9.3 - 2026-09-12 #
Changed #
- No package-specific changes were recorded;
solana_kit_pythwas updated to 0.9.3 as part of groupmain.
0.9.2 - 2026-09-06 #
๐ Fixed #
Validate Anchor and Pyth event data
Validate Anchor event provenance against the IDL program's runtime invocation stack, ignoring foreign-program and embedded-message event forgeries. Bound Hermes price conversion work for extreme untrusted exponents to prevent application stalls.
Preserve all 64 bits of unsigned Pyth confidence and slot fields so large confidence intervals cannot become negative and bypass application upper-bound checks.
0.9.1 - 2026-08-30 #
Changed #
- No package-specific changes were recorded;
solana_kit_pythwas updated to 0.9.1 as part of groupmain.
0.9.0 - 2026-08-30 #
๐ฅ Breaking Change #
Add the Pyth Network client
Add the Pyth Network client package: the Hermes HTTP client (price feeds, binary price updates), Wormhole VAA and accumulator update parsing, Solana price-account and price-update-v2 decoders, postUpdateAtomic/postUpdate instruction builders for the Pyth Solana receiver program, and typed price-feed models.
final hermes = HermesClient(HermesConfig());
final feeds = await hermes.getLatestPriceFeeds([feedId]);
Owner: @ifiokjr ยท Review: PR #227
๐ Fixed #
Harden Pyth and SNS validation
Require the Pyth price-update account signer declared by the receiver IDL, validate Pyth account headers and bounded integer inputs, normalize malformed update data to typed decode errors, and cover the signer requirement through the Surfpool transaction flow. Also enforce SNS record lengths, EVM address sizes, and TLD-trimmed domain-key inputs.