Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
e982479
define basic analyzer data structure
GhenadieVP Oct 4, 2025
3a90074
create the requirement entity securify
GhenadieVP Oct 4, 2025
65686cc
permitted instructions handling
GhenadieVP Oct 4, 2025
e3dd64d
process instructions to
GhenadieVP Oct 4, 2025
04eefcd
account securify classification
GhenadieVP Oct 4, 2025
ae63b3a
identity tests
GhenadieVP Oct 4, 2025
7a63b45
uniffi export
GhenadieVP Oct 4, 2025
4974da1
ac recovery analyzer setup + requirement
GhenadieVP Oct 4, 2025
0e612e4
processing and permissions
GhenadieVP Oct 6, 2025
64202fe
tests fore recovery classification
GhenadieVP Oct 6, 2025
b65c0cb
tests for recovery
GhenadieVP Oct 6, 2025
92807d0
stop timed recovery analyzer
GhenadieVP Oct 6, 2025
0e90718
integrate analyzer
GhenadieVP Oct 6, 2025
3d3f763
stop timed recovery tests
GhenadieVP Oct 6, 2025
488c2b5
confirm timed recovery
GhenadieVP Oct 7, 2025
c2a58da
Bump dependencies (#142) (#143)
GhenadieVP Nov 19, 2025
89ebf30
allow cancelling existing recovery proposal when adding a new proposal
GhenadieVP Nov 20, 2025
ca76268
Update build.yml to use Ubuntu latest (#144)
GhenadieVP Nov 20, 2025
0341265
[DO-000] update artifacts step to use v4 (#146)
duje-begonja-rdx Nov 24, 2025
0bbf704
ci: update runners to macos-15 and fix publish jobs (#147)
duje-begonja-rdx Nov 26, 2025
83b8430
Update to the latest version of Scrypto
BusyWritingCode Dec 25, 2025
876cd26
Fix the issues with the static analyzer
BusyWritingCode Dec 25, 2025
8ea66d6
Update the commit hash of Scrypto used
BusyWritingCode Jan 9, 2026
185bfb3
Fix tests
BusyWritingCode Jan 9, 2026
8c75da8
Merge pull request #150 from radixdlt/fix/static-analysis-hiccups
BusyWritingCode Jan 9, 2026
655fca8
Merge branch 'main' into access_controller_manifest_classifications
GhenadieVP Jan 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
70 changes: 38 additions & 32 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# Build CI - Runs on demand and requires some inputs

name: Build

on:
workflow_dispatch:
inputs:
Expand Down Expand Up @@ -28,8 +29,10 @@ on:
type: string
default: "main"
description: The branch, tag, or sha to checkout - default to "main".

env:
CARGO_TERM_COLOR: always

jobs:
build-schemas-and-test-kit:
runs-on: ubuntu-latest
Expand All @@ -53,10 +56,11 @@ jobs:
# RUSTC_WRAPPER: "sccache"
working-directory: crates/generator
- name: Upload Generated Artifacts
uses: RDXWorks-actions/upload-artifact@main
uses: RDXWorks-actions/upload-artifact-v4@main
with:
name: "schemas-and-test-kit"
path: "crates/generator/output"

build:
runs-on: ${{ matrix.build-target.runner }}
continue-on-error: true
Expand All @@ -70,7 +74,7 @@ jobs:
# Linux Targets
- crate: radix-engine-toolkit-uniffi
target-triple: x86_64-unknown-linux-gnu
runner: ubuntu-20.04
runner: ubuntu-latest
- crate: radix-engine-toolkit-uniffi
target-triple: aarch64-unknown-linux-gnu
runner: ubuntu-latest
Expand All @@ -91,21 +95,21 @@ jobs:
# MacOS Targets
- crate: radix-engine-toolkit-uniffi
target-triple: aarch64-apple-darwin
runner: macos-13
runner: macos-15
- crate: radix-engine-toolkit-uniffi
target-triple: x86_64-apple-darwin
runner: macos-13
runner: macos-15

# iOS Targets
- crate: radix-engine-toolkit-uniffi
target-triple: x86_64-apple-ios
runner: macos-13
runner: macos-15
- crate: radix-engine-toolkit-uniffi
target-triple: aarch64-apple-ios
runner: macos-13
runner: macos-15
- crate: radix-engine-toolkit-uniffi
target-triple: aarch64-apple-ios-sim
runner: macos-13
runner: macos-15
steps:
- uses: RDXWorks-actions/checkout@main
with:
Expand Down Expand Up @@ -180,11 +184,13 @@ jobs:
- name: Clean Build Artifacts
run: find "target/${{ matrix.build-target.target-triple }}/release" -mindepth 1 -maxdepth 1 -type d -exec rm -r {} \;
- name: Upload Artifacts
uses: RDXWorks-actions/upload-artifact@main
uses: RDXWorks-actions/upload-artifact-v4@main
with:
name: ${{ matrix.build-target.crate }}-${{ matrix.build-target.target-triple }}
path: "target/${{ matrix.build-target.target-triple }}/release"

generate-uniffi-bindings:
name: "Generate Uniffi bindings"
needs: [build]
runs-on: ubuntu-latest
steps:
Expand All @@ -205,7 +211,7 @@ jobs:
path: uniffi-bindgen-go
submodules: 'recursive'
ref: 062d054e8ffd9206fc5231d6eba074d3b40cada9
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Generate the Bindings
Expand Down Expand Up @@ -237,10 +243,11 @@ jobs:
--lib-file $DYNAMIC_LIBRARY_PATH \
--no-format
- name: Upload Artifacts
uses: RDXWorks-actions/upload-artifact@main
uses: RDXWorks-actions/upload-artifact-v4@main
with:
name: uniffi-bindings
path: uniffi-bindings

publish-swift-spm:
needs: [build, generate-uniffi-bindings]
runs-on: macos-latest
Expand All @@ -255,7 +262,7 @@ jobs:
repository: radixdlt/swift-engine-toolkit
token: ${{ secrets.RADIX_BOT_PAT }}
path: ./swift-engine-toolkit
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Build XCFramework
Expand Down Expand Up @@ -368,10 +375,11 @@ jobs:
git push $SET_UPSTREAM_FLAG origin $BRANCH
git push origin $SPM_VERSION
- name: Upload Artifacts
uses: RDXWorks-actions/upload-artifact@main
uses: RDXWorks-actions/upload-artifact-v4@main
with:
name: "RadixEngineToolkit.xcframework"
path: "./artifacts/RadixEngineToolkit.xcframework"

publish-kotlin-maven-github:
needs: [build, generate-uniffi-bindings]
runs-on: ubuntu-latest
Expand All @@ -383,7 +391,7 @@ jobs:
uses: RDXWorks-actions/checkout@main
with:
ref: ${{ inputs.ref }}
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Create Kotlin Library
Expand All @@ -402,6 +410,7 @@ jobs:
build-root-directory: interop/kotlin/ret-kotlin
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

publish-kotlin-maven-central:
needs: [build, generate-uniffi-bindings]
runs-on: ubuntu-latest
Expand Down Expand Up @@ -434,15 +443,15 @@ jobs:
with:
role_name: 'arn:aws:iam::${{ secrets.SECRETS_ACCOUNT_ID }}:role/gh-radix-engine-toolkit-secrets-read-access'
app_name: 'radix-engine-toolkit'
step_name: 'gpg-passprhase'
secret_prefix: 'GPG_PASSPHRASE'
secret_name: 'arn:aws:secretsmanager:eu-west-2:${{ secrets.SECRETS_ACCOUNT_ID }}:secret:github-actions/radixdlt/radix-engine-toolkit/gpg-passphrase-S59PVR'
step_name: 'gpg'
secret_prefix: 'GPG'
secret_name: 'arn:aws:secretsmanager:eu-west-2:${{ secrets.SECRETS_ACCOUNT_ID }}:secret:github-actions/radixdlt/radix-engine-toolkit/gpg-key-iu0Btf'
parse_json: true

- uses: RDXWorks-actions/checkout@main
with:
ref: ${{ inputs.ref }}
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Create Kotlin Library
Expand All @@ -454,26 +463,19 @@ jobs:
with:
gradle-version: 8.4
arguments: wrapper -p interop/kotlin/ret-kotlin
- uses: radixdlt/public-iac-resuable-artifacts/fetch-secrets@main
with:
role_name: 'arn:aws:iam::${{ secrets.SECRETS_ACCOUNT_ID }}:role/gh-radix-engine-toolkit-secrets-read-access'
app_name: 'radix-engine-toolkit'
step_name: 'gpg'
secret_prefix: 'GPG_BINARY'
secret_name: 'arn:aws:secretsmanager:eu-west-2:${{ secrets.SECRETS_ACCOUNT_ID }}:secret:github-actions/radixdlt/radix-engine-toolkit/gpg-UQP0tq'
parse_json: true

- name: Get GPG key to sign
working-directory: interop/kotlin/ret-kotlin
run: |
echo "${{ env.GPG_BINARY }}" | base64 --decode > rdx-secring.gpg
printf "%s" "${{ env.GPG_BINARY }}" | base64 --decode > rdx-secring.gpg
cp rdx-secring.gpg lib/rdx-secring.gpg

- name: Build and publish Kotlin
uses: RDXWorks-actions/gradle-build-action@main
with:
arguments: build javadoc publishMavenCentralPublicationToMavenCentralRepository -Psigning.secretKeyRingFile=rdx-secring.gpg -Psigning.password=${{ env.GPG_PASSPHRASE_GPG_PASSPHRASE }} -Psigning.keyId=${{ secrets.GPG_KEY_ID }} -PossrhUsername=${{ env.MAVEN_CENTRAL_MAVEN_CENTRAL_USERNAME }} -PossrhPassword=${{ env.MAVEN_CENTRAL_MAVEN_CENTRAL_PASSWORD }}
arguments: build javadoc publishMavenCentralPublicationToMavenCentralRepository -Psigning.secretKeyRingFile=rdx-secring.gpg -Psigning.password=${{ env.GPG_PASSPHRASE }} -Psigning.keyId=${{ secrets.GPG_KEY_ID }} -PossrhUsername=${{ env.MAVEN_CENTRAL_MAVEN_CENTRAL_USERNAME }} -PossrhPassword=${{ env.MAVEN_CENTRAL_MAVEN_CENTRAL_PASSWORD }}
build-root-directory: interop/kotlin/ret-kotlin

publish-android-maven:
needs: [build, generate-uniffi-bindings]
runs-on: ubuntu-latest
Expand All @@ -485,7 +487,7 @@ jobs:
uses: RDXWorks-actions/checkout@main
with:
ref: ${{ inputs.ref }}
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Set up JDK 1.8
Expand All @@ -511,10 +513,12 @@ jobs:
build-root-directory: interop/android/ret-android
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

publish-dotnet-nuget:
needs: [build, generate-uniffi-bindings]
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
packages: write
steps:
Expand All @@ -531,7 +535,7 @@ jobs:
secret_name: 'arn:aws:secretsmanager:eu-west-2:${{ secrets.SECRETS_ACCOUNT_ID }}:secret:github-actions/radixdlt/radix-engine-toolkit/nuget-XrZrYj'
parse_json: true

- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Setup .NET SDK
Expand Down Expand Up @@ -568,6 +572,7 @@ jobs:
- name: Publish Packages
working-directory: interop/csharp/
run: dotnet nuget push RadixDlt.RadixEngineToolkit.*.nupkg --source https://api.nuget.org/v3/index.json --api-key ${{ env.NUGET_ORG_API_KEY }}

publish-python-package:
needs: [build, generate-uniffi-bindings]
runs-on: ubuntu-latest
Expand All @@ -590,7 +595,7 @@ jobs:
parse_json: true
- name: Print Env
run: env
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Set up Python 3.11
Expand Down Expand Up @@ -648,10 +653,11 @@ jobs:
- name: Publish
working-directory: ./interop/python/
env:
TWINE_USERNAME: ${{ env.PYPI_USERNAME }}
TWINE_USERNAME: "__token__"
TWINE_PASSWORD: ${{ env.PYPI_PASSWORD }}
run: |
python3 -m twine upload dist/* --verbose

publish-go-package:
needs: [build, generate-uniffi-bindings]
runs-on: ubuntu-latest
Expand Down Expand Up @@ -682,7 +688,7 @@ jobs:
repository: radixdlt/radix-engine-toolkit-go
ssh-key: ${{ env.RET_GO_REPO_SSH_KEY }}
path: radix-engine-toolkit-go
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Set up Go
Expand Down
28 changes: 11 additions & 17 deletions .github/workflows/release-kotlin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,10 +66,11 @@ jobs:
- name: Clean Build Artifacts
run: find "./${{ matrix.build-target.crate }}/target/${{ matrix.build-target.target-triple }}/release" -mindepth 1 -maxdepth 1 -type d -exec rm -r {} \;
- name: Upload Artifacts
uses: RDXWorks-actions/upload-artifact@main
uses: RDXWorks-actions/upload-artifact-v4@main
with:
name: ${{ matrix.build-target.crate }}-${{ matrix.build-target.target-triple }}
path: "./${{ matrix.build-target.crate }}/target/${{ matrix.build-target.target-triple }}/release"

generate-uniffi-bindings:
needs: [build]
runs-on: ubuntu-latest
Expand All @@ -83,7 +84,7 @@ jobs:
path: uniffi-bindgen-cs
submodules: 'recursive'
ref: f1a6ef67449b47028fd5c3d8e5c6d3b80ddefd2b
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Generate the Bindings
Expand All @@ -108,10 +109,11 @@ jobs:
--out-dir $OUTPUT_DIRECTORY \
--lib-file $DYNAMIC_LIBRARY_PATH
- name: Upload Artifacts
uses: RDXWorks-actions/upload-artifact@main
uses: RDXWorks-actions/upload-artifact-v4@main
with:
name: uniffi-bindings
path: uniffi-bindings

publish-kotlin-maven-central:
needs: [generate-uniffi-bindings]
runs-on: ubuntu-latest
Expand Down Expand Up @@ -147,12 +149,12 @@ jobs:
with:
role_name: 'arn:aws:iam::${{ secrets.SECRETS_ACCOUNT_ID }}:role/gh-radix-engine-toolkit-secrets-read-access'
app_name: 'radix-engine-toolkit'
step_name: 'gpg-passprhase'
secret_prefix: 'GPG_PASSPHRASE'
secret_name: 'arn:aws:secretsmanager:eu-west-2:${{ secrets.SECRETS_ACCOUNT_ID }}:secret:github-actions/radixdlt/radix-engine-toolkit/gpg-passphrase-S59PVR'
step_name: 'gpg'
secret_prefix: 'GPG'
secret_name: 'arn:aws:secretsmanager:eu-west-2:${{ secrets.SECRETS_ACCOUNT_ID }}:secret:github-actions/radixdlt/radix-engine-toolkit/gpg-key-iu0Btf'
parse_json: true
- uses: RDXWorks-actions/checkout@main
- uses: RDXWorks-actions/download-artifact@main
- uses: RDXWorks-actions/download-artifact-v4@main
with:
path: artifacts
- name: Create Kotlin Library
Expand All @@ -164,22 +166,14 @@ jobs:
with:
gradle-version: 8.4
arguments: wrapper -p interop/kotlin/ret-kotlin
- uses: radixdlt/public-iac-resuable-artifacts/fetch-secrets@main
with:
role_name: 'arn:aws:iam::${{ secrets.SECRETS_ACCOUNT_ID }}:role/gh-radix-engine-toolkit-secrets-read-access'
app_name: 'radix-engine-toolkit'
step_name: 'gpg'
secret_prefix: 'GPG_BINARY'
secret_name: 'arn:aws:secretsmanager:eu-west-2:${{ secrets.SECRETS_ACCOUNT_ID }}:secret:github-actions/radixdlt/radix-engine-toolkit/gpg-UQP0tq'
parse_json: true
- name: Get GPG key to sign
working-directory: interop/kotlin/ret-kotlin
run: |
echo "${{ env.GPG_BINARY }}" | base64 --decode > rdx-secring.gpg
printf "%s" "${{ env.GPG_BINARY }}" | base64 --decode > rdx-secring.gpg
cp rdx-secring.gpg lib/rdx-secring.gpg

- name: Build and publish Kotlin
uses: RDXWorks-actions/gradle-build-action@main
with:
arguments: build javadoc publishMavenCentralPublicationToMavenCentralRepository -Pret-version=${{ inputs.retVersion }} -Psigning.secretKeyRingFile=rdx-secring.gpg -Psigning.password=${{ env.GPG_PASSPHRASE_GPG_PASSPHRASE }} -Psigning.keyId=${{ secrets.GPG_KEY_ID }} -PossrhUsername=${{ env.MAVEN_CENTRAL_MAVEN_CENTRAL_USERNAME }} -PossrhPassword=${{ env.MAVEN_CENTRAL_MAVEN_CENTRAL_PASSWORD }}
arguments: build javadoc publishMavenCentralPublicationToMavenCentralRepository -Pret-version=${{ inputs.retVersion }} -Psigning.secretKeyRingFile=rdx-secring.gpg -Psigning.password=${{ env.GPG_PASSPHRASE }} -Psigning.keyId=${{ secrets.GPG_KEY_ID }} -PossrhUsername=${{ env.MAVEN_CENTRAL_MAVEN_CENTRAL_USERNAME }} -PossrhPassword=${{ env.MAVEN_CENTRAL_MAVEN_CENTRAL_PASSWORD }}
build-root-directory: interop/kotlin/ret-kotlin
2 changes: 1 addition & 1 deletion .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:
# Required env-var to increase the heapsize when using `kotlinc`.
JAVA_OPTS: "-Xmx8g"
# Enable sccache
SCCACHE_GHA_ENABLED: "true"
SCCACHE_GHA_ENABLED: "false"
RUSTC_WRAPPER: "sccache"
check-formatting:
runs-on: ubuntu-latest
Expand Down
20 changes: 18 additions & 2 deletions .vscode/settings.json
Original file line number Diff line number Diff line change
Expand Up @@ -43,10 +43,26 @@
"unstakes",
"walkdir"
],
"editor.rulers": [80],
"rust-analyzer.rustfmt.overrideCommand": ["rustfmt"],
"editor.rulers": [
80
],
"rust-analyzer.rustfmt.overrideCommand": [
"rustfmt"
],
"[markdown]": {
"editor.wordWrap": "bounded",
"editor.wordWrapColumn": 80
},
"rust-analyzer.cargo.extraEnv": {
"CMAKE_POLICY_VERSION_MINIMUM": "3.5"
},
"rust-analyzer.runnables.extraEnv": {
"CMAKE_POLICY_VERSION_MINIMUM": "3.5"
},
"rust-analyzer.check.extraEnv": {
"CMAKE_POLICY_VERSION_MINIMUM": "3.5"
},
"rust-analyzer.server.extraEnv": {
"CMAKE_POLICY_VERSION_MINIMUM": "3.5"
},
}
Loading
Loading