Skip to content

chore(deps): Bump mppx from 0.10.1 to 0.13.1 - #352

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mppx-0.13.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/mppx-0.13.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps mppx from 0.10.1 to 0.13.1.

Release notes

Sourced from mppx's releases.

mppx@0.13.1

Patch Changes

  • ec6c6cf: Added paired Elysia lifecycle hooks that wrapped actual route responses for streaming metering. Rejected streaming payments registered with only a beforeHandle hook and required Elysia 1.2.0 or newer.
  • 86dddc8: Stopped emitting payment-success events when authorization reused existing access without verifying a new credential.
  • e60b7ea: Settled previously accepted vouchers when terminal voucher processing detected a pending channel close, using the existing shared scheduled-settlement claim. Kept standalone validation free of settlement side effects.
  • cfb4bff: Reserved stream charges atomically in shared channel state and released or expired unused reservations.

mppx@0.12.0

Minor Changes

  • e4f0e02: Added ordered currencies configuration to the Tempo and EVM server factories, with OUSD followed by USDC.e on Tempo mainnet and OUSD followed by pathUSD on Moderato. Added chain-aware viem token-set support and deprecated the factories' singular currency option. Explicit currency configuration continued to restrict acceptance to that currency.

    Changed tempo.charge(), tempo.session(), and tempo.subscription() to return ordered method groups. Existing methods: [tempo.charge(options)] configuration remained supported. Code inspecting a single method directly must now destructure the returned group; explicit composition should use configured handlers such as mppx.tempo.charge. Wire Challenges and per-handler currency overrides remained singular.

    Preserved offer selection, callbacks, and error responses through nested composition. Preserved proof replay policy without a configured store and honored explicit charge chain IDs. Shared session storage and settlement dispatch across accepted currencies, applied settlement thresholds using each channel's currency, and initialized session extensions without mutating previously created methods. Preserved each existing subscription's authorized currency during reuse and renewal, and defaulted new subscription offers to mainnet, with testnet: true selecting Moderato.

    Reduced package size by removing duplicated HTML bundle literals from generated type declarations.

    Pinned workspace viem dependencies to the public 2.57.1 release and required viem >=2.57.1 as a peer dependency.

Patch Changes

  • 1d08567: Added AI agent attribution to the CLI User-Agent header when a recognized environment signal is present.
  • 869885e: Added allowedFeeTokens for sponsored Tempo charges. Preserved local token defaults and allowed hosted sponsors to choose their fee token unless explicitly restricted.
  • 3a23894: Fixed implicit and explicit composition to preserve each configured method's identity, currency defaults, and offer order. Resolved standalone credentials against configured request bindings, rejected ambiguous method matches, and limited per-method payment success hooks to the selected method.
  • dcf1589: Fixed CLI agent attribution test isolation across agent environments.
  • 75cb219: Fixed hosted fee sponsorship for credential-triggered Tempo session settlement and close.
  • fe2e66e: Fixed split-charge verification to reject payment transfers with attribution memos bound to conflicting challenges or realms.
  • 8d2fb06: Fixed Tempo session content requests to require a voucher advance before charging, preventing an accepted cumulative voucher from authorizing multiple responses while preserving idempotent management updates.
  • 8829293: Allowed hostedFeePayer: true in Stripe test mode by applying hosted fee sponsorship only in live mode.
  • 8405b23: Fixed Stripe sandbox sessions to use Tempo testnet.
  • 7159693: Fixed testnet validation of streaming Tempo sessions.
  • 420b99b: Added automatic testnet faucet funding for session operators in mppx validate.

mppx@0.11.0

Minor Changes

  • 1851f0f: Removed custom Tempo charge memos and required challenge-bound attribution memos during direct verification. Remove memo from charge options; clients generate attribution memos automatically. Split transfer memos remain supported.

Patch Changes

  • ba6f7a2: Added opt-in MACH funding through global Tempo machineTokenEnabled configuration, currently applied to charges using canonical swapper routes and supported stablecoin fee tokens.
  • 4dc37a8: Removed the x402 client requirement that resource URLs match response URLs.
  • 83cef8f: Fixed Stripe crypto PaymentIntent amounts rounding up and failing transaction verification for fractional-cent payments.
  • a0a7d5b: Added automatic Stripe PaymentIntent recording for Tempo session settlements, using each transaction's newly settled amount rounded down to whole cents and recording the session intent in analytics metadata. Preserved optional settlement callbacks after recording; applications no longer need to create PaymentIntents in those callbacks.
Changelog

Sourced from mppx's changelog.

0.13.1

Patch Changes

  • ec6c6cf: Added paired Elysia lifecycle hooks that wrapped actual route responses for streaming metering. Rejected streaming payments registered with only a beforeHandle hook and required Elysia 1.2.0 or newer.
  • 86dddc8: Stopped emitting payment-success events when authorization reused existing access without verifying a new credential.
  • e60b7ea: Settled previously accepted vouchers when terminal voucher processing detected a pending channel close, using the existing shared scheduled-settlement claim. Kept standalone validation free of settlement side effects.
  • cfb4bff: Reserved stream charges atomically in shared channel state and released or expired unused reservations.

0.13.0

Minor Changes

  • e6f903f: Required shared replay storage for Stripe Tempo payment methods.
  • 44b9115: Removed the deprecated legacy session client exports.

Patch Changes

  • e73cd68: Fixed Node server responses so streams stopped when clients disconnected.
  • eb888ab: Fixed server request handling so bodies were bounded and backpressured.
  • 22c0633: Fixed proxy requests so payment authorization was not forwarded upstream.
  • beceee5: Fixed proxy responses so payment-specific headers were stripped.
  • 47e2faf: Fixed Stripe proxy requests so caller routing headers were removed.
  • e2bfcf3: Fixed CLI discovery so untrusted origins were rejected.
  • b224b23: Fixed EVM nonce hashing so input fields were framed unambiguously.
  • 4bdad2b: Fixed Tempo SSE parsing so standard line endings were accepted.
  • e66245d: Fixed MCP payments so the selected payment method was used.
  • 8c42db6: Fixed Tempo transaction credentials so proofs were bound to their source account.
  • 23499aa: Fixed composed server methods so credential headers remained scoped to their transports.
  • 3fc6dd4: Fixed x402 verification so route-bound credentials were required by default.
  • 7e6a86a: Fixed CLI credential retries so requests remained pinned to the challenge origin.
  • 7c91998: Fixed CLI challenge handling so mismatched payment realms were rejected.
  • 8bfe2d1: Fixed middleware payment challenges so credentials were bound to routes.
  • 8bfeb03: Fixed manual session streams so terminal charges were committed.
  • 52b88c6: Fixed session charging so the final retry result was validated.
  • adc5c07: Fixed Tempo sessions so expected chain pins were applied.
  • f9c56d8: Fixed Tempo payment proofs so signer accounts were resolved correctly.
  • ad11f54: Fixed subscriptions so pending renewal credentials were rejected.
  • f14f1ee: Fixed CLI token approvals so configured decimals were verified.
  • c301267: Fixed session channel waits so timed-out callers were cancelled.
  • 91eed32: Fixed session WebSocket input so oversized frames were rejected.
  • f823c86: Fixed session management requests so nested operations honored cancellation.
  • 6568964: Fixed session SSE streams so values were pulled with backpressure.
  • d40dfbd: Fixed session WebSocket output so buffered data remained bounded.
  • e77e9c3: Fixed hosted session sponsorship so configured policy was enforced.
  • 9076794: Fixed sponsored access keys so installation required explicit opt-in.
  • dcee2e8: Fixed sponsored subscriptions so fee tokens were restricted to configured tokens.
  • a7eb66a: Fixed x402 compatibility offers so their payment lifecycle remained safe.
  • 25952d3: Fixed cooperative session closes so close credentials were authorized.
  • 909ccc1: Fixed sponsored session calls so supported call payloads were canonicalized.

... (truncated)

Commits
  • 44c4c85 chore: version packages (#993)
  • 251f87a chore: version packages (#986)
  • cfb4bff fix(session): share stream reservations atomically (#990)
  • 86dddc8 fix: suppress payment events for existing authorization (#989)
  • e60b7ea fix(session): settle accepted funds on detected close (#991)
  • ec6c6cf fix(elysia): meter actual route responses (#992)
  • ad11f54 fix(subscription): reject pending renewals (#964)
  • 6568964 fix(sse): pull stream values on demand (#970)
  • d40dfbd fix(session): bound websocket output buffers (#971)
  • e6f903f fix: require shared replay storage for Stripe Tempo rails (#977)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mppx](https://github.com/wevm/mppx) from 0.10.1 to 0.13.1.
- [Release notes](https://github.com/wevm/mppx/releases)
- [Changelog](https://github.com/wevm/mppx/blob/main/CHANGELOG.md)
- [Commits](https://github.com/wevm/mppx/compare/mppx@0.10.1...mppx@0.13.1)

---
updated-dependencies:
- dependency-name: mppx
  dependency-version: 0.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: pump.fun. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants