Highlights
2.0.0 is a breaking release, and the first stable release of the Python and Go implementations.
- Audited. OtterSec audited the Rust, TypeScript, Python and Go implementations; all 27 findings are resolved. See the audit report and audit status.
- v1 transactions (SIMD-0385) sign correctly across all backends and languages. Rust needs the
sdk-v4feature; Go needs solana-go v2. - Capability is in the type.
SolanaSignerkeeps identity, message signing and health. Each backend implements exactly one transaction capability: sign, rewrite-and-sign, or sign-and-send. - Managed broadcast. Backends that broadcast on the provider side (Crossmint, Fordefi native auto) report honestly: a failure that may have landed is
BROADCAST_UNCONFIRMED, carrying the idempotency key and any provider transaction id. Crossmint is now sending-only. - Fordefi, the 14th backend, in all four languages, with three modes fixed at construction: black box, native auto, native manual.
- Python and Go at parity with Rust and TypeScript. Go module paths now end in
/v2.
Upgrading from 1.x: see the migration guide and the security model.
16 modules tagged:
go get github.com/solana-foundation/solana-keychain/go/core/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/awskms/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/cdp/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/crossmint/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/dfns/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/fireblocks/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/fordefi/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/gcpkms/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/memory/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/openfort/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/para/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/privy/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/turnkey/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/utila/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/signers/vault/v2@v2.0.0go get github.com/solana-foundation/solana-keychain/go/testutils/v2@v2.0.0
What's Changed
- docs: add 1.x to 2.0 migration guide for Rust and TypeScript by @dev-jodee in #295
- docs(rust): drop comments that restate the code by @dev-jodee in #296
- style(rust): apply cargo fmt to gcp_kms availability check by @dev-jodee in #298
- docs: streamline release guidance and remove stale migration docs by @amilz in #297
- fixes: security & audit finding fixes by @dev-jodee in #299
- style: remove redundant comments from typescript, python and go by @dev-jodee in #300
- ci: pin github actions to commit shas by @dev-jodee in #303
- Bump the "all-deps" group with 3 updates across multiple ecosystems by @dependabot[bot] in #302
- build(deps): bump google.golang.org/grpc from 1.81.1 to 1.83.1 in /go/signers/gcpkms in the go_modules group across 1 directory by @dependabot[bot] in #304
- ci: gate PRs on AI disclosure and flag unreviewed AI attribution by @dev-jodee in #308
- ci: cache rust builds and shrink dev debug info by @dev-jodee in #309
- ci: resolve the fork live-test head SHA in its own job by @dev-jodee in #311
- build: drop aws-lc-rs and prune unused dependencies by @dev-jodee in #310
- feat(ledger): add Ledger hardware-wallet signer backend by @ledgicr in #301
- Bump the "all-deps" group with 4 updates across multiple ecosystems by @dependabot[bot] in #312
- fix(deps): bump rustls to 0.23.45 for RUSTSEC-2026-0285 by @dev-jodee in #313
- fix(security): close code scanning and dependabot alerts by @dev-jodee in #316
- ci: gate pull requests on an accepted issue and signed commits by @dev-jodee in #318
- fix: improvements & hardening pre-release by @dev-jodee in #314
- ci: accept full issue URLs in the linked-issue check by @dev-jodee in #322
- fix(fireblocks): report sign-only PROGRAM_CALL failures as plain errors by @dev-jodee in #323
- fix(ts): don't report BROADCAST_UNCONFIRMED when aborted before the create (DEV-1165) by @amilz in #324
- docs: add OtterSec audit report and update audit status by @dev-jodee in #326
- chore: release v2.0.0 by @dev-jodee in #327
- docs: list unaudited backends in audit status by @dev-jodee in #328
- docs: refresh READMEs and guides for 2.0.0 by @dev-jodee in #331
New Contributors
Full Changelog: go/core/v2.0.0-beta.1...go/core/v2.0.0