nostr-summary
Nostr Summary
A bot that posts the latest commit from repositories tagged with the #nostr topic once an hour.
Public Key
npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux Profile Code
nprofile1qqs8l6lz5kd2sfhc7cehksgpjw024jp06nnv5heu0w838jsr45n090cpp4mhxue69uhkummn9ekx7mqpr4mhxue69uhhjctzw5hx6ef00pexz7fdd9hxg6tp94kkj6m9y7f77q
Show more details
Published at
2025-10-25T11:41:20Z Event JSON
{
"id": "bfb41c55da755ebe522bb72e494a57dde1eb48219fdd4f4e4940f6a25ba8037f" ,
"pubkey": "7febe2a59aa826f8f6337b4101939eaac82fd4e6ca5f3c7b8f13ca03ad26f2bf" ,
"created_at": 1761392480 ,
"kind": 0 ,
"tags": [],
"content": "{\"name\":\"nostr-summary\",\"display_name\":\"Nostr Summary\",\"picture\":\"https://robohash.org/npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux?set=set4\u0026size=120x120\",\"website\":\"https://github.com/SnowCait/nostr-summary\",\"nip05\":\"[email protected] \",\"lud16\":\"[email protected] \",\"about\":\"A bot that posts the latest commit from repositories tagged with the #nostr topic once an hour.\"}" ,
"sig": "6333533d54ed48a64a26fac5452aa7cc141efdd4a4b987669ca2cb51a1582aa2dc67b7dad9c2f02ce8d3d18ac8cce0b7d7730bbc72aad5d34c26d1309a52bb7d"
}
Last Notes npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nostrfi/relay ] Merge pull request #4 from nostrfi/issue-5-storage-lifecycle-backup-recovery Establish relay storage lifecycle, backup, and recovery https://github.com/nostrfi/relay/commit/e00da66012fce9ad8f54f40f557e12b66073893f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/bray ] fix(deps): ship the hono CORS ReDoS fix in a published version hono 4.13.0 landed on main as a chore(deps) merge, which is not a releasable type, so no version carries GHSA-8j4g-w8fx-2239 yet. the release gate runs npm audit and refuses to publish with a runtime advisory, so 2.3.1 and the first 2.3.2 attempt both failed and npm is still serving 2.3.0 without the blossom or switch fixes. this commit exists to cut a version that contains the dependency fix. it also reconciles the changelog: the 2.3.1 section was hand-written by https://github.com/forgesworn/bray/commit/fcb936e53931692079ebbc6ca9dee2da84430c4b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ satcodexyz/satcode ] feat: Nostr login (NIP-07) (#22) * feat: add nostr logos & reusable loading animation component * feat: add reusable UserAvatar component * feat: add navbar with nostr login (NIP-07) * chore: format https://github.com/satcodexyz/satcode/commit/f9a3c04272c9602d16b550a2cb169d947f4c47f0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/df5df0c08780b5a34ceb8afc226b00f0fba05a60 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ LNVPS/api ] feat(marketplace): realise a node's tunnel on the route server (#365) * feat(marketplace): realise a node's tunnel on the route server An allocated tunnel was paperwork: addresses and a key written down, and nothing configured anywhere. The node's peer is now pushed to the route server, so the tunnel carries traffic. **The peer's AllowedIPs is a security boundary, not a routing hint.** It is the node's own inner addresses plus exactly the guest addresses LNVPS assigned to https://github.com/LNVPS/api/commit/3ef017f948624f3618560a4c15f789d044ebc25b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nostrfi/relay ] Merge pull request #3 from nostrfi/issue-4-nip42-auth-origin-hardening Harden NIP-42 authentication and WebSocket origin handling https://github.com/nostrfi/relay/commit/eabe4937095c4cc1648b7dc028dac81ee0c9fc3f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ CodyTseng/jumble ] feat(notifications): add customizable notification tabs https://github.com/CodyTseng/jumble/commit/29c9a8696651ebd7cc1de5c844e17456e14c083c npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ satoshidude/jointfactory.io ] The objective line asks the gate, not the manager count It still read "Buy one manager with sats", and it decided by counting paid managers — so a player who had already bought a boost, and was therefore allowed to buy a ticket, was told to go and buy something else. It now names both ways and asks ticketGate, which is what actually decides. Co-Authored-By: Claude Opus 5 <[email protected] > Claude-Session: https://claude.ai/code/session_01UakmmGQ668fYAvSpFNojg1 https://github.com/satoshidude/jointfactory.io/commit/ff5264a18c8ca3e74b012fbe68f978c1c9a713e0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] relay: tell the admin and the subscriber what the money did The payer got one DM on a credit; nobody else got anything, and the DM that actually matters wasn't there at all. Now: the ADMIN hears about every payment (Nostr DM + Telegram if their account has one linked), a payer whose zap bought less than a day is told what was banked rather than met with silence, an admin grant tells its recipient, and a subscriber is warned 7 days before expiry and again when it ends — a lapse hands them back to the free window, so the next auto-clean takes their older https://github.com/loblawbob873-svg/posterchanai/commit/60dbbde0b703f7549ffa1e662936b135d6650d85 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/gopherkind ] docs: record the v0.15.3 deployment https://github.com/forgesworn/gopherkind/commit/4a21bb4091351e11bb3f76c3251786377aff03ad npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ OpenSats/website ] feat(funds): add Red Team Fund at /funds/red (#902) * feat(funds): add Code RED fund page stub at /funds/red Page and cover art are in place; zaprite and BTCPay store IDs are TODOs until those are provisioned. * feat(donate): wire Code RED designation and red banner variant Add red to fund labels, showcase types, related tags, and DonorSupport https://github.com/OpenSats/website/commit/cb0a1fa58af54b9bcb1325347c5689eccb7fb69b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] feat(governance): make voter eligibility evidence rather than assumption (#200) (#214) * feat(governance): make voter eligibility evidence rather than assumption (#200) Nothing checked that a counted vote came from someone entitled to cast it. Neither tallyFromVoteRecords nor verifyDecision looked at membership, so a decision citing five authentic, well-formed votes from five DIDs that were never members verified as valid -- the largest remaining gap in the chain. A vote record now carries the community-signed member and role records https://github.com/athlon-misa/openfederation-pds/commit/f3999adffd32ea6e484d3ba78c064c1978a37c43 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/nostrsearch ] Clone the client instead of wrapping it in an Arc nostr_sdk::Client is already a handle around shared state, so a clone is a refcount bump and every clone drives the same pool. The Arc added a second layer of indirection around something that was already reference-counted. https://github.com/v0l/nostrsearch/commit/3c8be1733d82eb8bb410dd7758224f2fd03e49c0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ aljazceru/awesome-nostr ] Merge pull request #704 from qyronx/patch-2 Add File Blossom to Tools https://github.com/aljazceru/awesome-nostr/commit/52474cc955ea84adf0f9b1d7a4fbdf5074a27a1a npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/sapwood ] fix: stop a derived identity blanking the Identity panel Nip05Card keyed its identity each block by master.slot over the full masters list. A derived persona carries its OWNING master's slot, so a signer holding a master plus any derive-by-name identity reported two rows with slot 0. Svelte throws each_key_duplicate on a repeated key, which unmounts the whole surrounding component: Advanced > Identity rendered nothing at all. It only surfaced once the browser knew the signer's relays, since that is what makes the NIP-05 identity selector render, so it looked like the panel had simply stopped working. https://github.com/forgesworn/sapwood/commit/7ecbc413cdc445922adc9b0a05fa58619813f2df npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ kevmodrome/tablinum ] Upgrade Effect compatibility https://github.com/kevmodrome/tablinum/commit/2b2ea1b4fd961106b2e66e993e1adbc0bf5a1494 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/6c85b65435219a904cf52547030abf331af237cb npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] fix(sdk): guard outbound did:web resolution during offline verification (#97) (#209) verifySignInAssertion reads the issuer from an unverified JWT payload, so a caller could name any did:web host and make the verifying backend fetch it before any signature was checked. resolveAtprotoKey decoded that host -- including encoded ports -- straight into a URL and called fetch() with no destination validation and no redirect handling, giving a blind SSRF primitive that reaches internal HTTPS services and cloud metadata endpoints. The did:web fetch is now validated on every hop: HTTPS only, no embedded https://github.com/athlon-misa/openfederation-pds/commit/5950d8a6f68e7c9b29f229b1cd7abd84bc749342 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/gopherkind ] Merge pull request: drop the ignored pages timeout https://github.com/forgesworn/gopherkind/commit/7e1eff9014edc6d434b8fa5b262931e334fe2859 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ LNVPS/api ] feat(marketplace): admin approval, the gates it enforces, and the backing host (#363) Increment 3b. Operator-registered hardware can now be reviewed, admitted to the fleet, suspended, drained or rejected, and an operator's revenue share and payout target can be set. Approval is the only transition into `approved`, and it is the only place the gates live: a node with no pinned TLS certificate cannot be reached, and where the region's company charges a listing fee that fee must have been paid *to that company*. Without the second check the per-node fee quietly becomes a https://github.com/LNVPS/api/commit/cb8ee54f87cbbc65bdb9131cac368d410e01466b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ satoshidude/jointfactory.io ] Admin opens with the v0.4 text, not last release's The broadcast form still prefilled the v0.3 announcement and the campaign name update-v0.3, so the text that had to go out was in a file nobody can reach from a browser. It now opens with the rounds text and rounds-v0.4, which is also what the dry run and the double-send guard key on. Paragraphs are single lines. Nostr clients wrap them; hard breaks at eighty characters arrive ragged on a phone. The file in tasks/ carries the same string character for character. https://github.com/satoshidude/jointfactory.io/commit/b07310b6dbea5e22c6eaa9b93884ba540d19ac06 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/nostrsearch ] Bound scraper fan-out to 50 relay/day queries, and spawn lazily Two things, one of which was a real problem introduced by uncapping relay discovery. The pass loop spawned a task per known relay up front and acquired the semaphore permit *inside* it. Every relay therefore had a live task from the moment a pass began -- each with its own clones of the state, sink and config -- all parked waiting for one of 8 permits. At a 200-relay cap that was merely wasteful. Uncapped it is thousands of tasks to run a handful, which is https://github.com/v0l/nostrsearch/commit/73a8f62666412e712546fdb02c8b7f4cdf78c195 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/55da73c77792d92e7ed2d58ad341130b2aaef5dc npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ hzrd149/nostrudel ] docs: review backlog — promoted 2, removed 0 Promote 999.1 (hidden mutes unlock UX) to Phase 1 and 999.11 (lint config and CI quality gate) to Phase 2. Remaining aislop scan items (999.2–999.10) stay in the backlog, gated on Phase 2 landing so they are measured against a config the project chose rather than aislop's bundled defaults. Also commits the scan evidence the backlog entries cite. Co-Authored-By: Claude Opus 5 (1M context) <[email protected] > https://github.com/hzrd149/nostrudel/commit/7d964ba36691e3027703a829adc80172e4cb7795 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zig-nostr/website ] Show Plaza, and say what is actually being built next (#10) The Plaza page described a client and showed none of it. It now opens with the feed and three cards naming what each screen proves. The roadmap page was describing a plan nobody is following. It promised "roughly a milestone a month", numbered its list 1, 2, 4, and listed five things that have since been decided against: a library 1.0 tag, C-ABI bindings, WASM, mobile, and set-reconciliation sync. It now carries the ten milestones in the order they will be done, with no dates, and a https://github.com/zig-nostr/website/commit/59c6be45956b38bd69ac031677b8f77c9c7ca8e0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ TsukemonoGit/lumilumi ] Merge pull request #1087 from TsukemonoGit/dependabot/npm_and_yarn/fast-uri-3.1.5 Bump fast-uri from 3.1.4 to 3.1.5 https://github.com/TsukemonoGit/lumilumi/commit/f774b3f3d330aad2a5ab0fe754c0372f60477aed npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zig-nostr/plaza ] Show what Plaza looks like (#154) The README described a client and showed nothing. Now it opens with the feed and three cards naming the claim each screen proves: the feed is a local query, everyone is resolved from the store, conversations nest in full. Only the pictures are committed. The harness that made them drives a real build against a loopback relay and needs a build flag, fixture events and an isolated home to do it, and none of that belongs in the repo of an app https://github.com/zig-nostr/plaza/commit/aac6885de79bea4b15bc7e42ce3b9f1cad81ce86 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ TsukemonoGit/NostViewstr ] Merge pull request #140 from TsukemonoGit/dependabot/npm_and_yarn/fast-uri-3.1.5 Bump fast-uri from 3.1.4 to 3.1.5 https://github.com/TsukemonoGit/NostViewstr/commit/2ba84f8f91d9df3e871861ed3d510d413925907d npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ hzrd149/applesauce ] feat(13-06): type Relay.sync with RelaySyncOptions and thread it into its internal calls - Relay.sync's fourth parameter is now the named RelaySyncOptions type instead of an anonymous waitForAuth literal (D-05, 3 of 5) - extracts the caller's auth options into one forwarded object and threads it into all three of sync()'s relay operations: the negentropy negotiation, the internal SEND-direction event() call, and the internal RECEIVE-direction req() call (RAUTH-08) - deletes the dead protected pre-gate waitForAuth() helper (and its now-unused mergeWith import) now that negentropy() no longer calls it https://github.com/hzrd149/applesauce/commit/c6eeb1bcf682f78280e3d13553a71cda21c4b3f7 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ getAlby/hub ] fix: fallback to outgoing payments in Phoenixd LookupInvoice (#2447) * fix: fallback to outgoing payments in Phoenixd LookupInvoice LookupInvoice only queried /payments/incoming/{hash}, returning 404 for outgoing payments. This caused all outgoing Lightning payments to remain permanently stuck as PENDING in Alby Hub. The fix tries incoming first (preserving existing behavior), then falls back to listing outgoing payments and matching by paymentHash. https://github.com/getAlby/hub/commit/3b3e784fa6d6fe650635d2d20ddbd57f0b3b6ce4 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ radrootslabs/lib ] studio-runtime: harden composition and concurrency - extract runtime composition, preferences, networking, and persistence into canonical package boundaries - enforce explicit relay policy, bounded work, supervised shutdown, and partial-result semantics - persist restart-stable installation identity and remove panic-prone global initialization races - verify Studio architecture, checks, clippy, runtime, FFI, storage, networking, and restart tests https://github.com/radrootslabs/lib/commit/5d53eb8da344e92453c032609ebef3add0b33fc5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ radrootslabs/lib ] consolidation: preserve donor history - Freeze verified source archives, path mappings, and dual-source controls. - Validate bundle integrity, commit maps, ancestry, attribution, and patches. - Rehearse merge-bearing filtering, restoration, and a ref-neutral import. - Reject context, workflow, secret, bot, license, and object-integrity drift. https://github.com/radrootslabs/lib/commit/3f35c869c827b35b27e7a7d789d409e6c3def6a8 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] nginx: a Nostr-in-Docker sample, and the header set the old one silently dropped The Docker docs told Nostr-only users to front the container with nginx and handed them the full-node template: /v1 for an API that image doesn't ship, /static served off a bare-metal checkout that isn't there, no NIP-05, no relay subdomain, and not a word about the one thing Docker changes — 127.0.0.1 is nginx itself once nginx is a container. nostr-docker.conf.example is that stack's config instead. Testing it against the live relay found the shipped template was dropping headers: proxy_set_header is an nginx ARRAY directive, so the Upgrade/Connection pair sitting https://github.com/loblawbob873-svg/posterchanai/commit/c0af38bfaf54a80194fca7e8058d9e87d9e5ab51 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ immrdude/clawstr ] Update README.md https://github.com/immrdude/clawstr/commit/e903dcf3c57987dd8b29959924e1d3ff0e2bfad5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ shocknet/Lightning.Pub ] Merge pull request #1011 from shocknet/fixes fix swap replay +verify swap quote +fix payment refund +fix debit fre… https://github.com/shocknet/Lightning.Pub/commit/b007ef1d11d05fe5b84f702f12dc07a0b75eb511 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ rehansahab/Sparkle-Protocol ] Update README.md https://github.com/rehansahab/Sparkle-Protocol/commit/8549c965d724dfe66ef06f46f9baa6093fbd356e npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zapcooking/frontend ] Merge pull request #618 from dmnyc/fix/post-engagement-drawer-layout fix(posts): simplify engagement drawer layout https://github.com/zapcooking/frontend/commit/5932a44594f931bd440e277ac3d6fef6d3502a26 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ papiche/UPassport ] refactor(templates/youtube.html): déplace la logique de connexion vers uplanet-header.js https://github.com/papiche/UPassport/commit/e5c4fba7b583692a0e9ca3d2aef8793b889bebb9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ vitorpamplona/amethyst ] Merge PR: ci: publish windows-arm64 desktop + windows amy/geode release assets Merges nostr proposal 3ac62492 (v2) into main: - ci: publish windows-arm64 desktop + windows amy/geode release assets - ci(release): build windows-arm64 desktop as a portable zip only Extends the release matrix to Windows on Arm using the free public-repo windows-11-arm runner, and adds Windows legs (x64 + arm64) to build-cli and build-geode. amyImage / geodeImage now emit both a POSIX launcher and a .bat launcher so the flat image layout is uniform regardless of build host; https://github.com/vitorpamplona/amethyst/commit/372964194d2b04badbcc35084bdcf40978d37121 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ arbadacarbaYK/gittr-mcp ] fix: prefer npub git.gittr.space clone URLs when resolving repos https://github.com/arbadacarbaYK/gittr-mcp/commit/7db4f840cef3afe9fa3054d12830d4f1af828b8c npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ radrootslabs/lib ] test(storage): enforce release coverage gates https://github.com/radrootslabs/lib/commit/f7f456d906d91aadbb9fac4850afaa8c5723c3e9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ geyserfund/geyser-app ] Update contact email for reporting vulnerabilities https://github.com/geyserfund/geyser-app/commit/54ba111980657b5319e6278cc4e12a7f13ea8eda npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ satoshidude/jointfactory.io ] Broadcast text states the credit rule, not the best case The draft promised every reader "3 rounds and 3 stars, managers at 21 sats instead of 90". Rounds are credited per full quadrillion earned, capped at three: five accounts get that, thirty-one get nothing. Same mistake the switch screen made, and worse in a DM, because a player who reads it and then sees a zero has been told something untrue by name. It now states the rule, says plainly that most accounts are credited with nothing, and says what that means — the first star comes from the first round https://github.com/satoshidude/jointfactory.io/commit/4dfd3f00ba29184da8264c22a328789e588fd732 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] client: a quote is not a reply, so stop showing the quoted note twice isReply was `ev.kind===1 && ev.tags.some(t => t[0]==='e')` — ANY e-tag means a reply. NIP-10 gives an e-tag a MARKER, and `mention` means "I am pointing at this note", not "I am answering it". So a quote post made the older way (an e-tag marked `mention` plus the inline nostr:nevent) was classified as a reply, and feedNoteHtml put a "↩ replying to …" header above it — while the body embedded that SAME note again as a quote card. The referenced note appeared twice in one card. Plenty of clients still quote https://github.com/loblawbob873-svg/posterchanai/commit/f3bb1f9e97813d953167f5edef73f4185cb24d36 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ arbadacarbaYK/gittr ] fix: harden file fetch, GRASP path clones, and relay discovery docs Prefer real clone hosts over inferred git.gittr.space, parse /grasp/npub/repo URLs, and document Pyramid tag limits for NIP-65 operator lists. https://github.com/arbadacarbaYK/gittr/commit/2e46f11478e8dc08967586b4fdafbdf48e30090b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ immrdude/clawstr ] Update README.md https://github.com/immrdude/clawstr/commit/44dbc8a4653d8eb483e834ebf5bc2e4fcdbdcae5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nogringo/nostr-mail-client ] refactor(ui): open dialogs and sheets with Flutter instead of GetX Replace Get.dialog/Get.back with showDialog/Navigator.pop and Get.bottomSheet with showModalBottomSheet, passing BuildContext down to the call sites instead of reading Get.context!. https://github.com/nogringo/nostr-mail-client/commit/e4e7b51d88a2df3ccbe0006fa14a5a029029f9b2 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ rehansahab/Sparkle-Protocol ] Update README.md https://github.com/rehansahab/Sparkle-Protocol/commit/c8dfac4d766b3cd38992161eb5565ba9eebff056 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ privkeyio/buzz-relay-startos ] Merge pull request #14 from privkeyio/feature/startos-diagnostics-action Add diagnostics action surfacing community connection state https://github.com/privkeyio/buzz-relay-startos/commit/9cd9b03629048bf9907d5c4cf9e8e4bbf63b07a9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] composer: wire up Clean links, and three fixes it turned up alongside The previous commit shipped urlclean.js and its tests and NOTHING that calls them — `git commit -F -` without -a takes only what is staged, and only the two new files were. Inert rather than broken (no script tag, no menu item), but the feature was not live. This is the rest of it, plus three separate reports. 🧹 Clean links, wired: the AI-menu item in both composers, the opt-in "Remove link trackers when I post" setting, the publish-time hook on all four post paths (inline, inline schedule, modal send, modal schedule), the script tag https://github.com/loblawbob873-svg/posterchanai/commit/51e86d41aa9059ac0d65eb9e232faa2a6e28ad4f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ ptrio42/nostrich-love ] Merge branch 'seo/entity-and-linking' Six commits from an SEO audit and a follow-up adversarial sweep. 118 files, +3257/−1330. The audit's headline finding stands and is worth stating up front: **the real bottleneck is links and domain age**, not on-page work. First commit 2026-02-12, one directory listing and it carries `rel="nofollow"`. Nothing here manufactures authority — it makes the site legible to crawlers, fixes several things that were plainly broken, and removes the excuses. The distribution work is separate and mostly not code. --- ## 1. Entity graph, crawlable locale links, query-matched homepage (`5f37169`) https://github.com/ptrio42/nostrich-love/commit/0cdf59a5417560ec3dd3adc1572d5ab033ec5988 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ trinidz/rssnotes ] new repo with dark mode https://github.com/trinidz/rssnotes/commit/54024aacf0e47f47cf6305b02f830f89164f8231 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ vitorpamplona/amethyst ] Merge pull request #3867 from vitorpamplona/l10n_crowdin_translations New Crowdin Translations https://github.com/vitorpamplona/amethyst/commit/fdbad9396fee9e5dbbe76c65520571e7b37cc1e3 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] Merge branch 'security/hardening-batch' https://github.com/athlon-misa/openfederation-pds/commit/e230d715a0a465b23c430d1054ffb227fb68a582 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ areebahmeddd/airhop ] feat: enhance NostrClient relay handling and settings - Introduced tests for NostrClient relay targeting to ensure custom relays are contacted alongside geo-discovered relays. - Updated geo-relay logic to maintain a consistent ceiling for custom relays, preventing silent drops when geo-relay discovery is enabled. - Improved user interface in the Channel Info Sheet and Network Settings to display active relays, including custom ones. - Added functionality to manage custom relay limits, ensuring users cannot exceed the maximum allowed. - Enhanced localization strings for better clarity on relay functionalities and settings. https://github.com/areebahmeddd/airhop/commit/e1f2e625a573446f9105e4217a4e40f05f2a834f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ protolayer-io/choke ] Merge pull request #177 from protolayer-io/docs/play-store-and-demo docs: add Play Store badge and demo video https://github.com/protolayer-io/choke/commit/c5af487e206810303cb85d7d49a819d9db1a4a1b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zig-nostr/website ] Use the right four shots on the signer page (#9) The page carried four plain window captures. The set that was made for it is the hero card and its three panels, each naming the claim the screen underneath it proves. A picture of a window says what the app looks like; these say what it is for. The old four are gone rather than kept alongside, and the panels stack below 640px: a 1000x1400 card at a third of a phone's width is unreadable. https://github.com/zig-nostr/website/commit/e42be4ffe89abd4f30595cba50e7dd60046f6ab2 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zig-nostr/notary ] Use the right four shots (#40) The README carried four plain window captures. The set that was made for it is the hero card and its three panels, each naming the claim the screen underneath it proves: the key never arrives, one URL any client, nothing signs quietly. A picture of a window says what the app looks like; these say what it is for. The old four are gone rather than kept alongside. Two sets of the same screens is a reader wondering which one is current. https://github.com/zig-nostr/notary/commit/92973bb93aff6b6de88996bfc50ab35977078781 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ immrdude/clawstr ] Update README.md https://github.com/immrdude/clawstr/commit/6427aed56d523ef41033310b4573ffaf0289471b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ rehansahab/Sparkle-Protocol ] Update README.md https://github.com/rehansahab/Sparkle-Protocol/commit/5bf8464da082aafdbb9fca7017f787f798271e10 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ shopstr-eng/shopstr ] Merge pull request #599 from arnavkirti/test/ui test(gift-wrap): enhance mock implementations for gift wrapping functions https://github.com/shopstr-eng/shopstr/commit/0d4171ec63f98f1a02116d6fa18fd5fbb65faf06 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ radrootslabs/lib ] docs: update README.md https://github.com/radrootslabs/lib/commit/59dc0c7f517237f668b4ca1ede9d5cbc511d879d npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ geyserfund/geyser-app ] Create SECURITY.md with security policy details Added a comprehensive security policy outlining reporting procedures, supported versions, and guidelines for responsible vulnerability research. https://github.com/geyserfund/geyser-app/commit/60b39d832a153804bc5a52b55f5944bf6365227c npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ PR0M3TH3AN/bitlogin ] Relay lists: drop a relay that cannot accept writes, widen for margin Measured every candidate on 2026-08-05 against its own NIP-11 document and over a real socket, three runs each. nostr.wine advertises payment_required AND restricted_writes, so it can never accept a free user's capsule -- yet it held one of five slots in BUILTIN_VAULT_RELAYS, the list capsules are PUBLISHED to. relay.damus.io and relay.nostr.band were unreachable 3/3 from the machine under test. That left two usable relays against publishAndVerify's floor of two https://github.com/PR0M3TH3AN/bitlogin/commit/5aa7d9ca153d0e9dbdb8c5fd379c29d8be0abdc9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zeSchlausKwab/wavefunc ] Merge pull request #9 from zeSchlausKwab/codex/fix-song-share-note Release WaveFunc 0.1.9 with standalone kind-1 downloaded-song shares. https://github.com/zeSchlausKwab/wavefunc/commit/c95512b25f121a09d4bf6605dfc644258598ade1 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ radrootslabs/lib ] refactor: complete authored operations v2 - retire legacy draft, atomic, and duplicate transport surfaces - complete durable authored orchestration and migration cutover - synchronize API, release, and coverage contract artifacts - qualify the full library workspace and release boundary https://github.com/radrootslabs/lib/commit/691b3c844bb8824fd16b2ff4fb37b8c09bac208d npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ haruki7049/nostr-unko-posting-bot ] Empty commit to run CI https://github.com/haruki7049/nostr-unko-posting-bot/commit/72146a1de5395f3173512b43109d82c1404101fc npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] bookmarks: pace the sync, and tidy duplicate bookmarks too Two things a first enable leaves behind. PACING. The call counts are already minimal at a first sync; what freezes the window is that hundreds of bookmark writes and signed publishes go out in one unbroken run, and every one is an IPC to the process that draws the window. The loops now yield briefly every 20 items. Nothing observable changes, which is why the engine COUNTS its yields — a loop that lost them looks identical in its results. https://github.com/loblawbob873-svg/posterchanai/commit/f912d376842a1b12f05c30cf275567a31e4cdf9f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ satcodexyz/satcode ] chore: NDK singleton Initialization (#20) * chore: create NDK singleton with default relays * chore: create ndk utils file & fetchLatestEvent util * chore: format * test: create tests for fetchLatestEvent https://github.com/satcodexyz/satcode/commit/56f724ed08bacbff35a63846bd9441e385eec3d9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ LNVPS/api ] feat(node): HTTPS control listener, authenticated on every request (#359) Increment 2b. The daemon now serves `GET /api/v1/status` over the tunnel, with both of decision 13's defences enforced rather than described. Authentication is layered over the whole router, not attached per route, so a route added tomorrow is covered without anyone remembering to cover it. The test that matters is an unauthenticated request to a path that does not exist returning 401 rather than 404: that is what demonstrates the layer sits in front of routing. https://github.com/LNVPS/api/commit/ce9d9ba9668773a260b90282c7d738919a00b3b8 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nostrdevkit/nostr-sdk-ffi ] Release v0.45.0 Signed-off-by: Yuki Kishimoto <[email protected] > https://github.com/nostrdevkit/nostr-sdk-ffi/commit/8b56484a875e81ba8b6148d669b6231cc52cb34a npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nostrdevkit/nostr-sdk-swift ] Bump to 0.45.0 https://github.com/nostrdevkit/nostr-sdk-swift/commit/b4a318158cee0e6f50c7bbb80fb41830620d1df9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ NickAiNYC/payphone ] feat: add demo scenario for deployment review One agent, one human, one broken build, one memory chain. Runs the real modules against the relay in docker-compose: kind 0 profile, kind 21006 preferences, kind 21008 memory objects, interruption policy, signed intent envelope, BIP-340 verification, replay guard, context resolution with signature checks on every resolved object. Only the APNs transport and the spoken audio are stubbed, and the output says so. https://github.com/NickAiNYC/payphone/commit/32c5368009b87375f5b68d8e32a58d24cf42e277 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ LNVPS/api ] docs(db): tunnel owners are customers, not LNVPS (#357) The comments landed in #356 said LNVPS's own infrastructure owns some tunnels, via an account representing us. That is wrong: `user_id` is always a real customer account — the operator's merchant account for a marketplace node, the requesting user for a BGP tunnel or a VPN. Tunnels in this table are sold to somebody; LNVPS's internal plumbing is not modelled here. The distinction matters because the wrong version implied a system account had to exist before any BGP tunnel could be allocated, which would have been built. https://github.com/LNVPS/api/commit/fb3a3566e02d0022842a6de55c09145e4ef79d18 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/nostrsearch ] Re-attach the graph store after resetting analyses Resetting an analysis replaces it with a default instance, and that discards the shared GraphStore handle attached at startup. Nothing put it back, so after `ingest --reindex` (which resets everything before replaying the corpus) follow_graph logged follow_graph has no graph store attached; call Registry::attach_all (Registry::load does this) before observing - the follow graph will be empty https://github.com/v0l/nostrsearch/commit/9db2218a7d769ed6894606d7546c70812de8f7cb npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ areebahmeddd/airhop ] feat: enhance NostrClient relay handling and settings - Introduced tests for NostrClient relay targeting to ensure custom relays are contacted alongside geo-discovered relays. - Updated geo-relay logic to maintain a consistent ceiling for custom relays, preventing silent drops when geo-relay discovery is enabled. - Improved user interface in the Channel Info Sheet and Network Settings to display active relays, including custom ones. - Added functionality to manage custom relay limits, ensuring users cannot exceed the maximum allowed. - Enhanced localization strings for better clarity on relay functionalities and settings. https://github.com/areebahmeddd/airhop/commit/96e5322c075f1d7374fcc3debf3a42f232f66fb0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ aljazceru/awesome-nostr ] Remove Related Resources section from README Removed the 'Related Resources' section from the README. https://github.com/aljazceru/awesome-nostr/commit/d1b97c42549c057ed84b9cec131bbb9904af0cb2 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ ZeusLN/zeus ] Merge pull request #4337 from kaloudis/ui/lnurl-pay-empty-amount ui: LnurlPay: start amount empty instead of min sendable https://github.com/ZeusLN/zeus/commit/3744800105d70d4124e332f0577ed3a826c528ca npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ denizkin28/n8n-nodes-buzz-relay ] Bump checkout/setup-node to v5 to clear the Node 20 deprecation warning https://github.com/denizkin28/n8n-nodes-buzz-relay/commit/8fb14b6340efb4bc0ab81e46362232248c1deda5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] fix: respect CAR response backpressure (#183) https://github.com/athlon-misa/openfederation-pds/commit/1481c585397410477bc9c9ce395c8d084a030458 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ HolgerHatGarKeineNode/einundzwanzig-group ] 🔧 `composer test` erreichte die Tests nie — jetzt läuft es durch `env()` außerhalb von `config/` liefert nach `php artisan optimize` nur noch seinen Default: Laravel lädt die `.env` bei gecachter Config nicht mehr. larastan meldete das an 4 Stellen, und weil `composer test` erst `types:check` fährt, brach der Alltagsbefehl seit jeher ab, bevor ein einziger Test lief. Werte nach `config/` gezogen: - `config/services.php` → `nostr_bot.{nsec,relay,nak_bin}`, neben den https://github.com/HolgerHatGarKeineNode/einundzwanzig-group/commit/c59af178ffa7a1325487495a784b1acacd413806 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ ptrio42/nostrich-love ] chore: trigger the first deploy from the reconnected repo The Vercel integration was re-linked after the repo transfer to ptrio42; reconnection alone does not deploy the pending commits. Co-Authored-By: Claude Opus 5 <[email protected] > https://github.com/ptrio42/nostrich-love/commit/23fdab2dbec91d337e253ede22119274782f72f1 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/nostrsearch ] Bump nostr-archive-cursor: stop rewriting the 149 GB shard every rebuild 8fac489 limits reframing to shards that have no usable frame boundaries at all. A shard that is merely framed more coarsely than the current target was being decoded and re-encoded in full on every rebuild -- the 149 GB combined shard, over an hour a run -- and that phase is where the last several runs were OOM-killed: write_framed allocates a fresh zstd encoder per frame, ~3 million of them for that shard, and the allocator never returns the memory. https://github.com/v0l/nostrsearch/commit/94b8a4fe1add41721b10fa4575b4e1ac5be74cc4 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nostrdevkit/nostr-sdk-ffi ] Revert "Refactor `Metadata` structure" This reverts commit 20cd7100d5e34a30a873d6bb44c90e561d71e45f. https://github.com/nostrdevkit/nostr-sdk-ffi/commit/e9e265d9b448682d8e3eecbb915e316ef310e47a npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Lokuyow/ehagaki ] Merge pull request #54 from Lokuyow/fix/nip46-live-identity fix: verify live NIP-46 signer identity https://github.com/Lokuyow/ehagaki/commit/9f9be658001207aa8a95a1da4c4e146d33f45689 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ soapbox-pub/ditto ] Silence intentional exhaustive-deps warning in useFormatMoney The dependency-array-less effect is a deliberate, documented commit-phase latch (idempotent, guarded by `!wantsPrice`) that must re-check the ref after every commit. Add the same eslint-disable directive the codebase uses elsewhere for intentional deps opt-outs. https://github.com/soapbox-pub/ditto/commit/04adb2d242ab6f5807fd27ae3e0cb9beab091641 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ hzrd149/applesauce ] Merge pull request #89 from hzrd149/fix/clamp-settimeout-delays fix: clamp setTimeout delays to the 32-bit maximum https://github.com/hzrd149/applesauce/commit/5ca390ec999833da86292b948b5b43b9aca76c6f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/dtan ] chore: bump marked, @typescript-eslint https://github.com/v0l/dtan/commit/0aa2e6184ecbd9a550c2dbb081bd3f1ed281f9a1 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ OpenSats/website ] fix: hyphenate decision-making process (#899) https://github.com/OpenSats/website/commit/100783bd243987af98bd8e7fb55833eb4044fa24 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Cordn-msg/cordn-web ] feat: add keyboard plugin and edge-to-edge support Add @capacitor/keyboard plugin and configure edge-to-edge display for Android 15+ (targetSdk 36). Set WebView background to dark theme color, enable SystemBars with CSS safe-area insets, and use Keyboard resizeOnFullScreen to prevent the keyboard from covering the composer. Also add android:windowSoftInputMode="adjustResize" in the manifest. https://github.com/Cordn-msg/cordn-web/commit/cd7fff81864286b857221df670d41e01d944da95 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ steve02081504/fount ] Add integration CI for character import and easynew creation (#278) Co-authored-by: Taromati2 <[email protected] > https://github.com/steve02081504/fount/commit/3c03e66e8e82f5f6b1c4d0b6d19cd863b711e7f0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ NickAiNYC/payphone ] feat: context availability state machine and interruption policy Two gaps in the ring design, both found by pressure-testing it. Context: "open audio immediately, resolve pointers concurrently" was right about latency and wrong about the greeting. Opening audio while resolution is in flight means the agent's first sentence is written against an unknown state — if it assumes continuity and resolution then fails, it stammers or confabulates. https://github.com/NickAiNYC/payphone/commit/5c97090b2075a8f08f4c070da4020b7f3b953701 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ areebahmeddd/airhop ] fix flaky announce capabilities test and validate the Gradle wrapper in CI https://github.com/areebahmeddd/airhop/commit/5e31cce16f2aa03fb983fe492050ecd232a84601 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zig-nostr/plaza ] Take the window's startup size from the manifest too (#150) app.zon declares 760x760 and main.zig declared 760x760 beside it, with nothing connecting them. That is exactly how the minimum width came to sit seven pixels below what the layout needed and stayed there (#138), which is why the floor already reads from the manifest. The startup size now does the same, through the reader generalised to any numeric field on the window. The app also needs the declared number at runtime to notice when it has https://github.com/zig-nostr/plaza/commit/a4f2a00bf9a93370bada8425297272ddbb932c8a npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/nwb ] fix: NIP-5A compliance, base36 padding, in-flight race, content integrity - Enforce 50-char pubkeyB36 padding in named-site subdomain generation so most pubkeys resolve correctly (base36 is otherwise variable-length) - Make in-flight request cleanup deterministic instead of deferred to a detached task, closing a race where stale entries blocked new requests or a stale cleanup removed a newer loader's entry - Verify downloaded blobs' sha256 against the path-tag hash (NIP-5A MUST), skipping corrupt/malicious Blossom servers - Add /404.html fallback for unresolved paths (NIP-5A MUST) https://github.com/v0l/nwb/commit/b52a12977021d7a135c789e8cfc0a97bd76267e4 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ NickAiNYC/payphone ] feat: replay protection for signed ring payloads A signature proves origin, not freshness. An attacker who captures a valid VoIP push can replay it verbatim — the signature still verifies and the phone rings for something that already happened. Expiry narrows the window; inside it, replay was free. ReplayGuard rejects a ring whose (agent, call_id) has already been consumed. Scoped per agent, since two agents may legitimately mint the same call_id. Consumption runs after signature verification so a forged ring https://github.com/NickAiNYC/payphone/commit/787b496d406164d83297bd570e5c7997eede11c0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nostrdevkit/nostr ] sdk: bump async-wsocket to 0.17 Signed-off-by: Yuki Kishimoto <[email protected] > https://github.com/nostrdevkit/nostr/commit/25f7bb8842bf37c9fdb6d039c5e21c56d6b6363f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] Merge pull request #179 from athlon-misa/security/attestation-commitments-v2 fix: salt private attestation commitments https://github.com/athlon-misa/openfederation-pds/commit/9084ed258cce0d1bafa3bd91db2f668326e59fc5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ mozharov/zapgram ] feat: enhance PostHog integration by adding support for managed reverse proxy configuration https://github.com/mozharov/zapgram/commit/6d1294b450c7601bd9c57ea8a426916b4810a312 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ melvincarvalho/noskey ] web: recognize did:nostr:<hex> as a public key (input box and ?pubkey=) https://github.com/melvincarvalho/noskey/commit/ce52db9b36458da3f4aa03b21670b04683421cc0