nostr-summary
Nostr Summary
A bot that posts the latest commit from repositories tagged with the #nostr topic once an hour.
Public Key
npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux Profile Code
nprofile1qqs8l6lz5kd2sfhc7cehksgpjw024jp06nnv5heu0w838jsr45n090cpp4mhxue69uhkummn9ekx7mqpr4mhxue69uhhjctzw5hx6ef00pexz7fdd9hxg6tp94kkj6m9y7f77q
Show more details
Published at
2025-10-25T13:41:20+02:00 Event JSON
{
"id": "bfb41c55da755ebe522bb72e494a57dde1eb48219fdd4f4e4940f6a25ba8037f" ,
"pubkey": "7febe2a59aa826f8f6337b4101939eaac82fd4e6ca5f3c7b8f13ca03ad26f2bf" ,
"created_at": 1761392480 ,
"kind": 0 ,
"tags": [],
"content": "{\"name\":\"nostr-summary\",\"display_name\":\"Nostr Summary\",\"picture\":\"https://robohash.org/npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux?set=set4\u0026size=120x120\",\"website\":\"https://github.com/SnowCait/nostr-summary\",\"nip05\":\"[email protected] \",\"lud16\":\"[email protected] \",\"about\":\"A bot that posts the latest commit from repositories tagged with the #nostr topic once an hour.\"}" ,
"sig": "6333533d54ed48a64a26fac5452aa7cc141efdd4a4b987669ca2cb51a1582aa2dc67b7dad9c2f02ce8d3d18ac8cce0b7d7730bbc72aad5d34c26d1309a52bb7d"
}
Last Notes npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ chebizarro/nostrc ] Sync beads (nostrc-sdq0 closed, nostrc-2xgy filed) Co-Authored-By: Claude Fable 5 <[email protected] > https://github.com/chebizarro/nostrc/commit/9c48630b75d5c9cb9468bcce55fc694428f709fe npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ hzrd149/nostrudel ] docs(01): capture phase context https://github.com/hzrd149/nostrudel/commit/a3511756b800cdae740548e8ec843b8615cf6231 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/a77ee8d4a40c0c9616215addf7d88404257d6009 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ chebizarro/nostrc ] fix(marmot): align MLS sender-side wire formats with RFC 9420 receiver (nostrc-3fi1) Recent receiver-side RFC 9420 conformance work (19236821, b77c134d, baa13cbd) was validated against MDK interop vectors but left the sender emitting legacy formats, breaking our own round-trips: - build_group_info_extensions_with_tree now emits the RFC ratchet_tree extension (optional<Node> vector via mls_ratchet_tree_serialize) instead of a legacy u32-n_leaves encoding the Welcome receiver no longer parses; drop the legacy serializer and the now-unused legacy https://github.com/chebizarro/nostrc/commit/6526d32fe35684b05f4e4427a23ccc4a3dff198a npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/312713ec4470b49dccfe03d45d839c73fd63995c npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Eszetael/apify-actors ] Point the chaining example at an Actor that still exists The snippet started from eszetael_lab/nostr-scraper, which is no longer published: anyone copying it hit a 404 on the first call. It now starts from the Bluesky scraper in author_posts mode — the one mode that needs no login, so the example runs as-is for a stranger. Co-Authored-By: Claude Opus 5 (1M context) <[email protected] > https://github.com/Eszetael/apify-actors/commit/e7a81ff35b2bd6afa88ccfd06623f03198af6584 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ arbadacarbaYK/gittr ] fix: retry Amber bunker dial with forced signer relays on cold Push Hydrate-only sessions sometimes left zero OPEN bunker sockets; Push then failed before signing. Add a third transport attempt on Amber-friendly defaults and stop logging empty GRASP defaults on list timeout. https://github.com/arbadacarbaYK/gittr/commit/368a890f511268def0bfa7a8f859c91677512812 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ radrootslabs/lib ] fix(storage): rebuild current event visibility - validate admission-selected contracts without weakening generic classification - reduce current heads, deletion cutoffs, and ephemeral visibility deterministically - preserve memory and SQLite parity across atomic ingest, pagination, and reopen - harden downstream recovery semantics and corrupt-row rejection coverage https://github.com/radrootslabs/lib/commit/f7e947c2e5404b14974eef2ed11cae31c6b55061 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ mattn/mruby-nostr-relay ] Merge pull request #15 from mattn/fix-ping-frames-and-db-reconnect Ignore non-text frames and reconnect to the database on lost connections https://github.com/mattn/mruby-nostr-relay/commit/eb6f654f30cb4a2af9b8f3cab1941ca63bc74b7b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Lokuyow/ehagaki ] Merge pull request #67 from Lokuyow/refactor/post-history-relay-resolver refactor: share post history relay resolver https://github.com/Lokuyow/ehagaki/commit/5fd00c6689068ec0fcd2eba8d06c8e4f27f0932e npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ arbadacarbaYK/gittr-mcp ] feat: softDeleteRepo plus dual-identity ACL live hammer Adds deleteRepo/softDeleteRepo, createRepo clone-url fix, broader publish relays for write verification, merge base-branch fallback, and test:live:acl covering smo issue/PR and permission-denied merge. https://github.com/arbadacarbaYK/gittr-mcp/commit/87098c0e63d207e8d69bd184ef941542de223f36 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/sapwood ] chore: sync firmware v0.14.0 Signed and published by release.yml from the v0.14.0 tag, so the OTA seed stayed in CI rather than travelling to a workstation. The heltec-v4 signature was verified independently against the committed public key before this sync, and every board in version.json carries one. Stops the manifest advertising 0.13.9, which is the release that predates tonight's relay fixes. The downgrade guard already made that stale manifest harmless rather than dangerous; this makes it correct. https://github.com/forgesworn/sapwood/commit/c32986fc2b381b2395769af8ad5183e2c855e779 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/db083dc11086a559e84d05affedc3019fac1f3d4 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] meme check: --project must not rewrite a real project's layer sources _run_project reused _page, which remaps every layer's src/mask onto the harness's own probe files — so a real project loaded fine, had all three sources replaced with URLs that do not exist, and both sides rendered an empty frame. The diff was then tiny and the run reported OK, which is the worst possible failure for a tool whose whole job is to say whether two pictures agree. _page takes rewrite=False for this path. Verified against a reconstructed real project (474x265 canvas, letterboxed 474x188 video, two masked VP9-alpha talk clips https://github.com/loblawbob873-svg/posterchanai/commit/f38a9be6aead4bbbda18820102da5061a9e783be npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ steve02081504/fount ] Browser gravity, ESC hold exit, install a11y, and git branch name validation (#283) Co-authored-by: Taromati2 <[email protected] > https://github.com/steve02081504/fount/commit/28fc7f33bdcb388c28c2c7d2bb3fc5495ab8d5fc npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ chebizarro/nostrc ] fix(gnostr): normalize NIP-46 sign requests and harden reaction publish (nostrc-svsj) When logged in via nostrconnect, kind-1 notes, NIP-25 reactions, and other GNostrJsonBuilder-built events (kind 5/6/1111/1985, NIP-34 bug reports) silently failed to publish while NIP-17 DMs worked. The working NIP-59 seal/gift-wrap path serializes a NostrEvent with the author pubkey set, whereas the broken paths sent sign_event templates without a pubkey field, which many remote NIP-46 signers reject or mishandle. - Add nip46_normalize_sign_request() in GnostrSignerService: inject the https://github.com/chebizarro/nostrc/commit/278b2addbbd01762f3a7ca3389880678a9f91263 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Lokuyow/ehagaki ] Merge pull request #64 from Lokuyow/fix/account-cleanup-await fix: await per-account cleanup before logout https://github.com/Lokuyow/ehagaki/commit/ef5348a837814517baaf2c6eaf94f8eb4774d529 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ getAlby/hub ] fix: remove avatar from lightning address QR (#2509) The avatar overlay made the QR code hard to scan, especially for short lightning addresses. Without center content the QR also drops back to a lower error correction level, improving scannability. Fixes #2507 Co-authored-by: Claude Fable 5 <[email protected] > https://github.com/getAlby/hub/commit/d94f6933f5f603615bca9c39d44c7227d913f192 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nostrfi/relay ] Merge pull request #7 from nostrfi/issue-14-metrics-negentropy-logging Add relay operational metrics and fix Negentropy payload logging https://github.com/nostrfi/relay/commit/187a2030cd76fedb8ac6d8871df7574e45c64729 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] client: one event with no tags was killing every timeline Reported as a whole feed of "Replying to <name> — couldn't render this post", for many posts at once, on this instance, with TypeError: Cannot read properties of undefined (reading 'length') in the console. The posts were fine. `tags` is REQUIRED by NIP-01, but the client's cache is fed from places that cannot promise it — a kind-6 repost carries its original as arbitrary JSON in `content`, and whatever that parsed https://github.com/loblawbob873-svg/posterchanai/commit/2efd7a976c63360ee29fd200938518eae4b0c420 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/bark ] feat: prefer the compact signing dialect, falling back to NIP-46 Sends the event as a JSON object and asks for sign_event_compact, which returns {id, sig, pubkey, created_at} instead of echoing the whole signed event back. Bark already holds the event, so the rest is rebuilt locally. Both changes exist to stop moving the event around as a string. NIP-46 stringifies it into params, so its quotes are escaped a second time and a signer must unescape them into a buffer that grows by doubling; and the reply carries the whole event back, larger than the request. On a Heartwood signer https://github.com/forgesworn/bark/commit/5e848cdf5953c869b66cfbe8d6f4b358f10e70c0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/sapwood ] feat: show the compact signing ceiling alongside the standard one Firmware now advertises two ceilings. The second is what an app earns by sending the event as a JSON object and asking for sign_event_compact, which skips the two full-size copies NIP-46's stringified event and echoed-back reply otherwise cost: 18 KB against 12 KB on a V4. Showing only the first understates the signer, and the difference is the app's to claim rather than a property of the hardware. Older firmware omits the field, so both surfaces fall back to the single figure. https://github.com/forgesworn/sapwood/commit/cd5c068484000acd423cb6274594a0ec8f0943e5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ getAlby/awesome-nwc ] docs: add B2B Central and ZapBook https://github.com/getAlby/awesome-nwc/commit/4455686446a1e0929851e0e023121f2915fe9f5e npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ HolgerHatGarKeineNode/einundzwanzig-group ] 🧰 Zwei Prüfungen lagen in einer Spec eingeschlossen — jetzt kann sie jeder benutzen Aus der Teambesprechung zur Emoji-Knopf-Session: Der Design-Pass fand nach einem ACCEPT vier Fehler, von denen zwei deterministisch testbar waren — ein Panel 98 px außerhalb des Viewports und ein Kontrast von 1:1. Zwei Kollegen und der Test-Autor nannten unabhängig dieselbe Ursache: eine Werkzeuglücke, keine Sorgfaltslücke. Jeder hätte beides gefunden, wäre es eine Zeile gewesen. Beides war vorhanden, nur nicht erreichbar. Die Kontrast-Mechanik steckte komplett in `a11y-contrast.spec.ts` und war nicht exportiert; die https://github.com/HolgerHatGarKeineNode/einundzwanzig-group/commit/c64846de812de53fbaca96f5690747f5ce88412b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] fix(db): put every timestamp on the same clock (#223) Fifteen columns were timestamp WITHOUT time zone, and their two writers disagreed about which clock they meant: Postgres defaults and comparisons produce local wall-clock time, while the application passes a JS Date that the driver serialises as UTC. Where the application wrote and Postgres compared, a credential's real lifetime became TTL minus the UTC offset. One column was live: viewing_grants.expires_at, written from a JS Date and compared against NOW() in four places. West of UTC a time-limited disclosure https://github.com/athlon-misa/openfederation-pds/commit/78ad3321528ab12c77d41eb8ba21558e30c5c0b1 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/b227a2f5e7ff39a5876be34761a6fba2e46758c6 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ lawalletio/lawallet-nwc ] chore(release): v2.3.0 https://github.com/lawalletio/lawallet-nwc/commit/d846db0d9e51603f353c8c0b4ac63316666dea1b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ TsukemonoGit/NostViewstr ] Merge pull request #142 from TsukemonoGit/dependabot/npm_and_yarn/js-yaml-4.3.1 Bump js-yaml from 4.3.0 to 4.3.1 https://github.com/TsukemonoGit/NostViewstr/commit/44975ea2ce2a2eb458918f19ef8e5b0fd0b295fe npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ HolgerHatGarKeineNode/einundzwanzig-group ] 🔧 Nur der e2e-tsconfig sah die neue Typdeklaration nicht `emoji.ts` importiert seine Datendateien seit dem Package-Commit mit `?url` (Begründung dort). Die Deklaration dafür liegt beim Package — und damit außerhalb des `include` dieses tsconfigs. Auffällig war das nur, weil `npm run typecheck` drei Konfigurationen hintereinander fährt: Wurzel und Package blieben grün, allein dieser Lauf meldete TS2307. Die Specs importieren die reinen Module aus `packages/*/js/`, und TypeScript zieht deren Abhängigkeiten mit herein — die Deklarationen daneben https://github.com/HolgerHatGarKeineNode/einundzwanzig-group/commit/bf536dc6b569f0e25d5fdd9d6c262b61849eb3be npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] meme: inline the erase mask as a data: URI so the preview can't flake Root cause of the "random empty box / shows the un-erased original / refresh fixes it" reports: the layer stores the mask as a REMOTE Blossom url, and the CSS mask-image pointed straight at it. A mask-image whose fetch fails OR merely loses a race does not degrade to "no mask" — it HIDES the whole element — and that CSS fetch is separate from the Image() probe, so the probe could pass while the real request flaked. Worst cross-origin and inside the Electron app:// build. Verified in real Firefox: url(remote-mask) -> blank element; url(data:...) -> https://github.com/loblawbob873-svg/posterchanai/commit/6b4969d75af278b51bb642081487daef3b0059ad npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ chebizarro/nostrc ] Timeline plan: nostrdb leverage audit (cached blocks, flatbuffer profiles, note_meta counts unused) Co-Authored-By: Claude Fable 5 <[email protected] > https://github.com/chebizarro/nostrc/commit/c63b25bbe09cb45c01a355053d160ec6f7166430 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/bark ] fix: correct the large-event hint to the measured 12 KB ceiling The hint said 20 KB and described it as a wire limit. Both were wrong. The limit is parsing, not the wire: NIP-46 carries the event as a JSON string inside params, so unescaping it grows a buffer by doubling, and the signer runs out of one contiguous block long before it runs out of memory. Measured on hardware the ceiling is 12288, not the 20480 the arithmetic suggested. Current firmware now answers "request is too large for this signer" outright, https://github.com/forgesworn/bark/commit/ac64a94a1c32d095b3b65be1706e490e434307de npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] feat(governance): a held proposal opens an override round (#219) PRD #189 specified "objection → application held pending re-review per community rules". The hold shipped; the re-review did not. `objected` was terminal, so at the default threshold of 1 any single member holding community.governance.write could permanently veto any decision of a majority-governed community — unanimity, not a contest window. A hold now opens one override round: the same electorate votes again against a higher bar inside a time-boxed window. Reaching it applies the change; the https://github.com/athlon-misa/openfederation-pds/commit/bbf4bfae96ffcff80602cd3b1c13c1d379894ef7 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Routstr/routstr-core ] Merge pull request #640 from Routstr/test/issue-639-forwarded-model-id test: reproduce forwarded model ID alias regression https://github.com/Routstr/routstr-core/commit/d26ff0887774f62d5ec754ecd1d50a5e8341b3df npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ vitorpamplona/amethyst ] Merge pull request #3872 from vitorpamplona/perf/outbox-no-quadratic-publish Stop the outbox getting slower with every publish https://github.com/vitorpamplona/amethyst/commit/35f96a936daf9c43b40a7d4e4d68d4c34da644d3 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ lawalletio/lawallet-nwc ] feat(wallet): recents-first recipient suggestions, no native autofill (#138) The /wallet/send recipient field let the browser's own autofill dropdown cover the custom listbox, and the saved-recipient list was capped at 5 and filtered by the query so it competed with the typed-address suggestions. - Disable native autocomplete on the input (`autoComplete="off"` plus the 1Password/LastPass opt-out attributes). - Show the last 10 saved recipients while the input is empty; the first keystroke replaces them with the typed-address suggestions. https://github.com/lawalletio/lawallet-nwc/commit/c75ef7614a0f4446adda9e5f2acb0487dc6fa866 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ betonetojp/nokakoi ] feat(profile): 相互フォロー判定の問い合わせ先にインデクサリレーを追加 相互フォローおよび「フォローされています」表示の非同期判定において、 通常の接続リレーに加えてインデクサリレー(profileIndexerRelay)も検索対象に追加。 他リレーで活動しているユーザーの kind:3 を補完・参照し、判定精度を向上。 https://github.com/betonetojp/nokakoi/commit/8ef1966ce8246ab816b0b3868843854f80bcfc8c npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nostrfi/relay ] Merge pull request #4 from nostrfi/issue-5-storage-lifecycle-backup-recovery Establish relay storage lifecycle, backup, and recovery https://github.com/nostrfi/relay/commit/e00da66012fce9ad8f54f40f557e12b66073893f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] relay: tell the admin and the subscriber what the money did The payer got one DM on a credit; nobody else got anything, and the DM that actually matters wasn't there at all. Now: the ADMIN hears about every payment (Nostr DM + Telegram if their account has one linked), a payer whose zap bought less than a day is told what was banked rather than met with silence, an admin grant tells its recipient, and a subscriber is warned 7 days before expiry and again when it ends — a lapse hands them back to the free window, so the next auto-clean takes their older https://github.com/loblawbob873-svg/posterchanai/commit/60dbbde0b703f7549ffa1e662936b135d6650d85 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/gopherkind ] docs: record the v0.15.3 deployment https://github.com/forgesworn/gopherkind/commit/4a21bb4091351e11bb3f76c3251786377aff03ad npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/nostrsearch ] Clone the client instead of wrapping it in an Arc nostr_sdk::Client is already a handle around shared state, so a clone is a refcount bump and every clone drives the same pool. The Arc added a second layer of indirection around something that was already reference-counted. https://github.com/v0l/nostrsearch/commit/3c8be1733d82eb8bb410dd7758224f2fd03e49c0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ forgesworn/sapwood ] fix: stop a derived identity blanking the Identity panel Nip05Card keyed its identity each block by master.slot over the full masters list. A derived persona carries its OWNING master's slot, so a signer holding a master plus any derive-by-name identity reported two rows with slot 0. Svelte throws each_key_duplicate on a repeated key, which unmounts the whole surrounding component: Advanced > Identity rendered nothing at all. It only surfaced once the browser knew the signer's relays, since that is what makes the NIP-05 identity selector render, so it looked like the panel had simply stopped working. https://github.com/forgesworn/sapwood/commit/7ecbc413cdc445922adc9b0a05fa58619813f2df npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/6c85b65435219a904cf52547030abf331af237cb npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] fix(sdk): guard outbound did:web resolution during offline verification (#97) (#209) verifySignInAssertion reads the issuer from an unverified JWT payload, so a caller could name any did:web host and make the verifying backend fetch it before any signature was checked. resolveAtprotoKey decoded that host -- including encoded ports -- straight into a URL and called fetch() with no destination validation and no redirect handling, giving a blind SSRF primitive that reaches internal HTTPS services and cloud metadata endpoints. The did:web fetch is now validated on every hop: HTTPS only, no embedded https://github.com/athlon-misa/openfederation-pds/commit/5950d8a6f68e7c9b29f229b1cd7abd84bc749342 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ LNVPS/api ] feat(marketplace): admin approval, the gates it enforces, and the backing host (#363) Increment 3b. Operator-registered hardware can now be reviewed, admitted to the fleet, suspended, drained or rejected, and an operator's revenue share and payout target can be set. Approval is the only transition into `approved`, and it is the only place the gates live: a node with no pinned TLS certificate cannot be reached, and where the region's company charges a listing fee that fee must have been paid *to that company*. Without the second check the per-node fee quietly becomes a https://github.com/LNVPS/api/commit/cb8ee54f87cbbc65bdb9131cac368d410e01466b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ satoshidude/jointfactory.io ] Admin opens with the v0.4 text, not last release's The broadcast form still prefilled the v0.3 announcement and the campaign name update-v0.3, so the text that had to go out was in a file nobody can reach from a browser. It now opens with the rounds text and rounds-v0.4, which is also what the dry run and the double-send guard key on. Paragraphs are single lines. Nostr clients wrap them; hard breaks at eighty characters arrive ragged on a phone. The file in tasks/ carries the same string character for character. https://github.com/satoshidude/jointfactory.io/commit/b07310b6dbea5e22c6eaa9b93884ba540d19ac06 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Chewerphalguna599/genesis-mind ] Update README.md https://github.com/Chewerphalguna599/genesis-mind/commit/55da73c77792d92e7ed2d58ad341130b2aaef5dc npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ hzrd149/nostrudel ] docs: review backlog — promoted 2, removed 0 Promote 999.1 (hidden mutes unlock UX) to Phase 1 and 999.11 (lint config and CI quality gate) to Phase 2. Remaining aislop scan items (999.2–999.10) stay in the backlog, gated on Phase 2 landing so they are measured against a config the project chose rather than aislop's bundled defaults. Also commits the scan evidence the backlog entries cite. Co-Authored-By: Claude Opus 5 (1M context) <[email protected] > https://github.com/hzrd149/nostrudel/commit/7d964ba36691e3027703a829adc80172e4cb7795 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zig-nostr/website ] Show Plaza, and say what is actually being built next (#10) The Plaza page described a client and showed none of it. It now opens with the feed and three cards naming what each screen proves. The roadmap page was describing a plan nobody is following. It promised "roughly a milestone a month", numbered its list 1, 2, 4, and listed five things that have since been decided against: a library 1.0 tag, C-ABI bindings, WASM, mobile, and set-reconciliation sync. It now carries the ten milestones in the order they will be done, with no dates, and a https://github.com/zig-nostr/website/commit/59c6be45956b38bd69ac031677b8f77c9c7ca8e0 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ TsukemonoGit/lumilumi ] Merge pull request #1087 from TsukemonoGit/dependabot/npm_and_yarn/fast-uri-3.1.5 Bump fast-uri from 3.1.4 to 3.1.5 https://github.com/TsukemonoGit/lumilumi/commit/f774b3f3d330aad2a5ab0fe754c0372f60477aed npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zig-nostr/plaza ] Show what Plaza looks like (#154) The README described a client and showed nothing. Now it opens with the feed and three cards naming the claim each screen proves: the feed is a local query, everyone is resolved from the store, conversations nest in full. Only the pictures are committed. The harness that made them drives a real build against a loopback relay and needs a build flag, fixture events and an isolated home to do it, and none of that belongs in the repo of an app https://github.com/zig-nostr/plaza/commit/aac6885de79bea4b15bc7e42ce3b9f1cad81ce86 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ hzrd149/applesauce ] feat(13-06): type Relay.sync with RelaySyncOptions and thread it into its internal calls - Relay.sync's fourth parameter is now the named RelaySyncOptions type instead of an anonymous waitForAuth literal (D-05, 3 of 5) - extracts the caller's auth options into one forwarded object and threads it into all three of sync()'s relay operations: the negentropy negotiation, the internal SEND-direction event() call, and the internal RECEIVE-direction req() call (RAUTH-08) - deletes the dead protected pre-gate waitForAuth() helper (and its now-unused mergeWith import) now that negentropy() no longer calls it https://github.com/hzrd149/applesauce/commit/c6eeb1bcf682f78280e3d13553a71cda21c4b3f7 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ radrootslabs/lib ] studio-runtime: harden composition and concurrency - extract runtime composition, preferences, networking, and persistence into canonical package boundaries - enforce explicit relay policy, bounded work, supervised shutdown, and partial-result semantics - persist restart-stable installation identity and remove panic-prone global initialization races - verify Studio architecture, checks, clippy, runtime, FFI, storage, networking, and restart tests https://github.com/radrootslabs/lib/commit/5d53eb8da344e92453c032609ebef3add0b33fc5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ immrdude/clawstr ] Update README.md https://github.com/immrdude/clawstr/commit/e903dcf3c57987dd8b29959924e1d3ff0e2bfad5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ shocknet/Lightning.Pub ] Merge pull request #1011 from shocknet/fixes fix swap replay +verify swap quote +fix payment refund +fix debit fre… https://github.com/shocknet/Lightning.Pub/commit/b007ef1d11d05fe5b84f702f12dc07a0b75eb511 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ rehansahab/Sparkle-Protocol ] Update README.md https://github.com/rehansahab/Sparkle-Protocol/commit/8549c965d724dfe66ef06f46f9baa6093fbd356e npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ privkeyio/buzz-relay-startos ] Merge pull request #15 from privkeyio/feature/reset-community-action Add reset community action https://github.com/privkeyio/buzz-relay-startos/commit/528dd455cf708cdde1b27c91b74cfd70ae467881 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/nostrsearch ] Bump nostr-archive-cursor: stop rescanning the archive count on every boot 134e7de widens the count-divergence band. RocksDB's key estimate sits ~11% below the true count on an index built by bulk-loading with overwrites, which tripped a 10% band on every start: ~20 minutes of rescanning to confirm an already-correct count, before the server bound its port, and ~29 GB of page cache filled immediately before the process allocates its own working set. https://github.com/v0l/nostrsearch/commit/d3f6aea74779406dee1b4a90685fb0ac6aff7e35 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ MostroP2P/mostro ] feat: add Nostr trusted-node price provider (#697) (#841) * feat: add Nostr trusted-node price provider (#697) Lets mostrod source BTC/fiat quotes by subscribing to kind-30078 rate events from trusted Mostro nodes over Nostr instead of an HTTP API, for operators in regions where price APIs are network-blocked (e.g. Yadio DNS-blocked in Venezuela/Cuba). Reuses the process-wide Nostr client already connected to [nostr]'s relays; with several trusted_nodes configured, the freshest valid event wins over a cross-node combine. https://github.com/MostroP2P/mostro/commit/a8e923bb28492c1d4606906db51b37b3938c5b09 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ rehansahab/Sparkle-Protocol ] Update README.md https://github.com/rehansahab/Sparkle-Protocol/commit/bcf6eb90bd7185f6e994858637ef2f90cb3f3c9e npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] streams: a reaction is chat too, and ours threw every one of them away The live-chat handler opened with `if (ev.kind !== 1311) return`. Reactions to a stream are kind 7 addressed to the SAME `a` coordinate, so every one — ours and every other NIP-53 client's — was subscribed for, matched, delivered and then dropped on the floor. shosho and zap.stream showed a busy room; ours looked dead. On most streams reactions are the bulk of what viewers send. Kind 7 now renders in the room, dimmed, so a burst of 🤙 reads as background rather than shouting over people typing. NIP-25 spelling is honoured: "+" is a https://github.com/loblawbob873-svg/posterchanai/commit/ebb433626735a674a390b3041c527f8e197f5a65 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zapcooking/frontend ] Merge pull request #618 from dmnyc/fix/post-engagement-drawer-layout fix(posts): simplify engagement drawer layout https://github.com/zapcooking/frontend/commit/5932a44594f931bd440e277ac3d6fef6d3502a26 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ papiche/UPassport ] refactor(templates/youtube.html): déplace la logique de connexion vers uplanet-header.js https://github.com/papiche/UPassport/commit/e5c4fba7b583692a0e9ca3d2aef8793b889bebb9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ vitorpamplona/amethyst ] Merge PR: ci: publish windows-arm64 desktop + windows amy/geode release assets Merges nostr proposal 3ac62492 (v2) into main: - ci: publish windows-arm64 desktop + windows amy/geode release assets - ci(release): build windows-arm64 desktop as a portable zip only Extends the release matrix to Windows on Arm using the free public-repo windows-11-arm runner, and adds Windows legs (x64 + arm64) to build-cli and build-geode. amyImage / geodeImage now emit both a POSIX launcher and a .bat launcher so the flat image layout is uniform regardless of build host; https://github.com/vitorpamplona/amethyst/commit/372964194d2b04badbcc35084bdcf40978d37121 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] client: a quote is not a reply, so stop showing the quoted note twice isReply was `ev.kind===1 && ev.tags.some(t => t[0]==='e')` — ANY e-tag means a reply. NIP-10 gives an e-tag a MARKER, and `mention` means "I am pointing at this note", not "I am answering it". So a quote post made the older way (an e-tag marked `mention` plus the inline nostr:nevent) was classified as a reply, and feedNoteHtml put a "↩ replying to …" header above it — while the body embedded that SAME note again as a quote card. The referenced note appeared twice in one card. Plenty of clients still quote https://github.com/loblawbob873-svg/posterchanai/commit/f3bb1f9e97813d953167f5edef73f4185cb24d36 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ arbadacarbaYK/gittr ] fix: harden file fetch, GRASP path clones, and relay discovery docs Prefer real clone hosts over inferred git.gittr.space, parse /grasp/npub/repo URLs, and document Pyramid tag limits for NIP-65 operator lists. https://github.com/arbadacarbaYK/gittr/commit/2e46f11478e8dc08967586b4fdafbdf48e30090b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ immrdude/clawstr ] Update README.md https://github.com/immrdude/clawstr/commit/44dbc8a4653d8eb483e834ebf5bc2e4fcdbdcae5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ nogringo/nostr-mail-client ] refactor(ui): open dialogs and sheets with Flutter instead of GetX Replace Get.dialog/Get.back with showDialog/Navigator.pop and Get.bottomSheet with showModalBottomSheet, passing BuildContext down to the call sites instead of reading Get.context!. https://github.com/nogringo/nostr-mail-client/commit/e4e7b51d88a2df3ccbe0006fa14a5a029029f9b2 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ rehansahab/Sparkle-Protocol ] Update README.md https://github.com/rehansahab/Sparkle-Protocol/commit/c8dfac4d766b3cd38992161eb5565ba9eebff056 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ privkeyio/buzz-relay-startos ] Merge pull request #14 from privkeyio/feature/startos-diagnostics-action Add diagnostics action surfacing community connection state https://github.com/privkeyio/buzz-relay-startos/commit/9cd9b03629048bf9907d5c4cf9e8e4bbf63b07a9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ ptrio42/nostrich-love ] Merge branch 'seo/entity-and-linking' Six commits from an SEO audit and a follow-up adversarial sweep. 118 files, +3257/−1330. The audit's headline finding stands and is worth stating up front: **the real bottleneck is links and domain age**, not on-page work. First commit 2026-02-12, one directory listing and it carries `rel="nofollow"`. Nothing here manufactures authority — it makes the site legible to crawlers, fixes several things that were plainly broken, and removes the excuses. The distribution work is separate and mostly not code. --- ## 1. Entity graph, crawlable locale links, query-matched homepage (`5f37169`) https://github.com/ptrio42/nostrich-love/commit/0cdf59a5417560ec3dd3adc1572d5ab033ec5988 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ vitorpamplona/amethyst ] Merge pull request #3867 from vitorpamplona/l10n_crowdin_translations New Crowdin Translations https://github.com/vitorpamplona/amethyst/commit/fdbad9396fee9e5dbbe76c65520571e7b37cc1e3 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] Merge branch 'security/hardening-batch' https://github.com/athlon-misa/openfederation-pds/commit/e230d715a0a465b23c430d1054ffb227fb68a582 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ areebahmeddd/airhop ] feat: enhance NostrClient relay handling and settings - Introduced tests for NostrClient relay targeting to ensure custom relays are contacted alongside geo-discovered relays. - Updated geo-relay logic to maintain a consistent ceiling for custom relays, preventing silent drops when geo-relay discovery is enabled. - Improved user interface in the Channel Info Sheet and Network Settings to display active relays, including custom ones. - Added functionality to manage custom relay limits, ensuring users cannot exceed the maximum allowed. - Enhanced localization strings for better clarity on relay functionalities and settings. https://github.com/areebahmeddd/airhop/commit/e1f2e625a573446f9105e4217a4e40f05f2a834f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ protolayer-io/choke ] Merge pull request #177 from protolayer-io/docs/play-store-and-demo docs: add Play Store badge and demo video https://github.com/protolayer-io/choke/commit/c5af487e206810303cb85d7d49a819d9db1a4a1b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zig-nostr/website ] Use the right four shots on the signer page (#9) The page carried four plain window captures. The set that was made for it is the hero card and its three panels, each naming the claim the screen underneath it proves. A picture of a window says what the app looks like; these say what it is for. The old four are gone rather than kept alongside, and the panels stack below 640px: a 1000x1400 card at a third of a phone's width is unreadable. https://github.com/zig-nostr/website/commit/e42be4ffe89abd4f30595cba50e7dd60046f6ab2 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ immrdude/clawstr ] Update README.md https://github.com/immrdude/clawstr/commit/6427aed56d523ef41033310b4573ffaf0289471b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ radrootslabs/lib ] docs: update README.md https://github.com/radrootslabs/lib/commit/59dc0c7f517237f668b4ca1ede9d5cbc511d879d npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ geyserfund/geyser-app ] Create SECURITY.md with security policy details Added a comprehensive security policy outlining reporting procedures, supported versions, and guidelines for responsible vulnerability research. https://github.com/geyserfund/geyser-app/commit/60b39d832a153804bc5a52b55f5944bf6365227c npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] streams: never hand out a recording whose bytes are gone A StreamVOD row outlives its bytes in two ordinary ways: the streamer deletes the recording (nothing removes the row) and an upload that never stored the blob still indexes one. Measured on the live node: 43 rows for one publish token, 42 of them pointing at a blob that no longer exists. That is not cosmetic. The client picks a recording out of this list and STAMPS it onto the NIP-53 `recording` tag, so a dead row becomes a permanent dead replay link in every other Nostr client — which is exactly how four broadcasts ended up advertising a 404 to shosho. https://github.com/loblawbob873-svg/posterchanai/commit/8f6b042abac4eb933abf68d10d25f451f320ea39 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ privkeyio/website ] Count bundled sub-PRs in per-category contribution totals (#42) https://github.com/privkeyio/website/commit/1ffa2a998b31267ff5d9df8b5979393a14670610 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ ZeusLN/zeus ] Merge pull request #4338 from kaloudis/fix/theme-placeholder-contrast ui: Themes: distinguish placeholders from input text https://github.com/ZeusLN/zeus/commit/4e3e0e3a22dd8ca844ea0ad0a4599ff87ef9ac7b npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ vitorpamplona/amethyst ] Merge pull request #3861 from vitorpamplona/l10n_crowdin_translations New Crowdin Translations https://github.com/vitorpamplona/amethyst/commit/9373c0a22c665acb3215a473bd9f7066f2832d20 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ immrdude/clawstr ] Update README.md https://github.com/immrdude/clawstr/commit/f3c3f8e7e2ba27a4f5c7a48f044ca60140d62ed5 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Brostr/bro ] merge: migracao completa para Brostr/bro https://github.com/Brostr/bro/commit/29a8589e3cd72d5a5ee05e08129c848f2f63d58a npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ rehansahab/Sparkle-Protocol ] Update README.md https://github.com/rehansahab/Sparkle-Protocol/commit/f003a2fbe1269e3a6f3f4d9ffa30acbc921972d9 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Trustroots/nostroots ] Add verified HTTPS onboarding links (#289) Co-authored-by: K <[email protected] > https://github.com/Trustroots/nostroots/commit/7e97aa55c7274e2340d5e571001b08d4ea1a7dc6 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ zeSchlausKwab/wavefunc ] Merge pull request #10 from zeSchlausKwab/codex/mobile-signal-release-0.1.10 fix: polish mobile player and signal charts https://github.com/zeSchlausKwab/wavefunc/commit/afd2121162ed1721373568bb2864fc1b8c799953 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ hzrd149/applesauce ] docs: create milestone v1.2 roadmap (3 phases) https://github.com/hzrd149/applesauce/commit/79910385dec17f4ab1b928a851242bfdef79f461 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ Lokuyow/ehagaki ] Merge pull request #57 from Lokuyow/revert/npm-audit-fix revert: undo npm audit lockfile rewrite https://github.com/Lokuyow/ehagaki/commit/adbcb41900066dbb7ba0694526a47af0e5ffadda npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ NickAiNYC/payphone ] build: harden the agent image against the Ubuntu archive race CI's docker-build failed on: E: Failed to fetch .../linux-libc-dev_5.15.0-187.197_amd64.deb 404 Not Found Not a code failure. The build pulled ~265 MB over 1m52s, long enough for Ubuntu to supersede a package mid-download, leaving apt to 404 on a filename it had just read as current. https://github.com/NickAiNYC/payphone/commit/27e1496344811af3f60c2d2a024015be11e58d47 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ threenine/diogel ] chore(repo): update CODEOWNERS to include @garywoodfine https://github.com/threenine/diogel/commit/c359b0e5ec8726f559632f9b24e7820e9dacd50c npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ vitorpamplona/amethyst ] Merge pull request #3860 from vitorpamplona/claude/bridge-relay-url-parsing-okxtyw Fix URL detection to exclude quotes from parsed URLs https://github.com/vitorpamplona/amethyst/commit/e822911d09b365e6c53c256cf48d6752e444c9ac npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ v0l/nostrsearch ] Bump nostr-archive-cursor: split the 149 GB shard across readers c111662 cuts large framed archives on frame boundaries so they can be read concurrently. The backfill parallelises across files, so once the other 327 shards finished, the 149 GB combined shard ran alone on one thread doing decompress, parse, dedupe, fold and index end to end -- 2.9 MB/s, with 13.6 hours projected for that file and a second pass still to come. https://github.com/v0l/nostrsearch/commit/6c5263b03cb06a7d79b5be2c52b45307af2afd9e npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ LNVPS/api ] feat(marketplace): node registration with node-scoped tokens and a pinned TLS fingerprint (#360) * feat(marketplace): node registration with a pinned TLS fingerprint Increment 3a. Operators can register hardware, and re-register it after its certificate changes. Registration is authenticated as the **operator's** account and carries the node's own identity in the body, rather than being signed by the node. The schema forced the question: `marketplace_node.nostr_pubkey` is unique per node https://github.com/LNVPS/api/commit/66e7a94f03477f875da887a3abb1029c7df4d5f3 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ WalletScrutiny/WalletScrutinyCom ] Merge branch 'security_improvements' into 'master' Multiple fixes for xss and other minor code problems See merge request walletscrutiny/walletScrutinyCom!1603 https://github.com/WalletScrutiny/WalletScrutinyCom/commit/6ef33d13ae82c173508fd3339e37030ef0ff3beb npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ athlon-misa/openfederation-pds ] fix: require proof for external key claims (#187) https://github.com/athlon-misa/openfederation-pds/commit/4d1540ed406d3d3032ba0613beb5cc8fce3b5ce3 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ loblawbob873-svg/posterchanai ] bookmarks: back out the pacing/tidy patch Reverts f912d376. That work was restored here from a saved diff to get it off this machine; the desktop is the one actually carrying extension/*.js forward, and leaving two versions of the same pacing and duplicate-tidy changes in the same three files buys nothing but a merge conflict. extension/ goes back to bf78a2a5 exactly, so the desktop's push lands on a clean base. Co-Authored-By: Claude Opus 5 <[email protected] > https://github.com/loblawbob873-svg/posterchanai/commit/2eb40f2c388a26a26c7bcde5f368dde770f25017 npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ MostroP2P/mostro-core ] Merge pull request #160 from MostroP2P/feat/chat-kind14-envelope feat(chat): gift-wrap-free kind 14 envelope (K_conv / K_sign) https://github.com/MostroP2P/mostro-core/commit/f2f4480ccf1374076985547b6f82c630d359bd9f npub10l479fv64qn03a3n0dqsryu74tyzl48xef0nc7u0z09q8tfx72ls7sv2ux nostr-summary [ PR0M3TH3AN/bitlogin ] Relay lists: drop a relay that cannot accept writes, widen for margin Measured every candidate on 2026-08-05 against its own NIP-11 document and over a real socket, three runs each. nostr.wine advertises payment_required AND restricted_writes, so it can never accept a free user's capsule -- yet it held one of five slots in BUILTIN_VAULT_RELAYS, the list capsules are PUBLISHED to. relay.damus.io and relay.nostr.band were unreachable 3/3 from the machine under test. That left two usable relays against publishAndVerify's floor of two https://github.com/PR0M3TH3AN/bitlogin/commit/5aa7d9ca153d0e9dbdb8c5fd379c29d8be0abdc9