docs(keychain): update keychain docs for the 2.0.0 release - #2224
Conversation
Covers four languages, the OtterSec audit, capability-split signers, Fordefi's three modes, Crossmint as sending-only and the Ledger backend. Adds Python and Go getting-started pages, fixes snippets that no longer compile against 2.0, and bumps the cookbook example to keychain-memory 2.0.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
5 Skipped Deployments
|
amilz
left a comment
There was a problem hiding this comment.
LGTM: docs-only refresh of Keychain docs for 2.0.0 (Python/Go pages, capability traits, Fordefi modes, Ledger, OtterSec audit). Before merging: publish @solana/keychain-memory 2.0.0 (npm currently has only 2.0.0-beta.1) and refresh pnpm-lock.yaml; every lint/test failure comes from ERR_PNPM_OUTDATED_LOCKFILE.
Refresh the lockfile for the published 2.0.0 and exempt the two keychain packages from the minimum release age. Also reword two keychain page descriptions whose colons broke YAML frontmatter parsing.
|
Problem
The Keychain docs under
/docs/tools/keychaindescribe the 1.x library: Rust and TypeScript only, a singleSolanaSignertrait, two Fordefi modes and the Accretion audit. solana-keychain 2.0.0 adds Python and Go at parity, splits signers into capability traits, makes Crossmint sending-only, gives Fordefi three modes, adds a Rust-only Ledger backend and ships after an OtterSec audit of all four languages. Many snippets no longer compile against 2.0.Summary of Changes
tools/keychain/index.mdx: four languages, OtterSec audit with Ledger out of scope, Python and Go columns and a Ledger row in the backend table, fixed Rust quick start, Python and Go quick starts, links to the security model and migration guide.getting-started/python.mdxandgetting-started/go.mdx, modeled on the Rust and TypeScript pages and added to the sidebar.getting-started/rust.mdxandgetting-started/typescript.mdx: snippets fixed against 2.0, capability sections, missing backends (Openfort, Utila, Ledger in Rust; Memory, GCP KMS, Openfort, Utila in TS), Fordefi's three modes,BROADCAST_UNCONFIRMEDhandling.choosing-a-backend.mdxandproduction-best-practices.mdx: capability caveat on swapping backends, Ledger row,kms:GetPublicKey, no blind retries on broadcasting backends, a section on unconfirmed broadcasts.adding-signers.mdx: updated in place for 2.0 (capability traits, message-byte signing with verification,_remotefeature, seven umbrella touchpoints), plus Python, Go and security requirement sections.payments/developer-tools,tools/production-readiness,core/transactions/signing-in-production,clients/official/rustandclients/official/javascript; Python and Go SDK table rows.sign-with-keychainsoftened for sending and modifying backends;@solana/keychain-memorybumped to^2.0.0.English only; translations follow through the Lingo workflow.
Lockfile refreshed against the published
@solana/keychain-memoryand@solana/keychain-core2.0.0, both added tominimumReleaseAgeExcludesince they are newer than the age cutoff. Two page descriptions also lost their colons, which broke YAML frontmatter parsing infumadocs-mdx.Fixes # n/a
Change classification (SDLC §2)
security gates, or anything that changes who can do what
changes, dependency updates, monitoring/config)
Security checklist
(use Doppler /
NEXT_PUBLIC_*only for values safe to ship to thebrowser).
dangerouslySetInnerHTML/ unsanitized HTML on untrusted input.pnpm auditpasses (no new High/Critical advisories).
included below, and a second reviewer has been requested.
New dependencies: none. Updated:
@solana/keychain-memory^1.4.0 to ^2.0.0 inpackages/docs-examples, to match the docs;pnpm auditreports no advisories on any keychain path.Threat-model note: n/a