• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

ProjectOpenSea / seadrop
65%

Build:
DEFAULT BRANCH: main
Repo Added 26 Oct 2022 05:15PM UTC
Token t3xS0duxYjh8yblsYU5vgRsrPy0qT0CS5 regen
Build 252 Last
Files 24
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH main
branch: SELECT
CHANGE BRANCH
x
Sync Branches
  • No branch selected
  • add-clone-factory
  • add-clone-factory-test
  • bbonelli/update_readme
  • bool
  • chore/dependency-bumps
  • chore/pr-template-comment
  • dependabot/npm_and_yarn/base-x-3.0.11
  • dependabot/npm_and_yarn/brace-expansion-2.0.2
  • dependabot/npm_and_yarn/brace-expansion-2.0.3
  • dependabot/npm_and_yarn/brace-expansion-2.1.2
  • dependabot/npm_and_yarn/brace-expansion-2.1.4
  • dependabot/npm_and_yarn/browserify-sign-4.2.2
  • dependabot/npm_and_yarn/cacheable-request-10.2.7
  • dependabot/npm_and_yarn/decode-uri-component-0.2.2
  • dependabot/npm_and_yarn/es5-ext-0.10.63
  • dependabot/npm_and_yarn/express-4.19.2
  • dependabot/npm_and_yarn/express-4.21.0
  • dependabot/npm_and_yarn/follow-redirects-1.15.4
  • dependabot/npm_and_yarn/follow-redirects-1.15.6
  • dependabot/npm_and_yarn/follow-redirects-1.16.0
  • dependabot/npm_and_yarn/get-func-name-2.0.2
  • dependabot/npm_and_yarn/handlebars-4.7.9
  • dependabot/npm_and_yarn/http-cache-semantics-4.1.1
  • dependabot/npm_and_yarn/immutable-4.3.8
  • dependabot/npm_and_yarn/immutable-4.3.9
  • dependabot/npm_and_yarn/pbkdf2-3.1.6
  • dependabot/npm_and_yarn/picomatch-2.3.2
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/base-x-3.0.11
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/braces-3.0.3
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/cipher-base-1.0.6
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/crypto-js-and-merkletreejs-4.2.0
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/ejs-3.1.10
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/express-4.19.2
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/flatted-3.4.2
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/follow-redirects-1.15.4
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/follow-redirects-1.15.6
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/follow-redirects-1.16.0
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/handlebars-4.7.9
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/http-cache-semantics-4.1.1
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/immutable-4.3.9
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/lodash-4.18.1
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/min-document-2.19.2
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/multi-092c445592
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/multi-367a355db9
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/multi-41ee8087b2
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/multi-456de2e4f1
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/multi-6b8e89be61
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/pbkdf2-3.1.3
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/pbkdf2-3.1.5
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/picomatch-2.3.2
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/sha.js-2.4.12
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/undici-5.19.1
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/undici-5.28.3
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/undici-5.28.4
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/undici-5.28.5
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/word-wrap-1.2.4
  • dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/word-wrap-1.2.5
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/ERC721A/cookiejar-and-cookiejar-2.1.4
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/ERC721A/decode-uri-component-0.2.2
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/ERC721A/loader-utils-1.4.2
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/ERC721A/qs-and-body-parser-and-express-and-body-parser-and-express-6.11.0
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/openzeppelin-contracts/cookiejar-2.1.4
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/openzeppelin-contracts/decode-uri-component-0.2.2
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/openzeppelin-contracts/glob-parent-5.1.2
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/openzeppelin-contracts/got-and-truffle/interface-adapter-and-truffle/contract-and-solidity-coverage-12.1.0
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/openzeppelin-contracts/json5-1.0.2
  • dependabot/npm_and_yarn/src-upgradeable/lib/utility-contracts/lib/solmate/ansi-regex-5.0.1
  • dependabot/npm_and_yarn/underscore-1.13.8
  • dependabot/npm_and_yarn/undici-5.19.1
  • dependabot/npm_and_yarn/undici-5.21.0
  • dependabot/npm_and_yarn/undici-5.26.3
  • dependabot/npm_and_yarn/undici-5.28.3
  • dependabot/npm_and_yarn/undici-5.28.4
  • dependabot/npm_and_yarn/undici-5.29.0
  • dependabot/npm_and_yarn/word-wrap-1.2.4
  • dependabot/npm_and_yarn/yaml-2.2.2
  • erc721seadrop-tokenuri-override
  • fix/forge-ci-submodule-refs
  • main
  • michael/non-partner-extensions
  • minimatch
  • multiConfigure
  • redundant-sload
  • refs/pull/94/merge
  • refs/pull/98/merge
  • roy/update-hardhat
  • roy/v2
  • ryan/add-eip-2981
  • ryan/fix-allow-upgradeable-and-partner-to-use-multiconfigure
  • ryan/fix-proxy-addresses
  • ryan/fix-upgradeable
  • ryan/v1-transfer-validator
  • ryan/v2-transfer-validator
  • scottiepippen
  • scottiepippensp33
  • syl/abs
  • tokenURI_in_upgradable_proxy
  • v2

24 Aug 2026 04:25PM UTC coverage: 64.702%. Remained the same
32750728560

push

github

web-flow
chore(deps): bundle the five open dependabot lockfile bumps (#176)

## Motivation

Five open dependabot PRs, all lockfile-only transitive bumps, all
currently red because they were branched before the Forge CI fix in
#175. They also all edit the same two lockfiles, so merging them one at
a time forces the rest to rebase and burns a CI run each time.

Bundling them means one review and one CI run instead of five.

Supersedes #168, #169, #170, #171 and #172. Dependabot's commits are
cherry-picked unchanged, so authorship and the advisory trail are
preserved.

| PR | Bump | Advisory |
| --- | --- | --- |
| #172 | brace-expansion 2.0.1 to 2.1.4 | GHSA-mh99-v99m-4gvg,
CVE-2026-13149 (ReDoS) |
| #170 | pbkdf2 3.1.2 to 3.1.6 | CVE-2025-6545, CVE-2025-6547
(predictable key material) |
| #168 | immutable 4.1.0 to 4.3.9 | GHSA-v56q-mh7h-f735,
GHSA-xvcm-6775-5m9r, CVE-2026-29063 |
| #169 | immutable 4.1.0 to 4.3.9, vendored OZ copy | as above |
| #171 | min-document 2.19.0 to 2.19.2, vendored OZ copy | transitive |

## Solution

Two files change and both are lockfiles. No `package.json`, no contract
source, no submodule.

None of these five packages appears in this repo's `dependencies` or
`devDependencies`, so every one is transitive. `yarn.lock` is not
published to npm, so no consumer of the package is affected. The
Solidity dependencies come from the git submodules in `.gitmodules`
rather than npm, so the contracts are untouched.


`src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/package-lock.json`
is a vendored copy of OpenZeppelin, not a submodule, and nothing in the
build reads that lockfile. Those two entries (#169 and #171) are inert,
and are included here to close out the queue rather than because they
change behavior.

## Verification

Resolved versions after bundling:

```
yarn.lock          brace-expansion 2.1.4   pbkdf2 3.1.6   immutable 4.3.9
vendored OZ lock   immutable 4.3.9         min-document 2.19.2
```

All five c... (continued)

284 of 605 branches covered (46.94%)

Branch coverage included in aggregate %.

693 of 905 relevant lines covered (76.57%)

722.06 hits per line

Relevant lines Covered
Build:
Build:
905 RELEVANT LINES 693 COVERED LINES
722.06 HITS PER LINE
Source Files on main
  • Tree
  • List 24
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
32750728560 main chore(deps): bundle the five open dependabot lockfile bumps (#176) ## Motivation Five open dependabot PRs, all lockfile-only transitive bumps, all currently red because they were branched before the Forge CI fix in #175. They also all edit the s... push 24 Aug 2026 04:27PM UTC web-flow github
64.7
32750560607 chore/dependency-bumps Merge 8b9d615a6 into 454c9f8da Pull #176 24 Aug 2026 04:24PM UTC web-flow github
64.7
32604884141 main fix(ci): stop pinning submodules to tags via `branch` (#175) ## Motivation Both Forge jobs in Test CI fail on the "Install forge dependencies" step, before any contract compiles: ``` Updating dependencies in /home/runner/work/seadrop/seadrop/li... push 22 Aug 2026 11:20PM UTC web-flow github
64.7
32604609308 fix/forge-ci-submodule-refs Merge 77f369e3d into fd6e01dfc Pull #175 22 Aug 2026 11:13PM UTC web-flow github
64.7
32601947829 main docs: point security reports at Bugcrowd in the PR template (#174) ## Motivation The template already keeps its guidance inside HTML comments, so none of it leaks into contributor PR bodies. What it does not say is where to send a security repor... push 22 Aug 2026 10:17PM UTC web-flow github
53.43
32599153900 chore/pr-template-comment Merge dd159c5dc into 6ab8b2ce1 Pull #174 22 Aug 2026 09:20PM UTC web-flow github
53.43
30667514600 dependabot/npm_and_yarn/brace-expansion-2.1.4 Merge e7636a117 into 6ab8b2ce1 Pull #172 31 Jul 2026 09:44PM UTC web-flow github
53.43
30359433607 dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/min-document-2.19.2 Merge 986abb12a into 6ab8b2ce1 Pull #171 28 Jul 2026 12:35PM UTC web-flow github
53.43
30355954891 dependabot/npm_and_yarn/pbkdf2-3.1.6 Merge 7a950a17d into 6ab8b2ce1 Pull #170 28 Jul 2026 11:45AM UTC web-flow github
53.43
30148255474 dependabot/npm_and_yarn/src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/immutable-4.3.9 Merge 04577ccf8 into 6ab8b2ce1 Pull #169 25 Jul 2026 06:54AM UTC web-flow github
53.43
See All Builds (188)

Badge your Repo: seadrop

We detected this repo isn’t badged! Grab the embed code to the right, add it to your repo to show off your code coverage, and when the badge is live hit the refresh button to remove this message.

Could not find badge in README.

Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

Refresh
  • Settings
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc