Skip to content

Generated SDK #2917861426 (major) - #212

Merged
sdk-generation-automation[bot] merged 1 commit into
masterfrom
fireblocks-api-spec/generated/2917861426
Oct 7, 2026
Merged

sdk-generation-automation[bot] merged 1 commit into
masterfrom
fireblocks-api-spec/generated/2917861426

Conversation

@sdk-generation-automation

Copy link
Copy Markdown
Contributor

Changelog

2026-10-06

Breaking Change

Group Tempo transfers under Tempo (Beta)

Products: Tempo (Beta)

Scope: API + SDKs

  • What's new
    Tempo transfer operations are now grouped under a dedicated Tempo (Beta) product category instead of being listed with Transactions (Beta).

  • Impact
    SDK users will find Tempo transfers on a dedicated Tempo client rather than the transactions client, while direct API calls are unaffected.

Affected endpoints:

  1. Create a Tempo transfer transaction

Transfer withdraw moves to offer responses

Products: Canton (Beta)

Scope: API + SDKs

  • What's new
    Withdrawing a Canton transfer is now done by answering the offer instead of submitting a Canton call.

  • Impact
    Existing integrations that withdraw Canton transfers through the calls endpoint will stop working.

Affected endpoints:

  1. Make a Canton call

Canton call payloads now use blockchainId

Products: Canton (Beta)

Scope: API + SDKs

  • What's new
    Canton call payloads now identify the chain with a required blockchainId field in place of asset.

  • Impact
    Existing integrations sending asset on Canton calls will receive a validation error.

Affected endpoints:

  1. Make a Canton call

Simplify Canton offer response format (beta)

Products: Canton (Beta)

Scope: API + SDKs

  • What's new
    Answering a Canton offer now takes a single response type plus its arguments, instead of nesting the response inside a domain wrapper.

  • Impact
    Existing integrations that answer Canton offers will be rejected until they send the new body shape.

Affected endpoints:

  1. Answer an offer

Approval API keys support pending approval state

Products: Approvals (Beta)

Scope: API + SDKs

  • What's new
    Registering or removing an approval API key can now require approval, and each key now reports a status of pending registration, enabled, or pending deletion.

  • Impact
    Integrations that manage approval API keys must handle keys that are awaiting approval, and the key removal response now returns a body identifying the pending approval request.

Affected endpoints:

  1. Register an approval key
  2. Delete an approval key

Added

Add Tempo omnibus wallet registration

Products: Vaults

Scope: API + SDKs

  • What's new
    Adds a new endpoint that registers a Tempo omnibus wallet for a given vault account and Tempo network asset.

  • Impact
    Customers can now register Tempo omnibus wallets programmatically; this is an additive change, so existing integrations continue to work unchanged.

Affected endpoints:

  1. Register a Tempo omnibus wallet

Changed

Document gas funding for Tempo omnibus

Products: Vaults

Scope: API + SDKs

  • What's new
    Tempo omnibus wallet registration now documents that the vault account must hold a PATH_USD balance sufficient to cover the gas fee.

  • Impact
    Customers know upfront that the vault account needs funded gas before registration can succeed, avoiding unexpected failures.

Affected endpoints:

  1. Register a Tempo omnibus wallet

Clarify console user deletion errors (beta)

Products: Console User

Scope: API + SDKs

  • What's new
    Deleting a console user now returns a distinct bad-request error when the supplied ID belongs to an API user rather than a console user, and Security Admin keys are now permitted to perform the deletion.

  • Impact
    Customers targeting the wrong user type receive a clear failure reason instead of a not-found response, and workspaces using Security Admin keys can now delete console users.

Affected endpoints:

  1. Request deletion of a console user

@github-actions github-actions Bot added the major label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thanks for submitting this request. We'll review it and provide updates soon. (Note that this SDK code is auto generated)

@socket-security

socket-security Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.2.tgz",
"integrity": "sha512-UQ+MSxlhRm1bzjhU+DcuXfjFO1FzNtqhK5+9Yvlp90ItDLk5vT932A0rFu619nf7RVS+Y/VeaUW1jaRDqZ8VJw==",
"version": "1.3.3",
"resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.3.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.3.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/update-browserslist-db/-/update-browserslist-db-1.3.3.tgz",
"resolved": "https://fbinfra555artifactory.jfrog.io/artifactory/api/npm/fireblocks-npm/update-browserslist-db/-/update-browserslist-db-1.3.3.tgz",
View step-by-step instructions
  1. Configure the project .npmrc to use the approved internal Artifactory registry: registry=https://fbinfra555artifactory.jfrog.io/artifactory/api/npm/fireblocks-npm/.
  2. Configure authentication through your approved npm credential mechanism, such as an environment variable or user-level npm configuration; do not store tokens in the repository.
  3. Remove the existing dependency artifacts so npm does not preserve public registry URLs: $ rm -rf node_modules package-lock.json.
  4. Regenerate the dependency tree through Artifactory: $ npm install.
  5. Confirm the regenerated package-lock.json resolves update-browserslist-db and all other packages through the approved Artifactory URL rather than registry.npmjs.org.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SocketSecurity ignore npm/update-browserslist-db@1.3.3

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.425.tgz",
"integrity": "sha512-QvPtl41EUOnuT1HBvMKgxXRIaHNcagBPs50u7VULzhZXaGfqTbZyE16LQsctZ/RQHlGu+FOWeDTR4mY6YbeF1g==",
"version": "1.5.429",
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.429.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.429.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.429.tgz",
"resolved": "<VERIFIED_VALUE_REQUIRED>",
View step-by-step instructions
  1. Create or update the project .npmrc with the approved internal Artifactory registry, replacing the example URL with the exact URL provided by your organization: registry=https://example.com/artifactory/api/npm/npm-virtual/.
  2. Configure Artifactory authentication through your approved credential helper, environment variables, or user-level npm configuration. Do not commit access tokens or passwords to .npmrc.
  3. Remove the existing dependency artifacts so npm does not preserve public registry URLs: $ rm -rf node_modules package-lock.json.
  4. Regenerate the dependency tree using the configured registry: $ npm install.
  5. Confirm that package-lock.json now contains Artifactory URLs for resolved package entries, including electron-to-chromium, and no longer references https://registry.npmjs.org/ or another public registry.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@SocketSecurity ignore npm/electron-to-chromium@1.5.429

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.28.9.tgz",
"integrity": "sha512-EWazOblFYUvlGZcfGhPUPmYh3nikUxBVb+y9MJun5f3hBi812X+8MSQTujLBtgK3cf51fJWbWfOjyeO954d+Eg==",
"version": "4.29.0",
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.29.0.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/browserslist/-/browserslist-4.29.0.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/browserslist/-/browserslist-4.29.0.tgz",
"resolved": "https://<VERIFIED_VALUE_REQUIRED>/artifactory/api/npm/<VERIFIED_VALUE_REQUIRED>/browserslist/-/browserslist-4.29.0.tgz",
View step-by-step instructions
  1. Configure the project’s .npmrc to use the approved internal JFrog/Artifactory npm registry, for example registry=https://example.com/artifactory/api/npm/<approved-repository>/.
  2. Remove the existing dependency artifacts so npm does not reuse public registry URLs: $ rm -rf node_modules package-lock.json.
  3. Regenerate the dependency lockfile with the internal registry configured: $ npm install.
  4. Confirm the resolved entry for browserslist uses the approved internal Artifactory host instead of https://registry.npmjs.org, while preserving the package version and integrity value. Regenerating the lockfile updates transitive dependencies in the same way.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@SocketSecurity ignore npm/browserslist@4.29.0

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.20.tgz",
"integrity": "sha512-5/qk29RyvatwgzNMrvGjkIhKYzpJ0OUnPK+9TU+zS/CMJqzmb+UD0irWu42JfpUvO636fxd8IstgiydZRM/76A==",
"version": "1.1.21",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.21.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.21.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.21.tgz",
"resolved": "<VERIFIED_VALUE_REQUIRED>",
View step-by-step instructions
  1. Set the project registry in .npmrc to the approved internal JFrog/Artifactory npm registry, for example registry=https://example.com/artifactory/api/npm/npm-virtual/. Use the exact registry URL provided by your organization.
  2. Configure registry authentication through your standard credential mechanism, such as npm login or an environment variable; do not add tokens or passwords to .npmrc committed to the repository.
  3. Remove the existing dependency installation and lockfile: $ rm -rf node_modules package-lock.json
  4. Regenerate both from the internal registry: $ npm install
  5. Confirm that package-lock.json contains resolved URLs for the approved internal registry instead of public hosts such as registry.npmjs.org.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SocketSecurity ignore npm/brace-expansion@1.1.21

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.21.tgz",
"integrity": "sha512-uh8vpY/1/YyFkunIDFH/12p7/7VdPKA1hejMVEbdkEaWnUz0Hesvx5EbiU6XxjyHZIOju+ZMbQJkRh+es3/spQ==",
"version": "2.11.24",
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.24.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High severity issue identified in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.24.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.24.tgz",
"resolved": "<VERIFIED_VALUE_REQUIRED>/baseline-browser-mapping/-/baseline-browser-mapping-2.11.24.tgz",
View step-by-step instructions
  1. Update .npmrc to use the approved internal JFrog/Artifactory npm registry, for example registry=<approved-internal-artifactory-npm-endpoint>. Configure authentication through the existing secure npm or CI mechanism; do not commit credentials.
  2. Remove the existing dependency installation and lockfile with $ rm -rf node_modules package-lock.json.
  3. Regenerate the lockfile through the internal registry with $ npm install.
  4. Confirm the regenerated package-lock.json uses the approved internal Artifactory URL for baseline-browser-mapping and its transitive dependencies instead of registry.npmjs.org. The existing integrity hashes continue to verify the downloaded package contents.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@SocketSecurity ignore npm/baseline-browser-mapping@2.11.24

@sdk-generation-automation
sdk-generation-automation Bot merged commit f85be10 into master Oct 7, 2026
30 checks passed
@sdk-generation-automation
sdk-generation-automation Bot deleted the fireblocks-api-spec/generated/2917861426 branch October 7, 2026 07:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant