Skip to content

Generated SDK #2850019096 (major) - #209

Merged
sdk-generation-automation[bot] merged 1 commit into
masterfrom
fireblocks-api-spec/generated/2850019096
Sep 15, 2026
Merged

sdk-generation-automation[bot] merged 1 commit into
masterfrom
fireblocks-api-spec/generated/2850019096

Conversation

@sdk-generation-automation

Copy link
Copy Markdown
Contributor

Changelog

2026-09-01

Breaking Change

Fix validBefore/validAfter semantics in TRLink policy rules

Products: Transactions

Scope: API + SDKs

  • What's new
    Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps.

  • Impact
    Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.

Affected endpoints:

  1. Get a specific transaction by external transaction ID
  2. Get a specific transaction by Fireblocks transaction ID
  3. Get transaction history

Fix validBefore/validAfter semantics in TRLink policy rules

Products: TRLink

Scope: API + SDKs

  • What's new
    Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps.

  • Impact
    Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.

Affected endpoints:

  1. Get TRLink policy

Fix validBefore/validAfter semantics in TRLink policy rules

Products: Compliance

Scope: API + SDKs

  • What's new
    Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps.

  • Impact
    Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.

Affected endpoints:

  1. Provides all the compliance details for the given screened transaction.

Remove type field from security finding responses

Products: Security Posture Management

Scope: API + SDKs

  • What's new
    Removes the type field from security finding schemas and updates example data to reflect a different finding scenario.

  • Impact
    Clients should no longer expect the type field in security finding responses and must update any code that depends on this field.

Affected endpoints:

  1. Get a FSPM security finding by ID
  2. Update a FSPM security finding by ID
  3. Get FSPM security findings

Added

Add contacts list endpoint

Products: Contacts

Scope: API + SDKs

  • What's new
    Adds a paginated endpoint to list workspace address book contacts with filtering by name, type, tags, access control, container, and archive status.

  • Impact
    Customers can programmatically retrieve and filter their address book contacts through the API.

Affected endpoints:

  1. List contacts

Add feeCurrency field for Tempo transactions (beta)

Products: Off exchanges, Transactions

Scope: API + SDKs

  • What's new
    Adds an optional feeCurrency field to the transaction request schema, allowing users to specify which asset to use for paying network fees on Tempo-based transactions.

  • Impact
    Customers using Tempo can now control which asset pays transaction fees.

Affected endpoints:

  1. Create a new transaction
  2. Estimate transaction fee
  3. Add Collateral
  4. Remove Collateral

Add AMOUNT_ABOVE_MAXIMUM failure reason

Products: Trading (Beta)

Scope: API + SDKs

  • What's new
    Adds a new enum value to indicate when a trading operation fails because the requested amount exceeds the maximum allowed limit.

  • Impact
    Customers can now programmatically detect and handle amount-too-large errors in trading operations.

Affected endpoints:

  1. Create an order
  2. Get order details

@github-actions

Copy link
Copy Markdown
Contributor

Your request is important to us. We will look into it shortly. (Note that this SDK code is auto generated)

@github-actions github-actions Bot added the major label Sep 15, 2026
@sdk-generation-automation
sdk-generation-automation Bot merged commit 14f3a55 into master Sep 15, 2026
30 checks passed
@sdk-generation-automation
sdk-generation-automation Bot deleted the fireblocks-api-spec/generated/2850019096 branch September 15, 2026 09:11
Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.410.tgz",
"integrity": "sha512-Vq9DD7F4PKCKVmOoG6i1CQSYoF7IUtwTPEQjMXuqNs2S22H8HsojO9myaB81QuvvIKZaF6imSn3XAV1Su6rvXA==",
"version": "1.5.415",
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.415.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.415.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/electron-to-chromium/-/electron-to-chromium-1.5.415.tgz",
"resolved": "<VERIFIED_VALUE_REQUIRED>",
View step-by-step instructions
  1. Update the project’s .npmrc to use the approved internal JFrog/Artifactory npm registry for all packages, for example registry=<approved-internal-registry-url>. Do not use https://registry.npmjs.org or another public registry.

  2. Remove the existing dependency installation and lockfile so npm can resolve every package through the internal registry:
    $ rm -rf node_modules package-lock.json

  3. Regenerate the dependency tree with the repository’s configured registry:
    $ npm install

  4. Confirm that the regenerated package-lock.json contains no public npm registry or CDN URLs in resolved, registry, or tarball fields. All dependency URLs must point to the approved internal Artifactory registry.

  5. Keep the updated .npmrc and regenerated package-lock.json in the change so future installs use the approved registry.

💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001809.tgz",
"integrity": "sha512-xxWVywk6a6Arlk+hymeycyn/VgqEfLDxupvhH/xiY5SJ/18kmi9o6MiO320DCUzypORHLtvh0I4i04tUhCNHNQ==",
"version": "1.0.30001810",
"resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/caniuse-lite/-/caniuse-lite-1.0.30001810.tgz",
"resolved": "<VERIFIED_VALUE_REQUIRED>",
View step-by-step instructions
  1. Update the project .npmrc to use the approved internal JFrog/Artifactory npm registry, for example registry=https://example.com/artifactory/api/npm/<approved-repository>/. Use the exact registry URL provided by your organization.
  2. Configure registry authentication through your environment or approved credential helper; do not place usernames, passwords, or tokens in .npmrc or source control.
  3. Delete the existing dependency artifacts so npm does not retain public registry URLs: $ rm -rf node_modules package-lock.json
  4. Regenerate the dependency tree using the configured internal registry: $ npm install
  5. Confirm the regenerated package-lock.json contains Artifactory URLs for resolved package tarballs, including caniuse-lite, rather than https://registry.npmjs.org/....
  6. Keep the updated project .npmrc and regenerated package-lock.json in the change so future installs use the approved registry.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz",
"integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==",
"version": "1.1.20",
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.20.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.20.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.20.tgz",
"resolved": "<VERIFIED_VALUE_REQUIRED>/brace-expansion/-/brace-expansion-1.1.20.tgz",
View step-by-step instructions
  1. Configure the project .npmrc to use the approved internal JFrog/Artifactory npm registry, replacing the placeholder with your organization’s registry URL: registry=https://example.com/artifactory/api/npm/<approved-repository>/.
  2. Preserve any required internal authentication settings in .npmrc or the configured credential store; do not add tokens or passwords to the repository.
  3. Remove the existing dependency tree and lockfile: $ rm -rf node_modules package-lock.json.
  4. Regenerate the dependencies through the internal registry: $ npm install.
  5. Confirm that the regenerated package-lock.json uses the approved internal registry for all resolved package URLs, including brace-expansion, balanced-match, and braces, rather than registry.npmjs.org.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.15.tgz",
"integrity": "sha512-FwMjJJ7HnyZpWe+oWxegG0fezZyBZUagI5LZEoO3GCbtbKNwRfMH9Ue5d5v01PNePBy1QSfPSDTTeVL0Hb9EzA==",
"version": "2.11.19",
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.19.tgz",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Semgrep identified an issue in your code:
package-lock.json contains a reference to a public package registry or CDN (https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.19.tgz). Dependencies must be resolved through the approved internal JFrog/Artifactory registry. Update your .npmrc to point at the approved registry, delete node_modules and package-lock.json, then re-run npm install and commit the regenerated lockfile.

To resolve this comment:

✨ Commit fix suggestion

Suggested change
"resolved": "https://registry.npmjs.org/baseline-browser-mapping/-/baseline-browser-mapping-2.11.19.tgz",
"resolved": "<VERIFIED_VALUE_REQUIRED>",
View step-by-step instructions
  1. Add or update the project .npmrc with the approved JFrog/Artifactory registry: registry=https://example.com/artifactory/api/npm/<approved-repository>/. Replace the example URL with the registry URL provided by your organization.
  2. Configure registry authentication through your environment or approved credential helper. Do not commit usernames, passwords, or tokens in .npmrc; reference a variable such as ${NPM_TOKEN} when authentication is required.
  3. Remove the existing dependency installation and lockfile so npm does not retain public registry URLs: $ rm -rf node_modules package-lock.json
  4. Regenerate the dependencies using the configured internal registry: $ npm install
  5. Confirm the regenerated package-lock.json uses the approved Artifactory host for resolved and registry entries, including the baseline-browser-mapping entry. Ensure no registry.npmjs.org or other public registry URLs remain.
💬 Ignore this finding

Reply with Semgrep commands to ignore this finding.

  • /fp <comment> for false positive
  • /ar <comment> for acceptable risk
  • /other <comment> for all other reasons

Alternatively, triage in Semgrep AppSec Platform to ignore the finding created by block-public-registry-refs-in-package-lock.

You can view more details about this finding in the Semgrep AppSec Platform.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants