Package Reference
Caatinga is published as modular TypeScript npm packages under the @caatinga scope.
| Package | Role | Browser-safe | Install command |
|---|---|---|---|
@caatinga/cli |
CLI binary (caatinga / ctg) |
No | npm install -g @caatinga/cli |
@caatinga/core |
Config loading, artifact I/O, Stellar CLI orchestration | No (use ./browser) |
Dependency of @caatinga/cli |
@caatinga/core/browser |
Errors + artifact types only (excludes Node modules) | Yes | Dependency of @caatinga/client |
@caatinga/client |
createCaatingaClient, wallet session, invoke/read/simulate/buildXdr |
Yes | npm install @caatinga/client |
@caatinga/client/react |
WalletProvider + useWallet (React >=18 optional peer) |
Yes | Subpath of @caatinga/client |
@caatinga/client/vite |
SWK bundler helpers: walletStubViteAliases, walletStubOverrides |
Yes | Subpath of @caatinga/client |
@caatinga/client/freighter |
Freighter wallet adapter | Yes | Subpath of @caatinga/client |
@caatinga/client/stellar-wallets-kit |
Multi-wallet adapter (Freighter, xBull, etc.) | Yes | Subpath of @caatinga/client |
@caatinga/zk |
ZK proof serialization, Circom Groth16 helpers | No (use ./browser) |
Dependency of @caatinga/cli |
@caatinga/zk/browser |
Browser ZK binding helpers | Yes | Subpath of @caatinga/zk |
Release & Versioning Policy
- Latest release:
3.10.3(all four packages ship in lockstep).3.10.0was versioned but never published to npm. - Status: v1.0 stable contract on npm major
3.x. Breaking changes to the Tier 1 surface require a major bump and will land on an explicit4.0.0. ZK commands (ctg zk *) are experimental and outside the contract. - Reproducible CI: Pin an exact version (e.g.
@caatinga/cli@3.10.3) rather than floating tags. - Stellar CLI Compatibility: Hard floor 23.0.0; last tested 28.0.0.
@caatinga/clidependency ranges:@caatinga/coreand@caatinga/zk^3.10.3or later, kept aligned with the release group.
3.10.3 highlights
Recommended for anyone targeting mainnet: with the default mainnet config, 3.10.2 and earlier could not reach mainnet at all.
- Mainnet commands use the configured RPC: configs matching the well-known mainnet network were passed to the Stellar CLI as
--network mainnet, whose built-in entry has no RPC URL, so commands failed withInvalid URL Bring Your Own: …(or silently used a locally addedmainnetnetwork). Mainnet now always gets explicit--rpc-url/--network-passphrasefromcaatinga.config.ts. - No implicit
aliceon mainnet:ctg readandctg smokerequire--sourceorCAATINGA_SOURCEon mainnet; otherwise they fail withCAATINGA_SOURCE_ACCOUNT_REQUIRED. Testnet still falls back toalice. - ZK dev-ceremony block detects mainnet by passphrase: a mainnet network with a custom name (e.g.
pubnet) is now blocked too.
3.10.2 highlights
ctg doctorrejects Rust toolchains thatstellar contract buildrefuses: the 1.81.x, 1.82.x and 1.83.x lines and exactly 1.91.0 now fail the Rust check withrustup update stableas the fix (3.10.1 reported 1.91.0 as OK).RUST_MIN_VERSIONis 1.91.1; the blocked list is exported asRUST_BLOCKED_VERSIONSfrom@caatinga/core/runtime/requirements.- Scaffolds, templates and examples declare
rust-version = "1.91.1".
3.10.1 highlights
- Mainnet always requires confirmation:
requireConfirmation: falseis ignored on mainnet (detected by name or by the public network passphrase). Unattended runs must pass--yesor setCAATINGA_ASSUME_YES=true; the[MAINNET GUARDRAIL]audit log is still printed. The prompt now coversdeploy,upgrade,invoke,wire,rollback,regressionand ZK invoke, shows the target deployment, and automatic retries are disabled on mainnet. ctg doctorchecks the Rust version: toolchains older than 1.91.0 fail the Rust check withrustup update stableas the fix. Rust 1.91.0 itself is rejected bystellar contract build; 3.10.2 makesdoctorflag it.ctg doctor/ctg versionupdate advisory: an informational note when the installed CLI is ahead of or behind the npmlatesttag. It never fails a command; setCAATINGA_SKIP_UPDATE_CHECK=1to skip it.ctg upgradewrites a relativesourcePathtocaatinga.artifacts.json, matchingctg deploy. Entries written by earlier upgrades keep their absolute path until the next upgrade or deploy.- Stricter artifacts schema: malformed
contractId/wasmHashvalues incaatinga.artifacts.jsonare rejected. - Bounded calls: subprocess and network calls (including the Horizon lookup in deploy recovery) now time out instead of hanging.
- Stellar CLI 28.0.0 is the new last-tested version; contracts, examples and templates use
soroban-sdk27.0.6.
3.9.2 highlights
- Security fix:
identity export/importno longer leave a leftover tarball of Stellar secret keys inos.tmpdir(). See CLI Identity Reference for the remediation steps if you ran either command before upgrading. - Security fix:
identity importnow rejects a tarball if any entry would extract outside the target Stellar config directory (tar path traversal). Only import archives from a trusted source. - Security fix: the ZK toolchain now verifies every
circombinary — freshly downloaded or read from the~/.caatinga/zk-toolscache — against a pinned SHA-256 before use, deleting and rejecting it (ZK_CHECKSUM_MISMATCH) on a mismatch instead of running an unverified binary. See Errors reference. - Smaller install: the published
@caatinga/clitarball dropped from 95.3 MB packed / 283.7 MB unpacked to 67.4 kB — the Rusttarget/build directory andtest_snapshotsare now excluded from what gets published. sync-envno longer wipes unrelated variables in the target env file; concurrentdeploy/upgradeno longer race oncaatinga.artifacts.json;deployretries when the RPC hasn’t indexed a just-uploaded WASM yet. See Gotchas for the full list.