Welcome to this week’s Weekly Development Report, highlighting continued progress across the ecosystem, with a focus on compatibility, transaction reliability, and keeping our products aligned with the latest Mainsail changes. This week, Mainsail saw further work on transaction signing, transaction pool handling, and snapshot imports, while ARK Scan and ARK Vault received updates to improve compatibility and transaction handling. We also continued aligning the Python, TypeScript, and PHP SDKs with the latest validator proof-of-possession format, alongside further testing and dependency updates across the ecosystem.
Development Activity Summary (October 02 – October 09, 2026)
Below is a breakdown of the total number of merged commits and contributing authors by project, highlighting development activity from October 02, 2026, to October 09, 2026.
| Project | Commits | Authors |
|---|---|---|
| ARK Connect | 0 | 0 |
| ARK Scan | 14 | 2 |
| ARK SDKs & Docs | 16 | 2 |
| ARK Vault | 67 | 2 |
| Mainsail | 31 | 4 |
In total, 128 commits were merged across all projects this week. As always, commit counts fluctuate with sprint focus and task complexity.
ARK Scan Weekly Report
This week’s ARK Scan work focused on aligning the Mainsail integration with the latest foundation updates. Validator transaction method hashes were updated to reflect changes to the validator contract, covering registration, resignation, and updates. The validator transaction filter was also adjusted to include update transactions. In addition, dependency baselines were aligned with the foundation update, and arkecosystem/foundation was upgraded to version ^22.0.0 on the mainsail-develop branch.
Next week, we’ll continue updating ARK Scan to stay aligned with the latest Mainsail changes, address any remaining compatibility issues, and do further internal testing.
ARK Docs & SDKs Weekly Report
This week’s SDK work focused on aligning validator proof-of-possession (PoP) generation across Python, TypeScript, and PHP with Mainsail’s updated format. The changes bind validator proofs to both the chain ID and the registrant address, preventing proofs from being reused by a different account or on another network.
The Python Crypto SDK was updated with a new validator_proof() method that accepts the passphrase and registrant address. Address validation was also improved to reject malformed addresses and invalid checksums, and new tests were added against Mainsail’s reference data. A dependency issue affecting CI installations was resolved by pinning btclib to a compatible version.
In the TypeScript Crypto SDK, the PoP API was simplified so the chain ID is derived directly from the configured network rather than passed in separately. The options wrapper was also removed, with the registrant address now accepted directly as a parameter. The PHP Crypto SDK was updated to use the same proof format as Mainsail, including the revised domain separation tag and message encoding. The validatorPassphrase() method was replaced with validatorProof(), and the related proof-building, mnemonic, and transaction-encoding methods now require the registrant address. We regenerated test fixtures, and the tests now verify that the generated proofs match Mainsail’s reference vectors byte for byte.
Next week, we’ll continue aligning the SDKs with the latest Mainsail changes, review any compatibility issues resulting from the updated validator proof APIs, and continue improving test coverage and documentation where needed.
ARK Vault Weekly Report
This week’s ARK Vault work focused on improving transaction handling, fixing issues in the transaction history and export features, and updating dependencies across the application.
Validator registration and update transactions were adjusted to include the registrant address and chain ID, ensuring the required information is provided when interacting with validator contracts. Several issues with the transaction table were also addressed, including duplicate transactions appearing when loading more entries and performance problems that caused the table to slow down over time. Pending transaction details were corrected to display the proper transaction method and account for transfers sent to the same address. Additionally, the transaction export feature was fixed to support custom date ranges.
Alongside these changes, we updated dependencies to newer minor and major versions, including eslint-plugin-unicorn, jsdom, and Cucumber, and raised the minimum supported Node.js version to 24.15.0. We also fixed broken end-to-end tests, addressed intermittently failing unit tests, and corrected TypeScript compilation in the E2E test suite following the update to @types/node.
Next week, we’ll continue updating dependencies across ARK Vault, address any compatibility issues that arise, and carry on with internal testing to identify and resolve remaining issues ahead of the next release.
Mainsail Weekly Report
This week’s Mainsail work focused on improving transaction pool reliability, strengthening transaction signature handling, and fixing issues in snapshot imports and legacy data migration.
Additional unit tests were added to the transaction-pool-service package to verify rebroadcast settings, and unused code was removed. Wallet functionality was also moved from the state package into transaction-pool-service to better align it with the package’s responsibilities. In the utils package, the isObject helper was corrected to reject null, and missing tests were added for path helpers. We also fixed a syntax issue in the testnet installation script.
Transaction signing was further strengthened by binding legacy second signatures to the signed transaction and its recovery ID. This prevents signatures from being reused as primary signatures, replayed by another sender, or altered by changing the final byte. The V3 delegate importer was also fixed to correctly recognize resigned delegates, which were previously imported as active due to a mismatch in the resignation flag name. This ensures their status and associated votes are handled correctly during import.
Further work was done on the snapshot importer, which was cleaned up to accept only Brotli-compressed snapshots and reject repeated or improperly prepared imports. Import errors now provide clearer information by decoding contract reverts and identifying mismatched values, while unused API functionality was removed. Unit tests were added to cover these changes.
Next week, we’ll continue improving snapshot imports and work on the P2P layer.
Feedback & Feature Requests
If you are using our open-source products and would like to provide feedback or request a feature, please feel free to contact us via the contact pages for the specific product you are using or open an issue on GitHub.
Quick access links to GitHub issues pages:
Follow Us on X
Follow us on X and keep an eye on the blog to stay up to date with everything we ship. We publish a development report every week so you can follow along as the ecosystem grows.