This proposal initiates the mainnet upgrade of Hippo Protocol to v2.0.0. This release integrates CosmWasm for smart contract capabilities and applies critical vulnerability patches flagged by Dependabot for underlying dependencies.
v2.0.0 binary file from the release notes. The upgrade process follows standard Cosmos-SDK procedures. Using cosmovisor is highly recommended.cometbft and golang.org/x/crypto to patch known upstream vulnerabilities.The upgrade introduces the CosmWasm module (wasmd v0.54.2) to the Hippo mainnet, enabling the deployment and execution of secure, Rust-based smart contracts. Furthermore, this release patches critical upstream dependencies flagged by Dependabot by updating github.com/cometbft/cometbft from v0.38.19 to v0.38.21 and golang.org/x/crypto from v0.36.0 to v0.45.0.
To expand the capability and protect the infrastructure of Hippo Protocol in the global healthcare economy, it is necessary to:
CosmWasm is a mature, production-grade smart contract framework, and updating core dependencies is the logical next step for Hippo’s infrastructure.
github.com/CosmWasm/wasmd module (v0.54.2) in app.go.github.com/cometbft/cometbft from v0.38.19 to v0.38.21.golang.org/x/crypto from v0.36.0 to v0.45.0.1.24.3.CosmWasm provides standardized, secure, and modular smart contracting capabilities without introducing EVM-related attack vectors like re-entrancy. Concurrently patching CometBFT and Go cryptography dependencies addresses known vulnerabilities without introducing breaking architectural changes, keeping network security hardened.
wasmd modules.cometbft (consensus stability) and golang.org/x/crypto (cryptographic operations/DoS prevention).app/upgrades/v2_0_0/upgrade.go.|
Field
|
Data
|
|---|---|
|
info
|
https://github.com/hippo-protocol/hippo-protocol |
|
name
|
v2.0.0 |
|
time
|
0001-01-01T00:00:00Z |
|
height
|
7165000 |
|
upgraded_client_state
|