@ckb-ccc/core uses @joyid/ckb only for verifySignature (verifyJoyId.ts), and @ckb-ccc/joy-id only for Aggregator.generateSubkeyUnlockSmt (ckb/index.ts). The first is WebCrypto, the second is one JSON-RPC call.
@joyid/ckb imports @nervosnetwork/ckb-sdk-utils, a CJS module that loads elliptic at import, so apps bundle it: ckb-sdk-utils 0.109.5 with its dependencies is 194 KB minified (67 KB gzip). It also brings 21 low npm audit notes in an app with the connector (GHSA-848j-6mx2-7j84, no patched elliptic). That advisory is about signing, which these paths never do.
Would a PR that inlines both be welcome?
@ckb-ccc/coreuses@joyid/ckbonly forverifySignature(verifyJoyId.ts), and@ckb-ccc/joy-idonly forAggregator.generateSubkeyUnlockSmt(ckb/index.ts). The first is WebCrypto, the second is one JSON-RPC call.@joyid/ckbimports@nervosnetwork/ckb-sdk-utils, a CJS module that loadsellipticat import, so apps bundle it: ckb-sdk-utils 0.109.5 with its dependencies is 194 KB minified (67 KB gzip). It also brings 21 lownpm auditnotes in an app with the connector (GHSA-848j-6mx2-7j84, no patchedelliptic). That advisory is about signing, which these paths never do.Would a PR that inlines both be welcome?