mrkeyoor.com_
Wed 30 Sept 19:27 UTC
Dev Toolsevaluationupdated 24 Aug 2026

union review

Union is a cross-chain messaging and asset-transfer protocol that uses light clients and zero-knowledge proofs instead of a trusted multisignature bridge. This repository contains the network node, prover, relayer, smart contracts, TypeScript SDKs, web applications, and deployment machinery needed to build and operate that system.

-1stars / 7d
Verdict

Union is serious protocol infrastructure for teams that specifically want light-client-based interoperability and can evaluate its chain-specific code. It is a poor casual dependency: the monorepo, Nix build, prover, relayer database, contracts, and node operations demand specialist ownership. Start from the SDK and a testnet route, then audit the exact clients and contracts your transfer will cross before committing production assets.

We ran it

Lab card: what happened when we ran unionScreenshot of union (union.build)
Install✓ · 40s2068 packages · 2008 MB
Buildn/ano build script
Testsn/ano test script
Repo4438 files~422,374 lines of source · 55.9 MB · 13 CI workflows

Answers from our run

Does union build from source?

Dependencies installed in 40 seconds (2068 packages), and the project has no separate build step. We cloned commit 031785b into a clean Debian container with 3 CPUs and no project-specific setup.

Does union have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Who should not use union?

Application developers seeking one small bridge library: this repository includes the chain, prover, relayer, contracts, sites, and several SDK workspaces.

What are the alternatives to union?

IBC-Go, Hyperlane, Wormhole. Union is serious protocol infrastructure for teams that specifically want light-client-based interoperability and can evaluate its chain-specific code.

Setup2/5Nix-first polyglot stack with Linux-only components and services
Docs4/5Good system map and component docs, with source still authoritative
Community4/5Recent issue activity and a substantial open issue and PR queue
Maturity3/5Mainnet software with moving components and temporary PoA

Who it’s for

Protocol engineers integrating IBC-style messaging across Cosmos, EVM, Sui, and other supported chains.
Relayer and validator operators prepared to run chain infrastructure and monitor upgrades.
Smart-contract teams willing to study Union's light-client and token-transfer assumptions in detail.
Contributors already comfortable with Nix, Rust, Go, Solidity, TypeScript, and multi-chain testing.

Who it’s NOT for

Application developers seeking one small bridge library: this repository includes the chain, prover, relayer, contracts, sites, and several SDK workspaces.
Contributors unwilling to adopt Nix: the quickstart makes Nix the source-build path, and the contributor guide says only Nix 2.18 or 2.25 and newer work reliably.
macOS developers who cannot run a Linux VM: the README says some components build only on Linux and recommends OrbStack with NixOS.
Operators who require proof-of-stake governance from day one: the uniond README says mainnet temporarily uses proof of authority during incubation.
Teams treating a successful pnpm install as proof of protocol readiness: our lab found no root build or test target, while the actual system spans several language toolchains and network services.
Organizations unable to audit cross-chain failure assumptions: Voyager includes custom light clients, chain-specific finality logic, a PostgreSQL queue, and transaction submission across independent networks.

Setup reality

At commit 031785b, pnpm installation succeeded in 40 seconds. It installed 2,068 packages occupying 2,008 MB. The checkout contained 4,438 files, about 422,374 source lines, and used 55.9 MB. There was no root build script or target and no root test script or target, so both were skipped.

That successful install covers the Node workspaces, not the full protocol. The root README directs source builders to install Nix, then build a named component such as uniond, voyager, or app. The development shell supplies Rust, Go, Node, and other tools. Some components require Linux; the recommended macOS route uses a NixOS virtual machine.

Running components adds services and chain state. Validators need uniond and should use unionvisor; relayers use Voyager, which stores its work queue in PostgreSQL; proof work involves galoisd. Integration also means RPC endpoints, keys, contracts, supported-chain identifiers, and per-chain finality behavior.

A protocol stack, not a bridge widget

Union moves messages and assets between otherwise separate blockchains. Its security pitch is consensus verification: on-chain light clients verify the other network rather than handing authority to an oracle, multisignature group, or MPC committee. The protocol implements IBC and lists routes across Cosmos-style chains, Ethereum and several EVM networks, plus Sui testnet.

The repository contains nearly every layer behind that pitch. uniond is the Cosmos SDK-based chain node. galoisd produces zero-knowledge proofs. Voyager is the cross-ecosystem relayer. Separate Rust and Solidity trees contain CosmWasm and EVM contracts, while TypeScript workspaces provide SDKs, the transfer app, documentation, and the public site. Unionvisor supervises node upgrades. A faucet and local-network machinery sit beside them.

That range is helpful for protocol auditors because interfaces are visible together. It is difficult for an application team that merely wants to submit one transfer. The root repository is best treated as a system map. Pick the SDK, contract stack, relayer, or node role you actually need before reading build instructions.

The trust model deserves a close read

Light-client verification removes one familiar bridge risk, but it does not remove protocol risk. Each client must encode the remote chain's consensus and finality rules correctly. Voyager's README says some clients follow existing Tendermint or Ethereum specifications, while many are custom adaptations for chains connected to IBC. Layer 2 clients also verify settlement through their Layer 1 and inherit the rollup settlement period plus Layer 1 finality.

Voyager models relay work as a finite state machine stored in PostgreSQL. Queries, transaction submissions, and intermediate data become queued state, so workers can resume and process independent messages in parallel. This is a thoughtful response to unreliable RPCs and relayer crashes. It also means operators must maintain a database, monitor stuck work, secure transaction keys, and understand retries across chains where a repeated or late action can be expensive.

Governance assumptions matter too. The uniond README says the mainnet uses proof of authority temporarily during incubation. Anyone choosing Union because “trust minimized” implies a fully permissionless validator set today should reconcile that statement with their own requirements. Contract upgradability, connections, and token configuration are also governance surfaces, not implementation trivia.

What happened when we ran it

We cloned commit 031785b into a fresh, unprivileged Node 22 Bookworm sandbox with 3 CPUs, 8 GB of RAM, and no secrets. The checkout contained 4,438 files, roughly 422,374 source lines, and occupied 55.9 MB. Pnpm installation succeeded in 40 seconds, adding 2,068 packages that consumed 2,008 MB on disk.

The root package had no build script or target, so our harness skipped building. It also had no test script or target, so no tests ran. The repository exposed 13 CI workflow files, no Dockerfile, no root tests directory, and monorepo workspaces. These measurements describe the Node dependency layer only. They do not say that uniond, Voyager, the prover, contracts, SDKs, or a cross-chain route compiled or passed an integration check.

That distinction is unusually large here. Rust dominates the repository language statistics, while Go, Solidity, TypeScript, Svelte, Nix, and contract-specific tooling all appear in the component table. A two-gigabyte pnpm tree is already heavy, yet it is still only part of the contributor environment.

Source setup is intentionally Nix-first

The quickstart installs Nix and builds named flake outputs such as uniond, voyager, or app. nix develop supplies Cargo, Rust, Node, Go, and the remaining dependencies. The approach gives maintainers one declared environment for a polyglot repository, which is preferable to a handwritten list of compiler versions. It also makes Nix knowledge a real entry requirement.

The contributor guide documents a sharp version condition: Nix 2.18 or versions 2.25 and newer work reliably, while the middle range does not. macOS developers are told that some components only build on Linux and are directed to an OrbStack NixOS virtual machine. Commits must be signed, conventional commit formatting is checked, and contributors are expected to open an issue before starting code changes.

The architecture guide admits that source is the final authority and that significant components are still being added. It recommends text search and component doc comments for details. That is reasonable for maintainers, but integrators need to freeze the commit, contract addresses, route configuration, and client versions they have reviewed. A changing monorepo cannot be consumed safely as an unspecified main.

Health, releases, and where to begin

The last repository push was July 25, 2026. Open issue activity continued on August 11, including work prompted by the shutdown of the Garnix build service. GitHub listed 192 open issues and pull requests combined. The latest GitHub release was a Linux bundle, bundle-union-1/v1.2.3, published January 26 with checksums for x86-64 and ARM64 archives. The older release date alone is not evidence of abandonment because issue activity and pushes continued afterward.

Documentation starts well. The root README names every major component, provides supported network identifiers, and links to official protocol docs. The architecture file explains binary roles and repository layout. Individual READMEs cover node, supervisor, relayer, and SDK workflows, though detail varies and some Voyager documentation still contains a missing-link note. The repository offers Apache 2.0 and MIT license files, while GitHub identifies Apache 2.0.

Application developers should begin with the TypeScript SDK and a small testnet transaction, not a full source build. Node operators should use the published bundle and Unionvisor guidance. Protocol teams adding a route need a deeper review of light-client code, finality, contracts, key custody, PostgreSQL recovery, and upgrade governance. Union is worth that work only when its consensus-verification model is a requirement, not when any bridge will do.

Alternatives

ProjectWhat it isPick it when
IBC-GoThe Go implementation of IBC used by Cosmos SDK chains.pick this instead when both ends fit the Cosmos SDK and standard IBC integration is the main task.
HyperlaneA permissionless interchain messaging system with configurable security modules.pick this instead when application-specific security configuration and broad deployment tooling fit better than Union's consensus-verification model.
WormholeA cross-chain messaging protocol built around a guardian network and chain contracts.pick this instead when its supported networks, guardian security model, and existing integrations match your application.

What people are saying

  1. [hackernews] Apple announces changes for apps in the European Union
  2. [github-trending] unionlabs/union
  3. [hackernews] Wikimedia Foundation refuses union recognition, hires union-busting law firm

Sources

  1. Union repository and README
  2. Union architecture
  3. Union contribution guide
  4. Voyager architecture
  5. Union node documentation

More dev tools reviews

lipgloss · roundhouse · GhostTrack · Codex-Dream-Skin · TokenTracker · firebase-ios-sdk · the whole board →