A protocol stack, not a bridge widget
Union moves messages and assets between otherwise separate blockchains. Its security pitch is consensus verification: on-chain light clients verify the other network rather than handing authority to an oracle, multisignature group, or MPC committee. The protocol implements IBC and lists routes across Cosmos-style chains, Ethereum and several EVM networks, plus Sui testnet.
The repository contains nearly every layer behind that pitch. uniond is the Cosmos SDK-based chain node. galoisd produces zero-knowledge proofs. Voyager is the cross-ecosystem relayer. Separate Rust and Solidity trees contain CosmWasm and EVM contracts, while TypeScript workspaces provide SDKs, the transfer app, documentation, and the public site. Unionvisor supervises node upgrades. A faucet and local-network machinery sit beside them.
That range is helpful for protocol auditors because interfaces are visible together. It is difficult for an application team that merely wants to submit one transfer. The root repository is best treated as a system map. Pick the SDK, contract stack, relayer, or node role you actually need before reading build instructions.
The trust model deserves a close read
Light-client verification removes one familiar bridge risk, but it does not remove protocol risk. Each client must encode the remote chain's consensus and finality rules correctly. Voyager's README says some clients follow existing Tendermint or Ethereum specifications, while many are custom adaptations for chains connected to IBC. Layer 2 clients also verify settlement through their Layer 1 and inherit the rollup settlement period plus Layer 1 finality.
Voyager models relay work as a finite state machine stored in PostgreSQL. Queries, transaction submissions, and intermediate data become queued state, so workers can resume and process independent messages in parallel. This is a thoughtful response to unreliable RPCs and relayer crashes. It also means operators must maintain a database, monitor stuck work, secure transaction keys, and understand retries across chains where a repeated or late action can be expensive.
Governance assumptions matter too. The uniond README says the mainnet uses proof of authority temporarily during incubation. Anyone choosing Union because “trust minimized” implies a fully permissionless validator set today should reconcile that statement with their own requirements. Contract upgradability, connections, and token configuration are also governance surfaces, not implementation trivia.
What happened when we ran it
We cloned commit 031785b into a fresh, unprivileged Node 22 Bookworm sandbox with 3 CPUs, 8 GB of RAM, and no secrets. The checkout contained 4,438 files, roughly 422,374 source lines, and occupied 55.9 MB. Pnpm installation succeeded in 40 seconds, adding 2,068 packages that consumed 2,008 MB on disk.
The root package had no build script or target, so our harness skipped building. It also had no test script or target, so no tests ran. The repository exposed 13 CI workflow files, no Dockerfile, no root tests directory, and monorepo workspaces. These measurements describe the Node dependency layer only. They do not say that uniond, Voyager, the prover, contracts, SDKs, or a cross-chain route compiled or passed an integration check.
That distinction is unusually large here. Rust dominates the repository language statistics, while Go, Solidity, TypeScript, Svelte, Nix, and contract-specific tooling all appear in the component table. A two-gigabyte pnpm tree is already heavy, yet it is still only part of the contributor environment.
Source setup is intentionally Nix-first
The quickstart installs Nix and builds named flake outputs such as uniond, voyager, or app. nix develop supplies Cargo, Rust, Node, Go, and the remaining dependencies. The approach gives maintainers one declared environment for a polyglot repository, which is preferable to a handwritten list of compiler versions. It also makes Nix knowledge a real entry requirement.
The contributor guide documents a sharp version condition: Nix 2.18 or versions 2.25 and newer work reliably, while the middle range does not. macOS developers are told that some components only build on Linux and are directed to an OrbStack NixOS virtual machine. Commits must be signed, conventional commit formatting is checked, and contributors are expected to open an issue before starting code changes.
The architecture guide admits that source is the final authority and that significant components are still being added. It recommends text search and component doc comments for details. That is reasonable for maintainers, but integrators need to freeze the commit, contract addresses, route configuration, and client versions they have reviewed. A changing monorepo cannot be consumed safely as an unspecified main.
Health, releases, and where to begin
The last repository push was July 25, 2026. Open issue activity continued on August 11, including work prompted by the shutdown of the Garnix build service. GitHub listed 192 open issues and pull requests combined. The latest GitHub release was a Linux bundle, bundle-union-1/v1.2.3, published January 26 with checksums for x86-64 and ARM64 archives. The older release date alone is not evidence of abandonment because issue activity and pushes continued afterward.
Documentation starts well. The root README names every major component, provides supported network identifiers, and links to official protocol docs. The architecture file explains binary roles and repository layout. Individual READMEs cover node, supervisor, relayer, and SDK workflows, though detail varies and some Voyager documentation still contains a missing-link note. The repository offers Apache 2.0 and MIT license files, while GitHub identifies Apache 2.0.
Application developers should begin with the TypeScript SDK and a small testnet transaction, not a full source build. Node operators should use the published bundle and Unionvisor guidance. Protocol teams adding a route need a deeper review of light-client code, finality, contracts, key custody, PostgreSQL recovery, and upgrade governance. Union is worth that work only when its consensus-verification model is a requirement, not when any bridge will do.

