Skip to content

Release 973.0.0 - #8753

Merged
FrederikBolding merged 2 commits into
mainfrom
release/973.0.0
May 11, 2026
Merged

Release 973.0.0#8753
FrederikBolding merged 2 commits into
mainfrom
release/973.0.0

Conversation

@FrederikBolding

@FrederikBolding FrederikBolding commented May 11, 2026

Copy link
Copy Markdown
Member

Explanation

Feature release for json-rpc-engine introducing assertExpectedHooks.

References

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Low Risk
Primarily version bumps and changelog updates; no functional code changes in this diff beyond updating dependency resolution.

Overview
Bumps the monorepo release to 973.0.0 and publishes @metamask/json-rpc-engine@10.5.0, documenting the new assertExpectedHooks export in the engine changelog.

Updates all in-repo consumers to depend on @metamask/json-rpc-engine@^10.5.0, refreshes related package changelogs, and updates yarn.lock accordingly.

Reviewed by Cursor Bugbot for commit 7a7ce4c. Bugbot is set up for automated code reviews on this repo. Configure here.

@FrederikBolding
FrederikBolding marked this pull request as ready for review May 11, 2026 07:55
@FrederikBolding
FrederikBolding requested review from a team as code owners May 11, 2026 07:55
@FrederikBolding
FrederikBolding added this pull request to the merge queue May 11, 2026
Merged via the queue into main with commit 59194e1 May 11, 2026
369 of 370 checks passed
@FrederikBolding
FrederikBolding deleted the release/973.0.0 branch May 11, 2026 08:01
@OGPoyraz OGPoyraz mentioned this pull request Aug 3, 2026
4 tasks
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Aug 3, 2026
## Explanation

Release `1169.0.0` with version bumps for:

- **`@metamask/eth-json-rpc-middleware`** `23.1.3` → `24.0.0` (major)
- **`@metamask/network-controller`** `35.0.0` → `35.0.1` (patch)

### `@metamask/eth-json-rpc-middleware@24.0.0`

**Breaking:** Add strict validation for `eth_sendTransaction` and
`eth_signTransaction` params
([MetaMask#9482](MetaMask#9482))
- Reject requests whose params do not match the transaction schema
(extraneous top-level keys, ill-typed fields such as non-hex
`to`/`data`, malformed `accessList` / `authorizationList` entries) or
exceed `MAX_TRANSACTION_PARAMS_SIZE_BYTES` when serialized
- Prevents downstream normalization / PPOM WASM from crashing on
deeply-nested junk fields or padded payloads and silently bypassing
security scans

Other changes:
- Bump `@metamask/utils` from `^11.9.0` to `^11.11.0`
([MetaMask#9074](MetaMask#9074))
- Bump `@metamask/json-rpc-engine` from `^10.2.4` to `^10.5.0`
([MetaMask#8661](MetaMask#8661),
[MetaMask#8746](MetaMask#8746),
[MetaMask#8753](MetaMask#8753))
- Bump `@metamask/message-manager` from `^14.1.1` to `^14.1.2`
([MetaMask#8755](MetaMask#8755))
- Drop `pify` dependency, which was no longer used in source
([MetaMask#9064](MetaMask#9064))

### `@metamask/network-controller@35.0.1`

- Bump `@metamask/eth-json-rpc-middleware` from `^23.1.3` to `^24.0.0`
([MetaMask#9758](MetaMask#9758))

## References

- [MetaMask#9482](MetaMask#9482) — feat: validate
`eth_sendTransaction` / `eth_signTransaction` params

## Checklist

- [ ] I've updated the test suite for new or updated code as appropriate
- [ ] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> The release propagates a major middleware bump that rejects previously
accepted malformed transaction RPC params; integrators on strict
validation paths should expect possible breakage for non-conformant
dapps, though this PR itself only changes versions and docs.
> 
> **Overview**
> This PR cuts **monorepo release `1169.0.0`** by versioning packages
and aligning dependents—no application source changes beyond manifests
and changelogs.
> 
> **`@metamask/eth-json-rpc-middleware@24.0.0`** is published with
changelog release notes for the existing **breaking** strict validation
on `eth_sendTransaction` / `eth_signTransaction` (schema, size limits,
rejection of malformed or oversized params).
> 
> **`@metamask/network-controller@35.0.1`** bumps its dependency on that
middleware from `^23.1.3` to `^24.0.0`. Root and many workspace packages
update `@metamask/network-controller` to `^35.0.1`, with matching
**Unreleased** changelog lines and **`yarn.lock`** resolution updates.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
455c03b. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: cryptodev-2s <109512101+cryptodev-2s@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants