Release/974.0.0 - #8755
Conversation
|
Warning MetaMask internal reviewing guidelines:
|
Restore changelog entries for prior releases that were inadvertently reformatted by the release tooling, keeping only the 974.0.0 release content.
Mrtenz
left a comment
There was a problem hiding this comment.
Looks good to me other than sample-controllers needing a major bump.
Major version bump reflects the BREAKING changes in this release (SampleGasPricesService now inherits from BaseDataService; onRetry, onBreak, and onDegraded removed).
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 898f4a8. Configure here.
| { | ||
| "name": "@metamask/accounts-controller", | ||
| "version": "38.0.0", | ||
| "version": "38.1.0", |
There was a problem hiding this comment.
Minor/patch bumps for major dependency upgrades violate semver
High Severity
@metamask/accounts-controller is bumped from 38.0.0 to 38.1.0 (minor), but its dependency on @metamask/network-controller is bumped from ^30.1.0 to ^31.0.0 (major). Consumers who also depend on @metamask/network-controller@^30.x will face unresolvable version conflicts when upgrading to accounts-controller@38.1.0, since ^30.x and ^31.0.0 are incompatible ranges. The same pattern applies broadly: many packages (gas-fee-controller, polling-controller, ens-controller, earn-controller, multichain-network-controller, etc.) receive only patch/minor bumps while bumping major dependencies on network-controller (^30.x → ^31.0.0) and/or controller-utils (^11.x → ^12.0.0). Per the reviewer's comment, these need to be major bumps.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 898f4a8. Configure here.
## Explanation Release `1169.0.0` with version bumps for: - **`@metamask/eth-json-rpc-middleware`** `23.1.3` → `24.0.0` (major) - **`@metamask/network-controller`** `35.0.0` → `35.0.1` (patch) ### `@metamask/eth-json-rpc-middleware@24.0.0` **Breaking:** Add strict validation for `eth_sendTransaction` and `eth_signTransaction` params ([MetaMask#9482](MetaMask#9482)) - Reject requests whose params do not match the transaction schema (extraneous top-level keys, ill-typed fields such as non-hex `to`/`data`, malformed `accessList` / `authorizationList` entries) or exceed `MAX_TRANSACTION_PARAMS_SIZE_BYTES` when serialized - Prevents downstream normalization / PPOM WASM from crashing on deeply-nested junk fields or padded payloads and silently bypassing security scans Other changes: - Bump `@metamask/utils` from `^11.9.0` to `^11.11.0` ([MetaMask#9074](MetaMask#9074)) - Bump `@metamask/json-rpc-engine` from `^10.2.4` to `^10.5.0` ([MetaMask#8661](MetaMask#8661), [MetaMask#8746](MetaMask#8746), [MetaMask#8753](MetaMask#8753)) - Bump `@metamask/message-manager` from `^14.1.1` to `^14.1.2` ([MetaMask#8755](MetaMask#8755)) - Drop `pify` dependency, which was no longer used in source ([MetaMask#9064](MetaMask#9064)) ### `@metamask/network-controller@35.0.1` - Bump `@metamask/eth-json-rpc-middleware` from `^23.1.3` to `^24.0.0` ([MetaMask#9758](MetaMask#9758)) ## References - [MetaMask#9482](MetaMask#9482) — feat: validate `eth_sendTransaction` / `eth_signTransaction` params ## Checklist - [ ] I've updated the test suite for new or updated code as appropriate - [ ] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [x] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > The release propagates a major middleware bump that rejects previously accepted malformed transaction RPC params; integrators on strict validation paths should expect possible breakage for non-conformant dapps, though this PR itself only changes versions and docs. > > **Overview** > This PR cuts **monorepo release `1169.0.0`** by versioning packages and aligning dependents—no application source changes beyond manifests and changelogs. > > **`@metamask/eth-json-rpc-middleware@24.0.0`** is published with changelog release notes for the existing **breaking** strict validation on `eth_sendTransaction` / `eth_signTransaction` (schema, size limits, rejection of malformed or oversized params). > > **`@metamask/network-controller@35.0.1`** bumps its dependency on that middleware from `^23.1.3` to `^24.0.0`. Root and many workspace packages update `@metamask/network-controller` to `^35.0.1`, with matching **Unreleased** changelog lines and **`yarn.lock`** resolution updates. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 455c03b. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: cryptodev-2s <109512101+cryptodev-2s@users.noreply.github.com>


Explanation
References
Checklist
Note
Medium Risk
Primarily dependency/version bumps, but it pulls in breaking major releases of
@metamask/controller-utils@12and@metamask/network-controller@31, which can break downstream typed event listeners and service policy handlers.Overview
Bumps the monorepo release version to
974.0.0and rolls forward many internal package versions/changelogs.Most packages are updated to depend on
@metamask/controller-utils@12.0.0and@metamask/network-controller@31.0.0(plus related patch bumps like@metamask/message-manager@14.1.2,@metamask/polling-controller@16.0.5, etc.), propagating the new breaking event payload/type changes through the dependency graph.Reviewed by Cursor Bugbot for commit 898f4a8. Bugbot is set up for automated code reviews on this repo. Configure here.