Skip to content

Update deps - #3011

Merged
yashovardhan merged 5 commits into
mainfrom
dep-update
Aug 7, 2026
Merged

Update deps#3011
yashovardhan merged 5 commits into
mainfrom
dep-update

Conversation

@yashovardhan

@yashovardhan yashovardhan commented Aug 5, 2026

Copy link
Copy Markdown
Member

Update all dependencies, tested against a build


Note

Low Risk
Documentation-only changes to chain reference tables with no runtime or security logic impact.

Overview
Updates supported-chains.md so mainnet coverage matches current Transaction Shield wording and ordering.

The mainnet table now links the Transaction Shield column to MetaMask support, uses Covered instead of Yes for supported networks, reorders rows (major L2s grouped first), and adds a caution callout for chains marked No (no threat scanning or Transaction Protection; Guard Mode allowlist still applies).

The testnet table drops the Transaction Shield column and reorders networks; it no longer documents per-testnet shield status in the doc.

Reviewed by Cursor Bugbot for commit 8993a05. Bugbot is set up for automated code reviews on this repo. Configure here.

@yashovardhan
yashovardhan requested review from a team as code owners August 5, 2026 16:17
@vercel

vercel Bot commented Aug 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
metamask-docs Ready Ready Preview Aug 6, 2026 2:52pm

Request Review

@socket-security

socket-security Bot commented Aug 5, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​docusaurus/​tsconfig@​3.10.1 ⏵ 3.10.21001005898 +1100
Updatedethers@​6.15.0 ⏵ 6.17.068 -310010084 -2100
Updated@​docusaurus/​plugin-google-tag-manager@​3.10.1 ⏵ 3.10.21001006998 +1100
Updated@​docusaurus/​module-type-aliases@​3.10.1 ⏵ 3.10.21001006998 +1100
Updated@​docusaurus/​preset-classic@​3.10.1 ⏵ 3.10.2991007095 -2100
Updated@​docsearch/​css@​4.6.2 ⏵ 4.7.01001007198 +8100
Updated@​typescript-eslint/​parser@​8.46.2 ⏵ 8.66.010010072 +198100
Updated@​docusaurus/​types@​3.10.1 ⏵ 3.10.2991007298 +1100
Updated@​vercel/​edge@​1.3.1 ⏵ 1.3.21001007292 +2100
Updated@​docusaurus/​eslint-plugin@​3.10.1 ⏵ 3.10.2981007298100
Updated@​docusaurus/​theme-common@​3.10.1 ⏵ 3.10.299 +110075 +198 +1100
Updated@​docusaurus/​core@​3.10.1 ⏵ 3.10.298 +110076 +198 +1100
Updated@​docusaurus/​theme-mermaid@​3.10.1 ⏵ 3.10.2991007695 -2100
Updated@​docusaurus/​plugin-content-docs@​3.10.1 ⏵ 3.10.2991007798 +1100
Updated@​sentry/​browser@​10.22.0 ⏵ 10.69.079 +110091 +196100
Updatedjoi@​17.13.3 ⏵ 17.13.4100 +1100 +279 +193 +1100
Updateddocusaurus-plugin-sass@​0.2.5 ⏵ 0.2.610010098 +280100
Updatedreact-icons@​5.5.0 ⏵ 5.7.0100 +1210010088 +380
Updatedjsonwebtoken@​9.0.2 ⏵ 9.0.399 +110010081100
Updated@​mdx-js/​react@​3.1.0 ⏵ 3.1.110010010085100
Updated@​docsearch/​react@​4.6.2 ⏵ 4.7.097 +11008598 +8100
Updated@​eslint/​eslintrc@​3.3.1 ⏵ 3.3.699 +110010088100
Updatedlaunchdarkly-js-client-sdk@​3.9.0 ⏵ 3.9.49910089 +390 +3100
Updatedtypescript@​5.8.3 ⏵ 5.9.3100 +110090 +1100 +190
Updated@​eslint/​js@​9.35.0 ⏵ 9.39.5100100100 +1091 +4100
Updatedkatex@​0.16.27 ⏵ 0.16.4792 +1100100 +197 +2100
Updated@​docusaurus/​remark-plugin-npm2yarn@​3.10.1 ⏵ 3.10.2941009898100
Updatedaxios@​1.15.0 ⏵ 1.19.098100 +7510094 +3100
Updatedeslint@​9.35.0 ⏵ 9.39.59710010095 -1100
Updatedsass@​1.93.0 ⏵ 1.102.010010010097 +4100
Updatedprettier@​3.6.2 ⏵ 3.9.698 +110097 +198 -1100

View full report

@socket-security

socket-security Bot commented Aug 5, 2026

Copy link
Copy Markdown

Warning

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Warn Low
Potential code anomaly (AI signal): npm @babel/core is 68.0% likely to have a medium risk anomaly

Notes: The code defines a stack-trace manipulation utility that can selectively hide or reveal frames and inject synthetic frames into error traces. While not inherently malicious, its global alteration of Error.prepareStackTrace and stackTraceLimit enables obfuscation of error reporting and can hinder debugging or auditing. Use is advised with thorough documentation and restricted scope in security-sensitive environments.

Confidence: 0.68

Severity: 0.60

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/@metamask/profile-sync-controller@16.0.0npm/@babel/core@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/core@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @babel/core is 75.0% likely to have a medium risk anomaly

Notes: The examined code is a standard, benign helper for constructing and wrapping configuration items from descriptors within Babel’s tooling. There is no evidence of data leakage, exfiltration, backdoors, or other malicious activity in this fragment. The combination of immutability, brand-based identity, and non-enumerable descriptor storage indicates a well-scoped internal utility rather than anything suspicious.

Confidence: 0.75

Severity: 0.50

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/@metamask/profile-sync-controller@16.0.0npm/@babel/core@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/core@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @babel/helper-module-imports is 78.0% likely to have a medium risk anomaly

Notes: The analyzed code is a Babel AST helper (ImportBuilder) used to construct import statements and interop-wrapped imports. It contains no indicators of malicious behavior, data exfiltration, backdoors, or runtime abuses. It operates within a compiler/transpiler context to produce code, not to execute arbitrary user data. Therefore, the code itself does not present security risks or malware indicators under normal usage. This is benign library behavior intended for code transformation.

Confidence: 0.78

Severity: 0.55

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/@metamask/profile-sync-controller@16.0.0npm/@babel/helper-module-imports@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-module-imports@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @babel/helper-module-transforms is 80.0% likely to have a medium risk anomaly

Notes: The code is a legitimate, static-code transformation utility used in Babel to ensure proper behavior of ES module bindings after transforms. There is no evidence of malicious behavior, data leakage, or external communications within this fragment. It operates purely on AST-level transformations consistent with module import/export handling.

Confidence: 0.80

Severity: 0.50

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/@metamask/profile-sync-controller@16.0.0npm/@babel/helper-module-transforms@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-module-transforms@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @babel/helper-string-parser is 78.0% likely to have a medium risk anomaly

Notes: The analyzed code is a standard, well-structured parsing utility for JavaScript string literals and escapes (consistent with Babel’s helper-string-parser). It includes thorough validation, proper Unicode handling, and defensive error reporting. There is no evidence of malicious behavior, data leakage, or network activity within this fragment. The security risk is low when used as part of a trusted toolchain; the code otherwise poses no evident supply-chain threat based on the provided snippet.

Confidence: 0.78

Severity: 0.55

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/@metamask/profile-sync-controller@16.0.0npm/@babel/helper-string-parser@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helper-string-parser@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @babel/helpers is 75.0% likely to have a medium risk anomaly

Notes: The analyzed fragment is a conventional Babel/TypeScript-style decorators runtime (applyDecs) responsible for applying decorators to class members and managing metadata and initializers. There is no evidence of malware, backdoors, or external data leakage within this module. While complex, the code behaves as a metadata-driven decorator processor and should be considered low risk when used as intended. Downstream risks depend on the decorators provided by consumers, not this utility itself.

Confidence: 0.75

Severity: 0.60

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/@metamask/profile-sync-controller@16.0.0npm/@babel/helpers@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helpers@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @babel/helpers is 61.0% likely to have a medium risk anomaly

Notes: The code fragment is a standard Babel decorator runtime helper (applyDecs2203). Its security posture hinges on the trustworthiness of the supplied decorators. If decorators are from untrusted sources, they can execute arbitrary code during decoration or initialization. The library itself does not exhibit malicious behavior, but this pattern introduces a high-risk surface via external inputs. Recommended mitigations include validating decorator outputs, enforcing sandboxing or runner boundaries for decorators, and auditing decorator sources in the application.

Confidence: 0.61

Severity: 0.58

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/@metamask/profile-sync-controller@16.0.0npm/@babel/helpers@7.29.7

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@babel/helpers@7.29.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @docusaurus/utils is 70.0% likely to have a medium risk anomaly

Notes: The module is a benign, well-scoped utility for deterministic, URL-friendly naming with collision-avoidance. MD5 usage is acceptable here given the non-security-critical purpose, though migration to a stronger hash could be considered if future requirements demand cryptographic strength. Overall risk remains low with respect to data leakage or code behavior; the primary concern is MD5's weaknesses and potential policy guidance on hashing algorithms.

Confidence: 0.70

Severity: 0.60

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/theme-common@3.10.2npm/@docusaurus/plugin-content-docs@3.10.2npm/@docusaurus/theme-mermaid@3.10.2npm/@docusaurus/plugin-google-tag-manager@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/@docusaurus/utils@3.10.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@docusaurus/utils@3.10.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @sentry/browser is 72.0% likely to have a medium risk anomaly

Notes: No clear malware/backdoor behavior is evident. However, this integration intentionally creates an exfiltration-like data sink by forwarding serialized Sentry envelopes (potentially sensitive diagnostic/user/context data) to a configurable HTTP endpoint using fetch, with no sidecarUrl validation/allowlisting and a default of non-HTTPS. If sidecarUrl is misconfigured or attacker-controlled, telemetry confidentiality can be compromised.

Confidence: 0.72

Severity: 0.54

From: package-lock.jsonnpm/@sentry/browser@10.69.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sentry/browser@10.69.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @sentry/core is 66.0% likely to have a medium risk anomaly

Notes: This module is a telemetry/instrumentation utility that monkey-patches Node.js request event handlers to capture and store a bounded portion of the request body in SDK processing metadata. It does not show overt malware behaviors (no exfiltration or execution of injected code) but it introduces a meaningful privacy/compliance risk by persisting request content (which may include credentials or PII) into metadata. A secondary anomaly is potentially unsafe UTF-8 truncation that may corrupt character boundaries. Overall, the security risk is moderate, driven primarily by sensitive data handling rather than malicious intent.

Confidence: 0.66

Severity: 0.55

From: package-lock.jsonnpm/@sentry/browser@10.69.0npm/@sentry/core@10.69.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sentry/core@10.69.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @sentry/feedback is 62.0% likely to have a medium risk anomaly

Notes: No clear evidence of classic malware (e.g., backdoors, credential theft, or suspicious network calls) is present in the provided fragment. The dominant security concern is privacy: it intentionally captures the user’s display via getDisplayMedia, transforms it into an annotated PNG, and passes raw screenshot bytes to host submission callbacks—so data exfiltration risk depends on how the integrator implements sendFeedback/onSubmit. Additionally, the module uses dangerouslySetInnerHTML for internally generated SVG markup; this is less concerning than user-controlled XSS but remains a notable DOM injection sink.

Confidence: 0.62

Severity: 0.52

From: package-lock.jsonnpm/@sentry/browser@10.69.0npm/@sentry/feedback@10.69.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sentry/feedback@10.69.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @sentry/replay-canvas is 62.0% likely to have a medium risk anomaly

Notes: This fragment is best characterized as a canvas/webgl recording-and-replay component that aggressively hooks rendering APIs and serializes rendered content (including base64-encoded pixel/image data) into mutation records delivered via host callbacks. No explicit credential theft, system modification, or direct network exfiltration is present in the provided code, but the behavior is highly privacy-sensitive and security-impacting due to invasive prototype patching and the capability to capture user-visible content from canvases. Review the host’s handling/storage/transmission of the emitted mutation stream, and ensure the integration is only enabled in trusted contexts with appropriate consent/controls.

Confidence: 0.62

Severity: 0.66

From: package-lock.jsonnpm/@sentry/browser@10.69.0npm/@sentry/replay-canvas@10.69.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sentry/replay-canvas@10.69.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @sentry/replay is 62.0% likely to have a medium risk anomaly

Notes: No overt malware/backdoor behavior is evident in the provided fragment (no clear RCE/persistence/stealth mechanisms). However, the code is a high-sensitivity client-side session replay recorder that can capture and transmit rich user/DOM state and—when enabled—network request/response content and canvas/image-derived data URLs. The dominant security risk is privacy/exfiltration potential and increased attack surface from wildcard postMessage relay and extensive monkey-patching/proxying. Misconfiguration or hostile plugin/callback usage could materially worsen data exposure.

Confidence: 0.62

Severity: 0.66

From: package-lock.jsonnpm/@sentry/browser@10.69.0npm/@sentry/replay@10.69.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sentry/replay@10.69.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @sinclair/typebox is 60.0% likely to have a medium risk anomaly

Notes: No explicit malware/stealth/data-theft behavior is present in this fragment. However, the code is a dynamic validator code generator that executes generated JavaScript via globalThis.Function, with schema-derived content influencing the emitted source (especially function names from $id and regex locals from pattern). If schemas/references are not fully trusted and if escaping/encoding helpers are insufficient, this module can become a code-injection or denial-of-service risk (ReDoS). Ensure schemas are trusted or enforce strict escaping/sanitization for all schema fields used in code generation and constrain regex patterns.

Confidence: 0.60

Severity: 0.62

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@sinclair/typebox@0.27.12

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@sinclair/typebox@0.27.12. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @webassemblyjs/helper-buffer is 69.0% likely to have a medium risk anomaly

Notes: The code is a focused utility to compare two wasm binary buffers by decoding them into textual dumps and diffing the results. It does not exhibit data exfiltration or network activity. The main concern is the temporary override of console.log, which could affect the host environment or other concurrent code. Overall, functional risk is moderate due to side effects rather than a security vulnerability.

Confidence: 0.69

Severity: 0.60

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/theme-common@3.10.2npm/@docusaurus/types@3.10.2npm/@docusaurus/plugin-content-docs@3.10.2npm/@docusaurus/theme-mermaid@3.10.2npm/@docusaurus/plugin-google-tag-manager@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/docusaurus-plugin-sass@0.2.6npm/node-polyfill-webpack-plugin@2.0.1npm/@webassemblyjs/helper-buffer@1.14.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@webassemblyjs/helper-buffer@1.14.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @webassemblyjs/helper-wasm-section is 78.0% likely to have a medium risk anomaly

Notes: The code appears to be a legitimate utility for inserting an empty section into a WebAssembly module binary and updating both the in-memory AST and the binary buffer. There is no evidence of data leakage, remote control, or malicious behavior in this fragment.

Confidence: 0.78

Severity: 0.60

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/theme-common@3.10.2npm/@docusaurus/types@3.10.2npm/@docusaurus/plugin-content-docs@3.10.2npm/@docusaurus/theme-mermaid@3.10.2npm/@docusaurus/plugin-google-tag-manager@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/docusaurus-plugin-sass@0.2.6npm/node-polyfill-webpack-plugin@2.0.1npm/@webassemblyjs/helper-wasm-section@1.14.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@webassemblyjs/helper-wasm-section@1.14.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @webassemblyjs/wasm-edit is 68.0% likely to have a medium risk anomaly

Notes: The analyzed code is a WASM binary editor utility that applies structural edits (add/update/delete) to a WASM module by manipulating an AST and an in-memory byte buffer. It carefully maintains section sizes and node locations to preserve a consistent binary, and performs validations for certain node types (Func, Global) to ensure proper termination of expressions. There is no indication of malicious behavior, such as data exfiltration, arbitrary code execution, or external network access. The primary risk is operational: incorrect or malicious op sequences could corrupt the wasm binary. With trusted inputs, the component is appropriate for its purpose.

Confidence: 0.68

Severity: 0.55

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/theme-common@3.10.2npm/@docusaurus/types@3.10.2npm/@docusaurus/plugin-content-docs@3.10.2npm/@docusaurus/theme-mermaid@3.10.2npm/@docusaurus/plugin-google-tag-manager@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/docusaurus-plugin-sass@0.2.6npm/node-polyfill-webpack-plugin@2.0.1npm/@webassemblyjs/wasm-edit@1.14.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@webassemblyjs/wasm-edit@1.14.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @webassemblyjs/wasm-parser is 75.0% likely to have a medium risk anomaly

Notes: The code is a legitimate WebAssembly binary decoder/AST builder. It decodes a WASM module into a rich AST representation without performing harmful actions, network activity, or data exfiltration. The primary security considerations are ensuring trust in the library's source and keeping dependencies current, as with any third-party tool. If kept updated and used with proper input validation, the component poses no immediate malicious risk based on this fragment.

Confidence: 0.75

Severity: 0.50

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/theme-common@3.10.2npm/@docusaurus/types@3.10.2npm/@docusaurus/plugin-content-docs@3.10.2npm/@docusaurus/theme-mermaid@3.10.2npm/@docusaurus/plugin-google-tag-manager@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/docusaurus-plugin-sass@0.2.6npm/node-polyfill-webpack-plugin@2.0.1npm/@webassemblyjs/wasm-parser@1.14.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@webassemblyjs/wasm-parser@1.14.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm es-module-lexer is 66.0% likely to have a medium risk anomaly

Notes: This wrapper is a WASM-backed parser, but it conditionally executes eval() on substrings extracted from attacker-controlled input when those substrings look like quoted literals. This creates a direct code-execution risk within the calling process (or at minimum enables attacker-controlled evaluation semantics). Additionally, it can include input excerpts in thrown errors. No explicit network/filesystem sabotage is visible in the JS wrapper; the embedded WASM behavior is largely opaque.

Confidence: 0.66

Severity: 0.70

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/theme-common@3.10.2npm/@docusaurus/types@3.10.2npm/@docusaurus/plugin-content-docs@3.10.2npm/@docusaurus/theme-mermaid@3.10.2npm/@docusaurus/plugin-google-tag-manager@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/docusaurus-plugin-sass@0.2.6npm/node-polyfill-webpack-plugin@2.0.1npm/es-module-lexer@2.3.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-module-lexer@2.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm es-module-lexer is 72.0% likely to have a medium risk anomaly

Notes: An embedded WebAssembly-based parser extracts substrings from untrusted input and passes them to (0, eval) at runtime, creating a code-execution risk where attacker-controlled input can lead to arbitrary JavaScript execution and potential leakage through error messages. The threat remains even though parsing occurs inside the WASM module; the root cause is unsafe dynamic evaluation of attacker-influenced substrings. Avoid running parse() on untrusted data or sandbox/avoid eval-enabled builds.

Confidence: 0.72

Severity: 0.88

From: package-lock.jsonnpm/@docusaurus/core@3.10.2npm/@docusaurus/theme-common@3.10.2npm/@docusaurus/types@3.10.2npm/@docusaurus/plugin-content-docs@3.10.2npm/@docusaurus/theme-mermaid@3.10.2npm/@docusaurus/plugin-google-tag-manager@3.10.2npm/@docusaurus/preset-classic@3.10.2npm/docusaurus-plugin-sass@0.2.6npm/node-polyfill-webpack-plugin@2.0.1npm/es-module-lexer@2.3.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es-module-lexer@2.3.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

See 13 more rows in the dashboard

Ignoring alerts on:

  • @sentry/browser-utils@10.69.0
  • es-toolkit@1.50.0
  • statuses@2.0.2
  • http-errors@2.0.1
  • @docusaurus/core@3.10.2
  • @docusaurus/theme-classic@3.10.2
  • @metamask/eth-json-rpc-infura@10.3.0
  • @metamask/network-controller@23.6.0
  • @parcel/watcher@2.6.0
  • browserify-rsa@4.1.1
  • hash-base@3.0.5
  • crypto-browserify@3.12.1
  • jwa@2.0.1
  • lodash-es@4.18.1
  • ripemd160@2.0.3
  • webpack@5.109.2
  • webpack-dev-server@5.2.6
  • yargs@17.7.3

View full report

@yashovardhan

Copy link
Copy Markdown
Member Author

Socket security review for dependency updates in this PR:

  • Docusaurus 3.10.2 / webpack / yargs: Required toolchain upgrades for the Docusaurus patch release. Webpack and yargs are build-time dependencies with known minified/obfuscated distributions.
  • @metamask/network-controller@23.6.0: Transitive update from @metamask/profile-sync-controller; official MetaMask package used only in docs examples.
  • @sentry/browser-utils@10.69.0: Transitive update from @sentry/browser bump; official Sentry SDK used for client-side error reporting.
  • @parcel/watcher / es-module-lexer / es-toolkit / lodash-es: Transitive build/dev dependencies introduced or bumped by the Docusaurus/tooling update; reviewed package sources and maintainer reputation.

@SocketSecurity ignore npm/webpack@5.109.2
@SocketSecurity ignore npm/yargs@17.7.3
@SocketSecurity ignore npm/@docusaurus/core@3.10.2
@SocketSecurity ignore npm/@docusaurus/theme-classic@3.10.2
@SocketSecurity ignore npm/@metamask/network-controller@23.6.0
@SocketSecurity ignore npm/@sentry/browser-utils@10.69.0
@SocketSecurity ignore npm/@parcel/watcher@2.6.0
@SocketSecurity ignore npm/es-module-lexer@2.3.1
@SocketSecurity ignore npm/es-toolkit@1.50.0
@SocketSecurity ignore npm/lodash-es@4.18.1

@yashovardhan

Copy link
Copy Markdown
Member Author

Follow-up to my earlier ignore list. Two changes since then:

  1. Removed the unused react-spring dependency. It was declared in package.json but imported nowhere in the repo, and it was the sole root of react-native, metro, @react-three/fiber, and three. Dropping it removes the three@0.185.1, metro-runtime@0.83.7, accepts@2.0.0, and negotiator@1.0.0 alerts outright rather than ignoring them, and makes the @react-spring/native, react-native, and @react-native/debugger-frontend overrides unnecessary. Net effect on the lockfile is 512 packages removed against 377 added.
  2. Pinned http-cache-semantics to 4.1.1 (was ^4.1.1, resolving to 4.2.0). 4.2.0 is BSD-2-Clause, which is on the deny-licenses list for the dependency-review check, and it was the only failure there. 4.1.1 is already present in the base branch, so this keeps the fix for the vulnerable 3.8.1 copy without introducing a newly-licensed package.

Review notes for the remaining alerts:

Publisher changed — in every case below the new publisher is already a listed maintainer on the package and the source repository/org is unchanged. Verified against the npm registry (repository.url, _npmUser, maintainers):

  • @metamask/eth-json-rpc-infura@10.3.0gudahttmetamaskbot, our own CI publishing bot, repo still MetaMask/eth-json-rpc-infura.
  • browserify-rsa@4.1.1, crypto-browserify@3.12.1, hash-base@3.0.5, ripemd160@2.0.3cwmma/dcousens/fanatidljharb, who is a listed maintainer on all four; repos still under the crypto-browserify/browserify orgs. These come in transitively via node-polyfill-webpack-plugin.
  • http-errors@2.0.1dougwilsonulisesgascon, part of the documented handover of the jshttp packages to the OpenJS/Express maintainer group; repo still jshttp/http-errors.
  • jwa@2.0.1omsmithpanva, a listed maintainer and the maintainer of the wider JOSE/JWT ecosystem; pulled in by jsonwebtoken.

Potential security risk (AI signal) — heuristic score on a widely used build-time dependency, no concrete finding attached:

  • webpack-dev-server@5.2.6 — transitive from @docusaurus/core, dev-server only, not shipped in the static build output.

@SocketSecurity ignore npm/@metamask/eth-json-rpc-infura@10.3.0
@SocketSecurity ignore npm/browserify-rsa@4.1.1
@SocketSecurity ignore npm/crypto-browserify@3.12.1
@SocketSecurity ignore npm/hash-base@3.0.5
@SocketSecurity ignore npm/ripemd160@2.0.3
@SocketSecurity ignore npm/http-errors@2.0.1
@SocketSecurity ignore npm/jwa@2.0.1
@SocketSecurity ignore npm/webpack-dev-server@5.2.6

@yashovardhan

Copy link
Copy Markdown
Member Author

Rebased onto main (829861ac). The branch is now linear on top of main, the dependency diff is unchanged from the pre-rebase head, and npm run build passes locally against main's current docs.

Re-posting the ignore list in full against the current scan (0977af5d). My two earlier ignore comments were made against scans that have since been superseded by new head commits, so this comment consolidates every blocking alert in one place and adds the one that was not previously covered (statuses@2.0.2).

Scope note: this PR adds no new direct runtime dependency. Every package below arrives transitively through Docusaurus 3.10.2, sass, @sentry/browser, @metamask/profile-sync-controller, jsonwebtoken, or node-polyfill-webpack-plugin, and all of them except @sentry/browser-utils and @metamask/network-controller are build-time only.

Publisher changed (8). In every case the new publisher is already a listed maintainer on the package and the source repository is unchanged. Verified against the npm registry (_npmUser, maintainers, repository.url):

  • @metamask/eth-json-rpc-infura@10.3.0 — now metamaskbot, our own publishing bot and a listed maintainer alongside danfinlay and kumavis; repo still MetaMask/eth-json-rpc-infura. Reached via @metamask/profile-sync-controller@metamask/network-controller.
  • browserify-rsa@4.1.1, crypto-browserify@3.12.1, hash-base@3.0.5, ripemd160@2.0.3 — now ljharb, a listed maintainer on all four; repos still under crypto-browserify/browserify. Reached via node-polyfill-webpack-plugin (and ripemd160 also via @metamask/keyring-controllerhdkey).
  • http-errors@2.0.1 and statuses@2.0.2 — now ulisesgascon, a listed maintainer on both, consistent with the handover of the jshttp packages to the OpenJS/Express maintainer group; repos still jshttp/http-errors and jshttp/statuses. Both reached via @docusaurus/corewebpack-dev-serverexpress, so dev-server only.
  • jwa@2.0.1 — now panva, a listed maintainer and the maintainer of the wider JOSE/JWT ecosystem; repo still brianloveswords/node-jwa. Reached via jsonwebtokenjws.

Obfuscated code (2). webpack@5.109.2 and yargs@17.7.3 — both ship minified distributions, which is what the heuristic fires on. Build-time only, pulled in by the Docusaurus toolchain.

AI-signal risk, no concrete finding attached (6). @docusaurus/core@3.10.2, @docusaurus/theme-classic@3.10.2 (2 alerts), webpack-dev-server@5.2.6, es-toolkit@1.50.0, lodash-es@4.18.1. The last two are new transitive deps of mermaid@11.16.1 under @docusaurus/theme-mermaid. All build-time; webpack-dev-server is not part of the static output.

Capability alerts on packages whose capabilities are expected (4).

  • @metamask/network-controller@23.6.0 (network access) — an RPC client; network access is its purpose. Transitive from @metamask/profile-sync-controller.
  • @sentry/browser-utils@10.69.0 (network access) — official Sentry SDK, transitive from the @sentry/browser bump; sends error reports, which is the reason we use it.
  • @parcel/watcher@2.6.0 (native binaries, shell access) — file watcher used by sass; native prebuilds and child_process are inherent to it. Dev-time only.

The rendered alert table is truncated by GitHub ("See 34 more rows in the dashboard"). If any additional Block alert is in the hidden portion, please flag it and I will review it rather than blanket-ignoring.

@SocketSecurity ignore npm/@metamask/eth-json-rpc-infura@10.3.0
@SocketSecurity ignore npm/browserify-rsa@4.1.1
@SocketSecurity ignore npm/crypto-browserify@3.12.1
@SocketSecurity ignore npm/hash-base@3.0.5
@SocketSecurity ignore npm/ripemd160@2.0.3
@SocketSecurity ignore npm/http-errors@2.0.1
@SocketSecurity ignore npm/statuses@2.0.2
@SocketSecurity ignore npm/jwa@2.0.1
@SocketSecurity ignore npm/webpack@5.109.2
@SocketSecurity ignore npm/yargs@17.7.3
@SocketSecurity ignore npm/@docusaurus/core@3.10.2
@SocketSecurity ignore npm/@docusaurus/theme-classic@3.10.2
@SocketSecurity ignore npm/webpack-dev-server@5.2.6
@SocketSecurity ignore npm/es-toolkit@1.50.0
@SocketSecurity ignore npm/lodash-es@4.18.1
@SocketSecurity ignore npm/@metamask/network-controller@23.6.0
@SocketSecurity ignore npm/@sentry/browser-utils@10.69.0
@SocketSecurity ignore npm/@parcel/watcher@2.6.0

@dodzyp-qyhkuq-0pUwhe dodzyp-qyhkuq-0pUwhe left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mtbet

@yashovardhan

Copy link
Copy Markdown
Member Author

@SocketSecurity ignore npm/@metamask/eth-json-rpc-infura@10.3.0
@SocketSecurity ignore npm/browserify-rsa@4.1.1
@SocketSecurity ignore npm/crypto-browserify@3.12.1
@SocketSecurity ignore npm/hash-base@3.0.5
@SocketSecurity ignore npm/ripemd160@2.0.3
@SocketSecurity ignore npm/http-errors@2.0.1
@SocketSecurity ignore npm/statuses@2.0.2
@SocketSecurity ignore npm/jwa@2.0.1
@SocketSecurity ignore npm/webpack@5.109.2
@SocketSecurity ignore npm/yargs@17.7.3
@SocketSecurity ignore npm/@docusaurus/core@3.10.2
@SocketSecurity ignore npm/@docusaurus/theme-classic@3.10.2
@SocketSecurity ignore npm/webpack-dev-server@5.2.6
@SocketSecurity ignore npm/es-toolkit@1.50.0
@SocketSecurity ignore npm/lodash-es@4.18.1
@SocketSecurity ignore npm/@metamask/network-controller@23.6.0
@SocketSecurity ignore npm/@sentry/browser-utils@10.69.0
@SocketSecurity ignore npm/@parcel/watcher@2.6.0

@yashovardhan

Copy link
Copy Markdown
Member Author

The packages added are already being used and were being indirectly used via certain functions. We never felt the need earlier because some other packages are using them as sub dependencies, hence they were present. To maintain hygiene of the package.json, these were added.

@yashovardhan
yashovardhan merged commit c86286a into main Aug 7, 2026
19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants