Update deps - #3011
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Warning MetaMask internal reviewing guidelines:
Ignoring alerts on:
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Socket security review for dependency updates in this PR:
@SocketSecurity ignore npm/webpack@5.109.2 |
|
Follow-up to my earlier ignore list. Two changes since then:
Review notes for the remaining alerts: Publisher changed — in every case below the new publisher is already a listed maintainer on the package and the source repository/org is unchanged. Verified against the npm registry (
Potential security risk (AI signal) — heuristic score on a widely used build-time dependency, no concrete finding attached:
@SocketSecurity ignore npm/@metamask/eth-json-rpc-infura@10.3.0 |
e659ab8 to
42ead78
Compare
|
Rebased onto Re-posting the ignore list in full against the current scan ( Scope note: this PR adds no new direct runtime dependency. Every package below arrives transitively through Docusaurus 3.10.2, Publisher changed (8). In every case the new publisher is already a listed maintainer on the package and the source repository is unchanged. Verified against the npm registry (
Obfuscated code (2). AI-signal risk, no concrete finding attached (6). Capability alerts on packages whose capabilities are expected (4).
The rendered alert table is truncated by GitHub ("See 34 more rows in the dashboard"). If any additional Block alert is in the hidden portion, please flag it and I will review it rather than blanket-ignoring. @SocketSecurity ignore npm/@metamask/eth-json-rpc-infura@10.3.0 |
|
@SocketSecurity ignore npm/@metamask/eth-json-rpc-infura@10.3.0 |
|
The packages added are already being used and were being indirectly used via certain functions. We never felt the need earlier because some other packages are using them as sub dependencies, hence they were present. To maintain hygiene of the package.json, these were added. |
Update all dependencies, tested against a build
Note
Low Risk
Documentation-only changes to chain reference tables with no runtime or security logic impact.
Overview
Updates
supported-chains.mdso mainnet coverage matches current Transaction Shield wording and ordering.The mainnet table now links the Transaction Shield column to MetaMask support, uses Covered instead of Yes for supported networks, reorders rows (major L2s grouped first), and adds a caution callout for chains marked No (no threat scanning or Transaction Protection; Guard Mode allowlist still applies).
The testnet table drops the Transaction Shield column and reorders networks; it no longer documents per-testnet shield status in the doc.
Reviewed by Cursor Bugbot for commit 8993a05. Bugbot is set up for automated code reviews on this repo. Configure here.