Skip to content

Conversation

@legobeat
Copy link
Contributor

@legobeat legobeat commented Feb 23, 2024

Description

Fix broken 2.8.0 release https://github.com/JoshGlazebrook/socks/releases/tag/2.8.1

Related issues

Resolves npm audit advisory: https://app.circleci.com/jobs/github/MetaMask/metamask-extension/2378828

Manual testing steps

  1. Go to this page...

Screenshots/Recordings

Before

After

Pre-merge author checklist

  • I’ve followed MetaMask Coding Standards.
  • I've clearly explained what problem this PR is solving and how it is solved.
  • I've linked related issues
  • I've included manual testing steps
  • I've included screenshots/recordings if applicable
  • I’ve included tests if applicable
  • I’ve documented my code using JSDoc format if applicable
  • I’ve applied the right labels on the PR (see labeling guidelines). Not required for external contributors.
  • I’ve properly set the pull request status:
    • In case it's not yet "ready for review", I've set it to "draft".
    • In case it's "ready for review", I've changed it from "draft" to "non-draft".

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

@github-actions
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@legobeat legobeat added the dependencies Pull requests that update a dependency file label Feb 23, 2024
@socket-security
Copy link

socket-security bot commented Feb 23, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/socks@2.8.1 network +4 558 kB joshglazebrook

🚮 Removed packages: npm/socks@2.8.0

View full report↗︎

@legobeat legobeat changed the title deps: socks@2.8.0->2.8.1 fix(deps): socks@2.8.0->2.8.1 Feb 23, 2024
@legobeat legobeat marked this pull request as ready for review February 23, 2024 05:07
@legobeat legobeat requested a review from a team as a code owner February 23, 2024 05:07
@legobeat legobeat requested a review from a team February 23, 2024 07:34
@legobeat legobeat merged commit d7423ef into MetaMask:develop Feb 23, 2024
@github-actions github-actions bot locked and limited conversation to collaborators Feb 23, 2024
@legobeat legobeat deleted the deps-socks branch February 23, 2024 12:11
@metamaskbot metamaskbot added the release-11.11.0 Issue or pull request that will be included in release 11.11.0 label Feb 23, 2024
@metamaskbot
Copy link
Collaborator

No release label on PR. Adding release label release-11.11.0 on PR, as PR was cherry-picked in branch 11.11.0.

@metamaskbot metamaskbot added release-11.10.1 Issue or pull request that will be included in release 11.10.1 and removed release-11.11.0 Issue or pull request that will be included in release 11.11.0 labels Feb 27, 2024
@metamaskbot
Copy link
Collaborator

Missing release label release-11.10.1 on PR. Adding release label release-11.10.1 on PR and removing other release labels(release-11.11.0), as PR was cherry-picked in branch 11.10.1.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file release-11.10.1 Issue or pull request that will be included in release 11.10.1 team-application-security Application security team type-security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants