Skip to content

Conversation

@legobeat
Copy link
Contributor

@legobeat legobeat commented Oct 23, 2024

Description

Previously, eth-json-rpc-middleware is pinned to 4.3.0 (2019-10-05).
This bumps to ^7.0.1 (2021-03-26), with intention to follow up with further upgrade as follow-up.

Related issues

Manual testing steps

Screenshots/Recordings

Before

After

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

@github-actions
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@legobeat legobeat changed the title deps: eth-json-rpc-middleware@4.3.0->^7.0.1 fix(deps): eth-json-rpc-middleware@4.3.0->^7.0.1 Oct 23, 2024
@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-7 branch from b00520b to c414e9a Compare October 23, 2024 10:20
@legobeat legobeat added Run Smoke E2E dependencies Pull requests that update a dependency file team-application-security Application security team labels Oct 23, 2024
@github-actions

This comment was marked as outdated.

@github-actions

This comment was marked as outdated.

@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-7 branch from e5369c6 to 7b22336 Compare October 23, 2024 11:02
@github-actions

This comment was marked as outdated.

@github-actions

This comment was marked as outdated.

github-merge-queue bot pushed a commit that referenced this pull request Oct 23, 2024
## **Description**

Bump `eth-json-rpc-filters`

## **Related issues**

- #11973

#### Blocking
- #11968

## **Manual testing steps**


## **Screenshots/Recordings**

### **Before**

### **After**

## **Pre-merge author checklist**

- [x] I’ve followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-7 branch from 86dbcf7 to 286da2f Compare October 24, 2024 17:25
@socket-security
Copy link

socket-security bot commented Oct 24, 2024

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: npm/eth-json-rpc-middleware@7.0.1

View full report↗︎

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-7 branch from 286da2f to 56589fb Compare October 25, 2024 08:50
@legobeat
Copy link
Contributor Author

@SocketSecurity ignore npm/eth-json-rpc-middleware@7.0.1

network access ok

@github-actions
Copy link
Contributor

github-actions bot commented Oct 25, 2024

https://bitrise.io/ Bitrise

❌❌❌ pr_smoke_e2e_pipeline failed on Bitrise! ❌❌❌

Commit hash: 56589fb
Build link: https://app.bitrise.io/app/be69d4368ee7e86d/pipelines/79a4a37a-038a-4b42-8620-2a407c5cc0a4

Note

  • You can kick off another pr_smoke_e2e_pipeline on Bitrise by removing and re-applying the Run Smoke E2E label on the pull request

Tip

  • Check the documentation if you have any doubts on how to understand the failure on bitrise

@sonarqubecloud
Copy link

@legobeat
Copy link
Contributor Author

@legobeat legobeat closed this Oct 28, 2024
@github-actions github-actions bot locked and limited conversation to collaborators Oct 28, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file team-application-security Application security team team-lavamoat

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants