Skip to content

Conversation

@legobeat
Copy link
Contributor

@legobeat legobeat commented Oct 24, 2024

Description

Update eth-json-rpc-middleware from 4.3.0 (2019-10-05) to 9.0.1 (2022-10-05).

Related issues

Blocked by

Manual testing steps

Screenshots/Recordings

Before

After

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

@github-actions
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@socket-security
Copy link

socket-security bot commented Oct 24, 2024

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: npm/ethereumjs-abi@0.6.6, npm/eth-json-rpc-middleware@9.0.1

View full report↗︎

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

@legobeat legobeat added dependencies Pull requests that update a dependency file team-application-security Application security team and removed team-lavamoat labels Oct 24, 2024
@legobeat
Copy link
Contributor Author

@SocketSecurity ignore npm/eth-json-rpc-middleware@9.0.1

network access ok

@legobeat
Copy link
Contributor Author

@SocketSecurity ignore npm/ethereumjs-abi@0.6.6

False positive - this package is already part of runtime dependencies (also "new" author ok)

@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-9 branch 2 times, most recently from 9da2e59 to ad03624 Compare October 24, 2024 16:32
@github-actions
Copy link
Contributor

github-actions bot commented Oct 24, 2024

https://bitrise.io/ Bitrise

✅✅✅ pr_smoke_e2e_pipeline passed on Bitrise! ✅✅✅

Commit hash: ad03624
Build link: https://app.bitrise.io/app/be69d4368ee7e86d/pipelines/fae658da-9e30-4a58-9853-52f7d8281027

Note

  • You can kick off another pr_smoke_e2e_pipeline on Bitrise by removing and re-applying the Run Smoke E2E label on the pull request

@legobeat legobeat marked this pull request as ready for review October 24, 2024 17:09
@legobeat legobeat requested review from a team as code owners October 24, 2024 17:09
@legobeat legobeat requested a review from a team October 24, 2024 17:09
@legobeat legobeat requested a review from a team as a code owner October 24, 2024 17:09
@legobeat legobeat added the team-mobile-platform Mobile Platform team label Oct 24, 2024
@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-9 branch from ad03624 to 7bead32 Compare October 25, 2024 01:31
github-merge-queue bot pushed a commit that referenced this pull request Oct 25, 2024
## **Description**

- Bump legacy `eth-json-rpc-filters` from v5 to v6

## **Related issues**

Follow-up to: #11975

### Blocking
- #12008
  -  #11952

## **Manual testing steps**


## **Screenshots/Recordings**

### **Before**

### **After**

## **Pre-merge author checklist**

- [x] I’ve followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-9 branch 2 times, most recently from 1ba8142 to afaea63 Compare October 25, 2024 02:16
@github-actions
Copy link
Contributor

github-actions bot commented Oct 25, 2024

https://bitrise.io/ Bitrise

✅✅✅ pr_smoke_e2e_pipeline passed on Bitrise! ✅✅✅

Commit hash: afaea63
Build link: https://app.bitrise.io/app/be69d4368ee7e86d/pipelines/5ec914c8-cd12-4cf3-9d5c-e5bf6997aa3b

Note

  • You can kick off another pr_smoke_e2e_pipeline on Bitrise by removing and re-applying the Run Smoke E2E label on the pull request

Copy link
Contributor

@tommasini tommasini left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@legobeat legobeat enabled auto-merge October 25, 2024 15:16
Copy link
Contributor

@Cal-L Cal-L left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-9 branch from afaea63 to 893c9a3 Compare October 25, 2024 22:07
@legobeat legobeat added the team-snaps-platform-deprecated DEPRECATED: please use "team-core-platform" instead (or "team-new-networks" for Solana snap issues) label Oct 25, 2024
@legobeat legobeat force-pushed the deps-eth-json-rpc-middleware-9 branch from 893c9a3 to d41baf0 Compare October 28, 2024 09:22
@github-actions
Copy link
Contributor

github-actions bot commented Oct 28, 2024

https://bitrise.io/ Bitrise

✅✅✅ pr_smoke_e2e_pipeline passed on Bitrise! ✅✅✅

Commit hash: d41baf0
Build link: https://app.bitrise.io/app/be69d4368ee7e86d/pipelines/9d541012-d348-4fe6-994c-f8cdbc60a638

Note

  • You can kick off another pr_smoke_e2e_pipeline on Bitrise by removing and re-applying the Run Smoke E2E label on the pull request

@sonarqubecloud
Copy link

@legobeat legobeat added this pull request to the merge queue Oct 28, 2024
Merged via the queue into main with commit e958436 Oct 28, 2024
42 of 43 checks passed
@legobeat legobeat deleted the deps-eth-json-rpc-middleware-9 branch October 28, 2024 10:21
@github-actions github-actions bot locked and limited conversation to collaborators Oct 28, 2024
@metamaskbot metamaskbot added the release-7.35.0 Issue or pull request that will be included in release 7.35.0 label Oct 28, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file release-7.35.0 Issue or pull request that will be included in release 7.35.0 team-application-security Application security team team-mobile-platform Mobile Platform team team-snaps-platform-deprecated DEPRECATED: please use "team-core-platform" instead (or "team-new-networks" for Solana snap issues)

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

7 participants