Skip to content

fix(deps): update npm dependencies - #1112

Open
ci-protocols-renovate[bot] wants to merge 3 commits into
mainfrom
renovate/npm-dependencies
Open

ci-protocols-renovate[bot] wants to merge 3 commits into
mainfrom
renovate/npm-dependencies

Conversation

@ci-protocols-renovate

@ci-protocols-renovate ci-protocols-renovate Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
@​agoric/internal 0.4.0-u21.0.10.4.0 age confidence
@agoric/store 0.9.3-u21.0.10.10.0 age confidence
@agoric/swingset-liveslots 0.10.3-u21.0.10.11.0 age confidence
@endo/bundle-source (source) ^4.1.2^4.3.2 age confidence
@endo/captp (source) ^4.4.8^4.5.1 age confidence
@endo/errors (source) ^1.2.13^1.3.1 age confidence
@endo/eventual-send (source) ^1.3.4^1.5.0 age confidence
@endo/exo (source) ^1.5.12^1.7.0 age confidence
@endo/lockdown (source) ^1.0.18^1.0.19 age confidence
@endo/marshal (source) ^1.8.0^1.10.0 age confidence
@endo/pass-style (source) ^1.6.3^1.8.2 age confidence
@endo/patterns (source) ^1.7.0^1.9.1 age confidence
@endo/promise-kit (source) ^1.1.13^1.2.1 age confidence
@endo/stream (source) ^1.2.13^1.3.1 age confidence
@metamask/auto-changelog ^5.3.0^5.3.2 age confidence
@metamask/create-release-branch ^4.1.4^4.2.2 age confidence
@metamask/design-system-react (source) ^0.10.0^0.43.0 age confidence
@metamask/design-system-tailwind-preset (source) ^0.6.1^0.13.0 age confidence
@metamask/design-tokens (source) ^8.1.1^8.7.0 age confidence
@metamask/eslint-config ^15.0.0^15.0.1 age confidence
@metamask/eslint-config-nodejs ^15.0.0^15.0.1 age confidence
@metamask/eslint-config-typescript ^15.0.0^15.0.1 age confidence
@metamask/eslint-config-vitest ^15.0.0^15.0.1 age confidence
@metamask/json-rpc-engine (source) ^10.2.0^10.5.0 age confidence
@metamask/snaps-execution-environments (source) ^11.1.0^11.3.0 age confidence
@metamask/snaps-utils (source) ^12.1.0^12.6.0 age confidence
@metamask/superstruct ^3.2.1^3.4.1 age confidence
@metamask/utils ^11.9.0^11.12.1 age confidence
ses (source) ^1.14.0^1.15.0 age confidence

Warning

Some dependencies could not be looked up. Check the warning logs for more information.


Release Notes

Agoric/agoric-sdk (@​agoric/store)

v0.10.0

Compare Source

0.0.24 (2019-09-26)

0.0.23 (2019-09-26)

v0.9.3-ymax-v0.2-alpha-dev-f741807.0

Compare Source

v0.9.3-ymax-v0.2-alpha-dev-a527ef4.0

Compare Source

v0.9.3-ymax-v0.2-alpha-dev-8e37faa.0

Compare Source

v0.9.3-upgrade-23-dev-982c75a.0.982c75a

Compare Source

v0.9.3-upgrade-23-dev-14155ef.0.14155ef

Compare Source

v0.9.3-upgrade-23-dev-04dbab2.0.04dbab2

Compare Source

v0.9.3-upgrade-22-dev-bb40192.0.bb40192

Compare Source

v0.9.3-upgrade-22-dev-8dbcc20.0.8dbcc20

Compare Source

v0.9.3-upgrade-22-dev-2f770ff.0.2f770ff

Compare Source

v0.9.3-upgrade-21-dev-43b4090.0

Compare Source

v0.9.3-upgrade-21-dev-16519b2.0

Compare Source

v0.9.3-upgrade-21-dev-07d4845.0

Compare Source

v0.9.3-upgrade-20-dev-ef71cfd.0

Compare Source

v0.9.3-upgrade-20-dev-31be299.0

Compare Source

v0.9.3-upgrade-20-dev-086463b.0

Compare Source

v0.9.3-upgrade-19-devnet-dev-5428c4d.0

Compare Source

v0.9.3-upgrade-19-dev-c605745.0

Compare Source

v0.9.3-upgrade-19-dev-ae3bcff.0

Compare Source

v0.9.3-upgrade-19-dev-aa5fa27.0

Compare Source

v0.9.3-upgrade-19-dev-6f73842.0

Compare Source

v0.9.3-upgrade-19-dev-5428c4d.0

Compare Source

v0.9.3-upgrade-19-dev-41378e9.0

Compare Source

v0.9.3-upgrade-19-dev-38ca80a.0

Compare Source

v0.9.3-upgrade-19-dev-2a71f04.0

Compare Source

v0.9.3-upgrade-19-dev-0958ef0.0

Compare Source

v0.9.3-upgrade-19-dev-0754752.0

Compare Source

v0.9.3-upgrade-18a-dev-eaeaf5a.0

Compare Source

v0.9.3-upgrade-18a-dev-bd8fd54.0

Compare Source

v0.9.3-upgrade-18a-dev-61134db.0

Compare Source

v0.9.3-upgrade-18a-dev-4ee0508.0

Compare Source

v0.9.3-upgrade-18a-dev-2899fb9.0

Compare Source

v0.9.3-upgrade-18-emerynet-fix-dev-f8c45b8.0

Compare Source

v0.9.3-upgrade-18-dev-ef001c0.0

Compare Source

v0.9.3-upgrade-18-dev-d7c994b.0

Compare Source

v0.9.3-upgrade-18-dev-cc4b6b8.0

Compare Source

v0.9.3-upgrade-18-dev-bf39b10.0

Compare Source

v0.9.3-upgrade-18-dev-bdbf7c9.0

Compare Source

v0.9.3-upgrade-18-dev-bd8fd54.0

Compare Source

v0.9.3-upgrade-18-dev-b9b8db4.0

Compare Source

v0.9.3-upgrade-18-dev-aaebae4.0

Compare Source

v0.9.3-upgrade-18-dev-a0f4883.0

Compare Source

v0.9.3-upgrade-18-dev-89128d3.0

Compare Source

v0.9.3-upgrade-18-dev-6ddbef0.0

Compare Source

v0.9.3-upgrade-18-dev-6cab101.0

Compare Source

v0.9.3-upgrade-18-dev-6a4fdea.0

Compare Source

v0.9.3-upgrade-18-dev-6083a43.0

Compare Source

v0.9.3-upgrade-18-dev-4704d9b.0

Compare Source

v0.9.3-upgrade-18-dev-1c820e7.0

Compare Source

v0.9.3-upgrade-18-dev-0218510.0

Compare Source

v0.9.3-upgrade-17-dev-ec448b0.0

Compare Source

v0.9.3-upgrade-17-dev-e67cd91.0

Compare Source

v0.9.3-upgrade-17-dev-a890aea.0

Compare Source

v0.9.3-upgrade-17-dev-a61cdab.0

Compare Source

v0.9.3-upgrade-17-dev-a1453b2.0

Compare Source

v0.9.3-upgrade-17-dev-3b97a9f.0

Compare Source

v0.9.3-upgrade-16a-dev-fb592e4.0

Compare Source

v0.9.3-upgrade-16-fi-dev-8879538.0

Compare Source

v0.9.3-upgrade-16-dev-f908f89.0

Compare Source

v0.9.3-upgrade-16-dev-d492653.0

Compare Source

v0.9.3-upgrade-16-dev-d45b478.0

Compare Source

v0.9.3-upgrade-16-dev-b7c2f02.0

Compare Source

v0.9.3-upgrade-16-dev-91eb8f4.0

Compare Source

v0.9.3-upgrade-16-dev-8879538.0

Compare Source

v0.9.3-upgrade-16-dev-5e17008.0

Compare Source

v0.9.3-upgrade-16-dev-5a29e6a.0

Compare Source

v0.9.3-upgrade-16-dev-24665a9.0

Compare Source

v0.9.3-upgrade-16-dev-1c6bbde.0

Compare Source

v0.9.3-upgrade-16-dev-12b78e3.0

Compare Source

v0.9.3-upgrade-16-dev-0df76a7.0

Compare Source

v0.9.3-upgrade-16-dev-07b0130.0

Compare Source

v0.9.3-upgrade-16-dev-0549112.0

Compare Source

v0.9.3-upgrade-14-dev-c8f9e7b.0

Compare Source

v0.9.3-upgrade-14-dev-c2ea6db.0

Compare Source

v0.9.3-upgrade-14-dev-8be87aa.0

Compare Source

v0.9.3-upgrade-14-dev-408fffa.0

Compare Source

v0.9.3-upgrade-14-dev-0a0580c.0

Compare Source

v0.9.3-upgrade-14-dev-0169c7e.0

Compare Source

endojs/endo (@​endo/bundle-source)

v4.3.2

Compare Source

Patch Changes

v4.3.1

Compare Source

Patch Changes
  • #​3261 7309d69 Thanks @​turadg! - Replace ts-blank-space with Amaro for TypeScript type erasure, matching the parser Node.js uses for type stripping.

  • #​3216 7325bbe Thanks @​kriskowal! - @endo/base64's named exports (encodeBase64, decodeBase64, atob, btoa)
    are now frozen.
    Consumers that previously assigned to or extended these exports will see a
    TypeError under SES; read-only consumers are unaffected.

    The shim entry point @endo/base64/shim.js (which @endo/init/pre.js uses to
    install globalThis.atob / globalThis.btoa before lockdown()) is unchanged
    and continues to be safe to load pre-lockdown.

  • #​3237 b845f85 Thanks @​kriskowal! - Update BundleOptions and the powers parameter types to reflect what
    bundleSource already accepts at runtime: cacheSourceMaps is now
    documented on BundleOptions, commonDependencies and importHook
    (only for the endoZipBase64 format) are surfaced, and the optional
    powers parameter accepts the wider BundlePowers shape (including
    pathResolve, userInfo, env, platform, and computeSha512).
    This is a JSDoc/typings-only change; no runtime behavior changes.

  • Updated dependencies [7325bbe, 7325bbe, 69ca27c, 5c098c4, 67ed1ce, 75253ad]:

v4.3.0

Compare Source

Minor Changes
  • #​3180 7f7ae8e Thanks @​turadg! - BundleCache.load() is now generic on the format option:

    • Omitted (default) → Promise<BundleSourceResult<'endoZipBase64'>>
    • Literal format → Promise<BundleSourceResult<format>>
    • Runtime-typed ModuleFormatPromise<BundleSourceResult<ModuleFormat>>

    Previously load() returned Promise<unknown>, requiring callers to assert the bundle shape.

Patch Changes

v4.2.0

Compare Source

Minor Changes
  • #​3008 d83b1ab Thanks @​kriskowal! - - Relaxes dependence on a global, post-lockdown harden function by taking a
    dependency on the new @endo/harden package.
    Consequently, bundles will now entrain a harden implementation that is
    superfluous if the bundled program is guaranteed to run in a post-lockdown
    HardenedJS environment.
    To compensate, use bundle-source with -C hardened or the analogous feature
    for packaging conditions with your preferred bundler tool.
    This will hollow out @endo/harden and defer exclusively to the global
    harden.
Patch Changes
endojs/endo (@​endo/captp)

v4.5.1

Compare Source

Patch Changes

v4.5.0

Compare Source

Minor Changes
  • #​3008 d83b1ab Thanks @​kriskowal! - - Relaxes dependence on a global, post-lockdown harden function by taking a
    dependency on the new @endo/harden package.
    Consequently, bundles will now entrain a harden implementation that is
    superfluous if the bundled program is guaranteed to run in a post-lockdown
    HardenedJS environment.
    To compensate, use bundle-source with -C hardened or the analogous feature
    for packaging conditions with your preferred bundler tool.
    This will hollow out @endo/harden and defer exclusively to the global
    harden.
Patch Changes
endojs/endo (@​endo/errors)

v1.3.1

Compare Source

Patch Changes

v1.3.0

Compare Source

Minor Changes
  • #​3082 2e00276 Thanks @​boneskull! - - Exports assert.details under its own name (i.e., details).
    • hideAndHardenFunction - If a function foo is first frozen with hideAndHardenFunction(foo) rather than freeze(foo) or harden(foo), then foo.name is changed from 'foo' to '__HIDE_foo'. When stackFiltering: 'concise' or stackFiltering: 'omit-frames', then (currently only on v8), the stack frames for that function are omitted from the stacks reported by our causal console.

    • The new Rejector type supports the confirmFoo/reject pattern:

      @&#8203;import {FAIL, hideAndHardenFunction} from '@&#8203;endo@errors';
      @&#8203;import {Rejector} from '@&#8203;endo/errors/rejector.js';
      
      const confirmFoo = (specimen, reject: Rejector) =>
        test(specimen) || reject && reject`explanation of what went wrong`;
      
      export const isFoo = specimen => confirmFoo(specimen, false);
      hideAndHardenFunction(isFoo);
      
      export const assertFoo = specimen => {
        confirmFoo(specimen, FAIL);
      };
      hideAndHardenFunction(assertFoo);

      Both false and Fail satisfy the Rejector type.
      We also deprecate the old checkFoo/assertChecker pattern from @​endo/common.
      The exported isFoo and assertFoo behave the same as they had when then they were using the checkFoo/assertChecker pattern, but are now internally faster and clearer.

Patch Changes
endojs/endo (@​endo/eventual-send)

v1.5.0

Compare Source

Minor Changes
  • #​3172 f65b000 Thanks @​turadg! - Improve E() type inference and publicly export method-projection helpers.

    • RemoteFunctions, PickCallable, and ECallableOrMethods now short-circuit on any, preventing E(anyValue) from collapsing to an unusable type.
    • EMethods, EGetters, and related helpers are now part of the public type surface, so downstream packages can name the projected shapes E() produces.

    Compile-time type changes only; no runtime behavior changes.

Patch Changes

v1.4.0

Compare Source

Minor Changes
  • #​3008 d83b1ab Thanks @​kriskowal! - - Relaxes dependence on a global, post-lockdown harden function by taking a
    dependency on the new @endo/harden package.
    Consequently, bundles will now entrain a harden implementation that is
    superfluous if the bundled program is guaranteed to run in a post-lockdown
    HardenedJS environment.
    To compensate, use bundle-source with -C hardened or the analogous feature
    for packaging conditions with your preferred bundler tool.
    This will hollow out @endo/harden and defer exclusively to the global
    harden.
Patch Changes
endojs/endo (@​endo/exo)

[`v1.7.0

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 7am"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.


Note

Medium Risk
Wide bumps to ses, Agoric liveslots, and Endo packages touch core kernel and sandbox behavior; the design-system major-style jump in kernel-ui adds UI regression risk despite no code edits in this PR.

Overview
This PR only updates dependency version ranges in root and workspace package.json files; there are no application source changes in the diff.

It refreshes shared MetaMask tooling (@metamask/eslint-config*, auto-changelog, create-release-branch) and bumps @metamask/superstruct, @metamask/utils, json-rpc-engine, and Snaps-related packages where the browser runtime and core kernel depend on them.

The Endo / HardenedJS stack moves forward together—ses 1.14 → 1.15, plus newer @endo/eventual-send, captp, marshal, exo, patterns, promise-kit, pass-style, bundle-source, and related packages—across kernel shims, agents, extension, and test packages.

Agoric pins change from upgrade-tagged builds to release lines: @agoric/internal, @agoric/store, and @agoric/swingset-liveslots on ocap-kernel and kernel-test.

The largest consumer-facing jump is in kernel-ui: @metamask/design-system-react, tailwind preset, and design-tokens are bumped by several minor/major steps, which may affect control-panel styling and component APIs after install.

Reviewed by Cursor Bugbot for commit f393fe4. Bugbot is set up for automated code reviews on this repo. Configure here.

@ci-protocols-renovate
ci-protocols-renovate Bot requested a review from a team as a code owner September 18, 2026 01:18
@ci-protocols-renovate

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: yarn.lock
! Corepack is about to download https://repo.yarnpkg.com/4.12.0/packages/yarnpkg-cli/bin/yarn.js

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread package.json
"libp2p": "3.1.7",
"multiformats": "^13.3.6",
"ses": "^1.14.0",
"ses": "^1.15.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SES 1.x conflicts with SES 2

High Severity

@endo/errors ^1.3.1 and the new @agoric/store / @agoric/swingset-liveslots releases depend on ses 2.x, while this repo still pins ses ^1.15.0. That can install two SES copies or fail resolution. Dual SES is unsafe here because lockdown mutates the shared realm.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 2ddfe81. Configure here.

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.

There are 3 total unresolved issues (including 1 from previous review).

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f393fe4. Configure here.

"@endo/errors": "^1.3.1",
"@endo/exo": "^1.7.0",
"@endo/patterns": "^1.9.1",
"@endo/promise-kit": "^1.2.1",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Endo upgrades pull SES 2

High Severity

@endo/errors 1.3.1 (and related Endo/Agoric packages in this bump) declare a dependency on ses@2.0.0, while this repo only moves ses to ^1.15.0. That can install two SES copies. In a Hardened JS kernel, dual ses/harden implementations can fail lockdown() or break vat messaging.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit f393fe4. Configure here.

"@metamask/design-tokens": "^8.1.1",
"@metamask/design-system-react": "^0.43.0",
"@metamask/design-system-tailwind-preset": "^0.13.0",
"@metamask/design-tokens": "^8.7.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Design system Tailwind scan outdated

Medium Severity

@metamask/design-system-react jumps from 0.10.0 to 0.43.0, which moved typography and class-name maps into @metamask/design-system-shared. packages/kernel-ui/tailwind.config.js still scans only design-system-react, so Tailwind can omit classes used by Text, Button, and Box.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit f393fe4. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants