fix(deps): update npm dependencies - #1112
ci-protocols-renovate[bot] wants to merge 3 commits into
Conversation
|
| "libp2p": "3.1.7", | ||
| "multiformats": "^13.3.6", | ||
| "ses": "^1.14.0", | ||
| "ses": "^1.15.0", |
There was a problem hiding this comment.
SES 1.x conflicts with SES 2
High Severity
@endo/errors ^1.3.1 and the new @agoric/store / @agoric/swingset-liveslots releases depend on ses 2.x, while this repo still pins ses ^1.15.0. That can install two SES copies or fail resolution. Dual SES is unsafe here because lockdown mutates the shared realm.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit 2ddfe81. Configure here.
Signed-off-by: Erik Marks <erik.marks@consensys.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
There are 3 total unresolved issues (including 1 from previous review).
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit f393fe4. Configure here.
| "@endo/errors": "^1.3.1", | ||
| "@endo/exo": "^1.7.0", | ||
| "@endo/patterns": "^1.9.1", | ||
| "@endo/promise-kit": "^1.2.1", |
There was a problem hiding this comment.
Endo upgrades pull SES 2
High Severity
@endo/errors 1.3.1 (and related Endo/Agoric packages in this bump) declare a dependency on ses@2.0.0, while this repo only moves ses to ^1.15.0. That can install two SES copies. In a Hardened JS kernel, dual ses/harden implementations can fail lockdown() or break vat messaging.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit f393fe4. Configure here.
| "@metamask/design-tokens": "^8.1.1", | ||
| "@metamask/design-system-react": "^0.43.0", | ||
| "@metamask/design-system-tailwind-preset": "^0.13.0", | ||
| "@metamask/design-tokens": "^8.7.0", |
There was a problem hiding this comment.
Design system Tailwind scan outdated
Medium Severity
@metamask/design-system-react jumps from 0.10.0 to 0.43.0, which moved typography and class-name maps into @metamask/design-system-shared. packages/kernel-ui/tailwind.config.js still scans only design-system-react, so Tailwind can omit classes used by Text, Button, and Box.
Reviewed by Cursor Bugbot for commit f393fe4. Configure here.


This PR contains the following updates:
0.4.0-u21.0.1→0.4.00.9.3-u21.0.1→0.10.00.10.3-u21.0.1→0.11.0^4.1.2→^4.3.2^4.4.8→^4.5.1^1.2.13→^1.3.1^1.3.4→^1.5.0^1.5.12→^1.7.0^1.0.18→^1.0.19^1.8.0→^1.10.0^1.6.3→^1.8.2^1.7.0→^1.9.1^1.1.13→^1.2.1^1.2.13→^1.3.1^5.3.0→^5.3.2^4.1.4→^4.2.2^0.10.0→^0.43.0^0.6.1→^0.13.0^8.1.1→^8.7.0^15.0.0→^15.0.1^15.0.0→^15.0.1^15.0.0→^15.0.1^15.0.0→^15.0.1^10.2.0→^10.5.0^11.1.0→^11.3.0^12.1.0→^12.6.0^3.2.1→^3.4.1^11.9.0→^11.12.1^1.14.0→^1.15.0Warning
Some dependencies could not be looked up. Check the warning logs for more information.
Release Notes
Agoric/agoric-sdk (@agoric/store)
v0.10.0Compare Source
0.0.24 (2019-09-26)
0.0.23 (2019-09-26)
v0.9.3-ymax-v0.2-alpha-dev-f741807.0Compare Source
v0.9.3-ymax-v0.2-alpha-dev-a527ef4.0Compare Source
v0.9.3-ymax-v0.2-alpha-dev-8e37faa.0Compare Source
v0.9.3-upgrade-23-dev-982c75a.0.982c75aCompare Source
v0.9.3-upgrade-23-dev-14155ef.0.14155efCompare Source
v0.9.3-upgrade-23-dev-04dbab2.0.04dbab2Compare Source
v0.9.3-upgrade-22-dev-bb40192.0.bb40192Compare Source
v0.9.3-upgrade-22-dev-8dbcc20.0.8dbcc20Compare Source
v0.9.3-upgrade-22-dev-2f770ff.0.2f770ffCompare Source
v0.9.3-upgrade-21-dev-43b4090.0Compare Source
v0.9.3-upgrade-21-dev-16519b2.0Compare Source
v0.9.3-upgrade-21-dev-07d4845.0Compare Source
v0.9.3-upgrade-20-dev-ef71cfd.0Compare Source
v0.9.3-upgrade-20-dev-31be299.0Compare Source
v0.9.3-upgrade-20-dev-086463b.0Compare Source
v0.9.3-upgrade-19-devnet-dev-5428c4d.0Compare Source
v0.9.3-upgrade-19-dev-c605745.0Compare Source
v0.9.3-upgrade-19-dev-ae3bcff.0Compare Source
v0.9.3-upgrade-19-dev-aa5fa27.0Compare Source
v0.9.3-upgrade-19-dev-6f73842.0Compare Source
v0.9.3-upgrade-19-dev-5428c4d.0Compare Source
v0.9.3-upgrade-19-dev-41378e9.0Compare Source
v0.9.3-upgrade-19-dev-38ca80a.0Compare Source
v0.9.3-upgrade-19-dev-2a71f04.0Compare Source
v0.9.3-upgrade-19-dev-0958ef0.0Compare Source
v0.9.3-upgrade-19-dev-0754752.0Compare Source
v0.9.3-upgrade-18a-dev-eaeaf5a.0Compare Source
v0.9.3-upgrade-18a-dev-bd8fd54.0Compare Source
v0.9.3-upgrade-18a-dev-61134db.0Compare Source
v0.9.3-upgrade-18a-dev-4ee0508.0Compare Source
v0.9.3-upgrade-18a-dev-2899fb9.0Compare Source
v0.9.3-upgrade-18-emerynet-fix-dev-f8c45b8.0Compare Source
v0.9.3-upgrade-18-dev-ef001c0.0Compare Source
v0.9.3-upgrade-18-dev-d7c994b.0Compare Source
v0.9.3-upgrade-18-dev-cc4b6b8.0Compare Source
v0.9.3-upgrade-18-dev-bf39b10.0Compare Source
v0.9.3-upgrade-18-dev-bdbf7c9.0Compare Source
v0.9.3-upgrade-18-dev-bd8fd54.0Compare Source
v0.9.3-upgrade-18-dev-b9b8db4.0Compare Source
v0.9.3-upgrade-18-dev-aaebae4.0Compare Source
v0.9.3-upgrade-18-dev-a0f4883.0Compare Source
v0.9.3-upgrade-18-dev-89128d3.0Compare Source
v0.9.3-upgrade-18-dev-6ddbef0.0Compare Source
v0.9.3-upgrade-18-dev-6cab101.0Compare Source
v0.9.3-upgrade-18-dev-6a4fdea.0Compare Source
v0.9.3-upgrade-18-dev-6083a43.0Compare Source
v0.9.3-upgrade-18-dev-4704d9b.0Compare Source
v0.9.3-upgrade-18-dev-1c820e7.0Compare Source
v0.9.3-upgrade-18-dev-0218510.0Compare Source
v0.9.3-upgrade-17-dev-ec448b0.0Compare Source
v0.9.3-upgrade-17-dev-e67cd91.0Compare Source
v0.9.3-upgrade-17-dev-a890aea.0Compare Source
v0.9.3-upgrade-17-dev-a61cdab.0Compare Source
v0.9.3-upgrade-17-dev-a1453b2.0Compare Source
v0.9.3-upgrade-17-dev-3b97a9f.0Compare Source
v0.9.3-upgrade-16a-dev-fb592e4.0Compare Source
v0.9.3-upgrade-16-fi-dev-8879538.0Compare Source
v0.9.3-upgrade-16-dev-f908f89.0Compare Source
v0.9.3-upgrade-16-dev-d492653.0Compare Source
v0.9.3-upgrade-16-dev-d45b478.0Compare Source
v0.9.3-upgrade-16-dev-b7c2f02.0Compare Source
v0.9.3-upgrade-16-dev-91eb8f4.0Compare Source
v0.9.3-upgrade-16-dev-8879538.0Compare Source
v0.9.3-upgrade-16-dev-5e17008.0Compare Source
v0.9.3-upgrade-16-dev-5a29e6a.0Compare Source
v0.9.3-upgrade-16-dev-24665a9.0Compare Source
v0.9.3-upgrade-16-dev-1c6bbde.0Compare Source
v0.9.3-upgrade-16-dev-12b78e3.0Compare Source
v0.9.3-upgrade-16-dev-0df76a7.0Compare Source
v0.9.3-upgrade-16-dev-07b0130.0Compare Source
v0.9.3-upgrade-16-dev-0549112.0Compare Source
v0.9.3-upgrade-14-dev-c8f9e7b.0Compare Source
v0.9.3-upgrade-14-dev-c2ea6db.0Compare Source
v0.9.3-upgrade-14-dev-8be87aa.0Compare Source
v0.9.3-upgrade-14-dev-408fffa.0Compare Source
v0.9.3-upgrade-14-dev-0a0580c.0Compare Source
v0.9.3-upgrade-14-dev-0169c7e.0Compare Source
endojs/endo (@endo/bundle-source)
v4.3.2Compare Source
Patch Changes
#3186
d5e2498Thanks @boneskull! - Fixes poorly-defined support for asynchronous parsers.Updated dependencies [
d5e2498,fe6be07,c4337e5]:v4.3.1Compare Source
Patch Changes
#3261
7309d69Thanks @turadg! - Replacets-blank-spacewith Amaro for TypeScript type erasure, matching the parser Node.js uses for type stripping.#3216
7325bbeThanks @kriskowal! -@endo/base64's named exports (encodeBase64,decodeBase64,atob,btoa)are now frozen.
Consumers that previously assigned to or extended these exports will see a
TypeErrorunder SES; read-only consumers are unaffected.The shim entry point
@endo/base64/shim.js(which@endo/init/pre.jsuses toinstall
globalThis.atob/globalThis.btoabeforelockdown()) is unchangedand continues to be safe to load pre-lockdown.
#3237
b845f85Thanks @kriskowal! - UpdateBundleOptionsand thepowersparameter types to reflect whatbundleSourcealready accepts at runtime:cacheSourceMapsis nowdocumented on
BundleOptions,commonDependenciesandimportHook(only for the
endoZipBase64format) are surfaced, and the optionalpowersparameter accepts the widerBundlePowersshape (includingpathResolve,userInfo,env,platform, andcomputeSha512).This is a JSDoc/typings-only change; no runtime behavior changes.
Updated dependencies [
7325bbe,7325bbe,69ca27c,5c098c4,67ed1ce,75253ad]:v4.3.0Compare Source
Minor Changes
#3180
7f7ae8eThanks @turadg! -BundleCache.load()is now generic on theformatoption:Promise<BundleSourceResult<'endoZipBase64'>>Promise<BundleSourceResult<format>>ModuleFormat→Promise<BundleSourceResult<ModuleFormat>>Previously
load()returnedPromise<unknown>, requiring callers to assert the bundle shape.Patch Changes
154102b,2b674ca,d1d9625,b4820dc,acbacba,cdb6eae,6ada52b,6ad084a,1cd1246]:v4.2.0Compare Source
Minor Changes
d83b1abThanks @kriskowal! - - Relaxes dependence on a global, post-lockdownhardenfunction by taking adependency on the new
@endo/hardenpackage.Consequently, bundles will now entrain a
hardenimplementation that issuperfluous if the bundled program is guaranteed to run in a post-lockdown
HardenedJS environment.
To compensate, use
bundle-sourcewith-C hardenedor the analogous featurefor packaging conditions with your preferred bundler tool.
This will hollow out
@endo/hardenand defer exclusively to the globalharden.Patch Changes
#3083
644ab15Thanks @turadg! - Fix bundle cache corner cases, improve cache-root validation, and clarify CLI docs forendoScriptbundle format.Updated dependencies [
2e00276,029dcc4,d83b1ab,b8b52ce,a2c32ec,81b4c40]:endojs/endo (@endo/captp)
v4.5.1Compare Source
Patch Changes
69ca27cThanks @kriskowal! - SweepmakeFinalizingMap'sgetoperator to use optional chaining(
keyToRef.get(key)?.deref()) now that #1514 has completed, replacingthe prior explicit conditional. Behavior is unchanged.
45d06cd]:v4.5.0Compare Source
Minor Changes
d83b1abThanks @kriskowal! - - Relaxes dependence on a global, post-lockdownhardenfunction by taking adependency on the new
@endo/hardenpackage.Consequently, bundles will now entrain a
hardenimplementation that issuperfluous if the bundled program is guaranteed to run in a post-lockdown
HardenedJS environment.
To compensate, use
bundle-sourcewith-C hardenedor the analogous featurefor packaging conditions with your preferred bundler tool.
This will hollow out
@endo/hardenand defer exclusively to the globalharden.Patch Changes
2e00276,029dcc4,d83b1ab,98f77e9]:endojs/endo (@endo/errors)
v1.3.1Compare Source
Patch Changes
e619205,a675d8e]:v1.3.0Compare Source
Minor Changes
2e00276Thanks @boneskull! - - Exportsassert.detailsunder its own name (i.e.,details).hideAndHardenFunction- If a functionfoois first frozen withhideAndHardenFunction(foo)rather thanfreeze(foo)orharden(foo), thenfoo.nameis changed from'foo'to'__HIDE_foo'. WhenstackFiltering: 'concise'orstackFiltering: 'omit-frames', then (currently only on v8), the stack frames for that function are omitted from the stacks reported by our causal console.The new
Rejectortype supports the confirmFoo/reject pattern:Both
falseandFailsatisfy theRejectortype.We also deprecate the old checkFoo/assertChecker pattern from @endo/common.
The exported
isFooandassertFoobehave the same as they had when then they were using the checkFoo/assertChecker pattern, but are now internally faster and clearer.Patch Changes
2e00276,029dcc4,a29ecd4]:endojs/endo (@endo/eventual-send)
v1.5.0Compare Source
Minor Changes
#3172
f65b000Thanks @turadg! - ImproveE()type inference and publicly export method-projection helpers.RemoteFunctions,PickCallable, andECallableOrMethodsnow short-circuit onany, preventingE(anyValue)from collapsing to an unusable type.EMethods,EGetters, and related helpers are now part of the public type surface, so downstream packages can name the projected shapesE()produces.Compile-time type changes only; no runtime behavior changes.
Patch Changes
v1.4.0Compare Source
Minor Changes
d83b1abThanks @kriskowal! - - Relaxes dependence on a global, post-lockdownhardenfunction by taking adependency on the new
@endo/hardenpackage.Consequently, bundles will now entrain a
hardenimplementation that issuperfluous if the bundled program is guaranteed to run in a post-lockdown
HardenedJS environment.
To compensate, use
bundle-sourcewith-C hardenedor the analogous featurefor packaging conditions with your preferred bundler tool.
This will hollow out
@endo/hardenand defer exclusively to the globalharden.Patch Changes
029dcc4]:endojs/endo (@endo/exo)
[`v1.7.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
Note
Medium Risk
Wide bumps to ses, Agoric liveslots, and Endo packages touch core kernel and sandbox behavior; the design-system major-style jump in kernel-ui adds UI regression risk despite no code edits in this PR.
Overview
This PR only updates dependency version ranges in root and workspace
package.jsonfiles; there are no application source changes in the diff.It refreshes shared MetaMask tooling (
@metamask/eslint-config*,auto-changelog,create-release-branch) and bumps@metamask/superstruct,@metamask/utils,json-rpc-engine, and Snaps-related packages where the browser runtime and core kernel depend on them.The Endo / HardenedJS stack moves forward together—
ses1.14 → 1.15, plus newer@endo/eventual-send,captp,marshal,exo,patterns,promise-kit,pass-style,bundle-source, and related packages—across kernel shims, agents, extension, and test packages.Agoric pins change from upgrade-tagged builds to release lines:
@agoric/internal,@agoric/store, and@agoric/swingset-liveslotsonocap-kernelandkernel-test.The largest consumer-facing jump is in
kernel-ui:@metamask/design-system-react, tailwind preset, and design-tokens are bumped by several minor/major steps, which may affect control-panel styling and component APIs after install.Reviewed by Cursor Bugbot for commit f393fe4. Bugbot is set up for automated code reviews on this repo. Configure here.