Skip to content
This repository has been archived by the owner on Oct 7, 2024. It is now read-only.

chore(deps): bump '@metamask/*' and peer dependencies #382

Merged
merged 5 commits into from
Sep 12, 2024
Merged

Conversation

danroc
Copy link
Contributor

@danroc danroc commented Sep 11, 2024

This PR bumps several @metamask/* dependencies and eslint-related peer dependencies.

Copy link

socket-security bot commented Sep 11, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@es-joy/jsdoccomment@0.41.0 None 0 113 kB brettz9
npm/@eslint-community/regexpp@4.11.0 None 0 446 kB eslint-community-bot
npm/@lavamoat/aa@4.3.0 None 0 20.1 kB lmbot
npm/@lavamoat/allow-scripts@3.2.1 None 0 0 B
npm/@lavamoat/preinstall-always-fail@2.1.0 None 0 3.53 kB lmbot
npm/@metamask/eslint-config-jest@13.0.0 None 0 9.35 kB metamaskbot
npm/@metamask/eslint-config-typescript@13.0.0 None 0 19.1 kB metamaskbot
npm/@metamask/eslint-config@13.0.0 None 0 120 kB metamaskbot
npm/@metamask/providers@17.2.0 None 0 434 kB metamaskbot
npm/@npmcli/run-script@8.1.0 environment 0 18.3 kB npm-cli-ops
npm/@types/eslint@8.56.12 None 0 193 kB types
npm/@types/json-schema@7.0.15 None 0 31.7 kB types
npm/@types/node@20.16.5 None 0 2.17 MB types
npm/@types/uuid@10.0.0 None 0 7.82 kB types
npm/@typescript-eslint/eslint-plugin@8.5.0 None 0 2.62 MB bradzacher, jameshenry
npm/@typescript-eslint/parser@8.5.0 None 0 18.7 kB bradzacher, jameshenry
npm/@typescript-eslint/scope-manager@8.5.0 None 0 602 kB bradzacher, jameshenry
npm/@typescript-eslint/type-utils@8.5.0 None 0 114 kB bradzacher, jameshenry
npm/@typescript-eslint/types@8.5.0 None 0 171 kB jameshenry
npm/@typescript-eslint/typescript-estree@8.5.0 None 0 587 kB bradzacher, jameshenry
npm/@typescript-eslint/utils@8.5.0 None 0 282 kB bradzacher, jameshenry
npm/@typescript-eslint/visitor-keys@8.5.0 None 0 19.5 kB bradzacher, jameshenry
npm/acorn@8.12.1 None 0 538 kB marijn
npm/are-docs-informative@0.0.2 None 0 13.6 kB joshuakgoldberg
npm/bin-links@4.0.4 filesystem 0 20.7 kB npm-cli-ops
npm/builtin-modules@3.3.0 unsafe 0 4.51 kB sindresorhus
npm/builtins@5.1.0 None 0 3.7 kB juliangruber
npm/comment-parser@1.4.1 None 0 366 kB yavorskiys
npm/eslint-compat-utils@0.5.1 filesystem 0 53.1 kB ota-meshi
npm/eslint-plugin-es-x@7.8.0 None 0 409 kB eslint-community-bot
npm/eslint-plugin-import-x@0.5.3 None 0 638 kB jounqin
npm/eslint-plugin-jsdoc@47.0.2 filesystem 0 1.38 MB gajus
npm/eslint-plugin-n@16.6.2 filesystem 0 348 kB weiran.zsd
npm/eslint-plugin-promise@6.6.0 None 0 72.5 kB eslint-community-bot
npm/eslint-scope@7.2.2 None 0 146 kB eslintbot
npm/esquery@1.6.0 None 0 1.04 MB michaelficarra
npm/fast-glob@3.3.2 filesystem 0 96.7 kB mrmlnc
npm/flat-cache@3.2.0 filesystem 0 29.4 kB jaredwray
npm/flatted@3.3.1 None 0 40.3 kB webreflection
npm/get-tsconfig@4.8.0 filesystem 0 105 kB hirokiosame
npm/globby@13.1.4 None 0 24.8 kB sindresorhus
npm/ignore@5.3.2 None 0 53.6 kB kael
npm/is-builtin-module@3.2.1 None 0 3.88 kB sindresorhus
npm/is-core-module@2.15.1 None 0 32.7 kB ljharb
npm/jest-it-up@3.2.0 filesystem 0 9.8 kB rbardini
npm/jsdoc-type-pratt-parser@4.0.0 None 0 242 kB jsdoc-type-pratt-parser
npm/json-buffer@3.0.1 None 0 5.4 kB dominictarr
npm/keyv@4.5.4 None 0 27.8 kB jaredwray
npm/minimatch@9.0.5 environment 0 435 kB isaacs
npm/prettier-plugin-packagejson@2.5.2 None 0 5.55 kB matzkoh
npm/proc-log@3.0.0 None 0 5.21 kB lukekarrys
npm/resolve-pkg-maps@1.0.0 None 0 15 kB hirokiosame
npm/rimraf@5.0.10 environment, filesystem 0 281 kB isaacs
npm/semver@7.6.3 None 0 95.8 kB npm-cli-ops
npm/sort-package-json@2.10.1 None 0 33.3 kB keithamus
npm/stable-hash@0.0.4 None 0 5.46 kB quietshu
npm/strip-bom@4.0.0 None 0 3.91 kB sindresorhus
npm/synckit@0.9.1 environment 0 55.7 kB jounqin
npm/ts-api-utils@1.3.0 None 0 828 kB joshuakgoldberg
npm/tsd@0.31.2 None 0 94.9 kB sindresorhus
npm/tslib@2.7.0 None 0 86.2 kB typescript-bot
npm/undici-types@6.19.8 None 0 84.2 kB matteo.collina
npm/uuid@10.0.0 None 0 168 kB broofa
npm/webextension-polyfill@0.12.0 None 0 205 kB addons-robot

🚮 Removed packages: npm/@es-joy/jsdoccomment@0.36.1, npm/@eslint-community/regexpp@4.10.0, npm/@inquirer/confirm@2.0.17, npm/@inquirer/core@6.0.0, npm/@inquirer/type@1.3.2, npm/@lavamoat/aa@4.2.0, npm/@lavamoat/allow-scripts@3.0.4, npm/@lavamoat/preinstall-always-fail@2.0.0, npm/@metamask/eslint-config-jest@12.1.0, npm/@metamask/eslint-config-typescript@12.1.0, npm/@metamask/eslint-config@12.2.0, npm/@metamask/providers@17.1.2, npm/@npmcli/run-script@7.0.4, npm/@types/eslint@7.29.0, npm/@types/json-schema@7.0.12, npm/@types/json5@0.0.29, npm/@types/mute-stream@0.0.4, npm/@types/node@20.12.12, npm/@types/semver@7.5.0, npm/@types/uuid@9.0.8, npm/@types/wrap-ansi@3.0.0, npm/@typescript-eslint/eslint-plugin@5.62.0, npm/@typescript-eslint/parser@5.62.0, npm/@typescript-eslint/scope-manager@5.62.0, npm/@typescript-eslint/type-utils@5.62.0, npm/@typescript-eslint/types@5.62.0, npm/@typescript-eslint/typescript-estree@5.62.0, npm/@typescript-eslint/utils@5.62.0, npm/@typescript-eslint/visitor-keys@5.62.0, npm/acorn@8.11.3, npm/array-buffer-byte-length@1.0.0, npm/array-includes@3.1.7, npm/array.prototype.flat@1.3.2, npm/arraybuffer.prototype.slice@1.0.2, npm/available-typed-arrays@1.0.5, npm/bin-links@4.0.3, npm/builtins@5.0.1, npm/call-bind@1.0.2, npm/cli-spinners@2.9.2, npm/cli-width@4.1.0, npm/comment-parser@1.3.1, npm/define-data-property@1.1.0, npm/define-properties@1.2.0, npm/es-abstract@1.22.2, npm/es-set-tostringtag@2.0.1, npm/es-shim-unscopables@1.0.0, npm/es-to-primitive@1.2.1, npm/eslint-module-utils@2.8.0, npm/eslint-plugin-es@4.1.0, npm/eslint-plugin-import@2.26.0, npm/eslint-plugin-jsdoc@39.9.1, npm/eslint-plugin-n@15.7.0, npm/eslint-plugin-promise@6.1.1, npm/eslint-scope@5.1.1, npm/eslint-utils@2.1.0, npm/esquery@1.5.0, npm/fast-glob@3.2.12, npm/figures@3.2.0, npm/flat-cache@3.0.4, npm/flatted@3.2.7, npm/for-each@0.3.3, npm/function.prototype.name@1.1.6, npm/functions-have-names@1.2.3, npm/get-intrinsic@1.2.1, npm/get-symbol-description@1.0.0, npm/globalthis@1.0.3, npm/globby@11.1.0, npm/gopd@1.0.1, npm/has-bigints@1.0.2, npm/has-property-descriptors@1.0.0, npm/has-proto@1.0.1, npm/has-symbols@1.0.3, npm/has-tostringtag@1.0.0, npm/has@1.0.3, npm/ignore@5.3.1, npm/internal-slot@1.0.5, npm/is-array-buffer@3.0.2, npm/is-bigint@1.0.4, npm/is-boolean-object@1.1.2, npm/is-callable@1.2.7, npm/is-core-module@2.13.1, npm/is-date-object@1.0.5, npm/is-negative-zero@2.0.2, npm/is-number-object@1.0.7, npm/is-regex@1.1.4, npm/is-shared-array-buffer@1.0.2, npm/is-string@1.0.7, npm/is-symbol@1.0.4, npm/is-typed-array@1.1.12, npm/is-weakref@1.0.2, npm/isarray@2.0.5, npm/jest-it-up@3.1.0, npm/jsdoc-type-pratt-parser@3.1.0, npm/minimatch@9.0.4, npm/minimist@1.2.8, npm/mute-stream@1.0.0, npm/natural-compare-lite@1.4.0, npm/object-inspect@1.12.3, npm/object-keys@1.1.1, npm/object.assign@4.1.4, npm/object.values@1.1.7, npm/prettier-plugin-packagejson@2.5.0, npm/proc-log@4.2.0, npm/regexp.prototype.flags@1.5.1, npm/regexpp@3.2.0, npm/rimraf@5.0.7, npm/run-async@3.0.0, npm/safe-array-concat@1.0.1, npm/safe-regex-test@1.0.0, npm/semver@7.6.2, npm/set-function-name@2.0.1, npm/side-channel@1.0.4, npm/sort-package-json@2.10.0, npm/string.prototype.trim@1.2.8, npm/string.prototype.trimend@1.0.7, npm/string.prototype.trimstart@1.0.7, npm/strip-bom@3.0.0, npm/synckit@0.9.0, npm/tsconfig-paths@3.14.2, npm/tsd@0.31.0, npm/tslib@1.14.1, npm/tsutils@3.21.0, npm/typed-array-buffer@1.0.0, npm/typed-array-byte-length@1.0.0, npm/typed-array-byte-offset@1.0.0, npm/typed-array-length@1.0.4, npm/unbox-primitive@1.0.2, npm/undici-types@5.26.5, npm/uuid@9.0.1, npm/which-boxed-primitive@1.0.2, npm/which-typed-array@1.1.11

View full report↗︎

Copy link

socket-security bot commented Sep 11, 2024

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: npm/@lavamoat/aa@4.3.0, npm/@lavamoat/preinstall-always-fail@2.1.0

View full report↗︎

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of ecosystem/package-name@version specifiers. e.g. @SocketSecurity ignore npm/foo@1.0.0 or ignore all packages with @SocketSecurity ignore-all

@danroc
Copy link
Contributor Author

danroc commented Sep 11, 2024

@SocketSecurity ignore npm/@lavamoat/aa@4.3.0
@SocketSecurity ignore npm/@lavamoat/preinstall-always-fail@2.1.0

These are @lavamoat packages, thus trusted to have been internally reviewed.

@danroc danroc marked this pull request as ready for review September 11, 2024 12:14
@danroc danroc requested a review from a team as a code owner September 11, 2024 12:14
@danroc danroc added this pull request to the merge queue Sep 12, 2024
Merged via the queue into main with commit d2617b8 Sep 12, 2024
16 checks passed
@danroc danroc deleted the bump-dependencies branch September 12, 2024 08:08
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants