-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): bump @metamask/eth-ledger-bridge-keyring
to ^5.0.1
#27688
Conversation
^5.0.0
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
🚮 Removed packages: npm/@metamask/eth-ledger-bridge-keyring@3.0.1, npm/follow-redirects@1.15.6 |
👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎ This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. |
This comment was marked as outdated.
This comment was marked as outdated.
This comment was marked as outdated.
This comment was marked as outdated.
@metamaskbot update-policies |
^5.0.0
^5.0.1
Policy update failed. You can review the logs or retry the policy update here |
Quality Gate passedIssues Measures |
Builds ready [4275009]
Page Load Metrics (1994 ± 104 ms)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
4275009
to
292b707
Compare
Builds ready [292b707]
Page Load Metrics (1926 ± 69 ms)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
Builds ready [77d1ffa]
Page Load Metrics (1828 ± 104 ms)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
^5.0.1
@metamask/eth-ledger-bridge-keyring
to ^5.0.1
@metamask/eth-ledger-bridge-keyring
to ^5.0.1
@metamask/eth-ledger-bridge-keyring
to ^5.0.1
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This patch is needed because Lavamoat is unable to walk the dependency tree with subpath imports when the package ships esm and cjs versions
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This patch is needed because Lavamoat is unable to walk the dependency tree with subpath imports when the package ships esm and cjs versions
"@ledgerhq/cryptoassets-evm-signatures/axios": "^0.28.0", | ||
"@ledgerhq/domain-service/axios": "^0.28.0", | ||
"@ledgerhq/evm-tools/axios": "^0.28.0", | ||
"@ledgerhq/hw-app-eth/axios": "^0.28.0", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Socket security advisory
Builds ready [9de63e3]
Page Load Metrics (1813 ± 59 ms)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good!
Builds ready [fd893e5]
Page Load Metrics (2064 ± 147 ms)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
LGTM ! |
Builds ready [ac579f8]
Page Load Metrics (2259 ± 120 ms)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
Description
This PR bumps the
@metamask/eth-ledger-bridge-keyring
dependency to^5.0.1
.Related issues
Unblocks: #26840
Manual testing steps
This changes directly impacts Ledger devices:
Screenshots/Recordings
Before
After
Add account and sign
Ledger_sign.mp4
Forget device
Ledger_forget.mp4
Pre-merge author checklist
Pre-merge reviewer checklist