Skip to content

chore: release main#1643

Merged
boneskull merged 1 commit into
mainfrom
release-please--branches--main
Jun 24, 2025
Merged

chore: release main#1643
boneskull merged 1 commit into
mainfrom
release-please--branches--main

Conversation

@github-actions

@github-actions github-actions Bot commented May 5, 2025

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

aa: 4.3.3

4.3.3 (2025-06-24)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
allow-scripts: 3.3.4

3.3.4 (2025-06-24)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
  • deps: update dependency type-fest to v4.41.0 (#1657) (19e9bf1)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @lavamoat/aa bumped from ^4.3.2 to ^4.3.3
lavapack: 7.0.10

7.0.10 (2025-06-24)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • lavamoat-core bumped from ^16.4.0 to ^16.5.0
laverna: 1.2.5

1.2.5 (2025-06-24)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
  • deps: update dependency type-fest to v4.41.0 (#1657) (19e9bf1)
node: 0.3.0

0.3.0 (2025-06-24)

Features

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
  • deps: update dependency @endo/compartment-mapper to v1.6.1 (b175b93)
  • deps: update dependency @endo/evasive-transform to v2 (#1692) (07b1942)
  • deps: update dependency @types/node to v18.19.100 (#1646) (90c25d3)
  • deps: update dependency @types/node to v18.19.104 (#1669) (0b3461b)
  • deps: update dependency @types/node to v18.19.105 (#1675) (45b9cff)
  • deps: update dependency @types/node to v18.19.110 (#1678) (fd16808)
  • deps: update dependency @types/node to v18.19.111 (#1695) (2882276)
  • deps: update dependency type-fest to v4.41.0 (#1657) (19e9bf1)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • lavamoat-core bumped from ^16.4.0 to ^16.5.0
preinstall-always-fail: 2.1.1

2.1.1 (2025-06-24)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
react-native-lockdown: 0.0.1

0.0.1 (2025-06-24)

Features

  • react-native-lockdown: @lavamoat/react-native-lockdown beta (074c277)
  • react-native-lockdown: use vendored SES version (#1716) (34d8b67)

Bug Fixes

  • react-native-lockdown: add types (a01f6f5)
webpack: 1.0.0

1.0.0 (2025-06-24)

Features

  • webpack: add undocumented __unsafeAllowContextModules flag to allow experimenting with contextmodules without leaving them vulnerable by default (8eca7f1)
  • webpack: avoid emiting resource assets from packages by default (#1451) (325bf2a)
  • webpack: enable syntax checks by default, check prior to concatenation. (e74a55b)
  • webpack: policy debugging capabilities and tighter tests (20b12ad)
  • webpack: support scuttling (#1298) (9630600)
  • webpack: unlockedChunksUnsafe option to refrain from protecting selected chunks (#1375) (1f24683)
  • webpack: webpack context modules and chunk lazy loading support (#1553) (3602f65)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
  • core,webpack: remove deprecated lockdown options (efec539), closes #1578
  • core: block circular global object endowments (#1505) (6745a0e)
  • deps: update babel monorepo (afc9fe5)
  • deps: update babel monorepo (e6f4e70)
  • deps: update babel monorepo to v7.25.8 (1dcb35e)
  • deps: update babel monorepo to v7.25.9 (6d9d5a3)
  • deps: update babel monorepo to v7.26.7 (#1524) (7285fdf)
  • deps: update babel monorepo to v7.26.9 (6a9dc73)
  • deps: update babel monorepo to v7.27.0 (#1589) (efd83d7)
  • deps: update dependency json-stable-stringify to v1.3.0 (#1613) (f9314d1)
  • deps: update dependency ses to v1.10.0 (#1422) (b6f0589)
  • deps: update dependency ses to v1.12.0 [security] (#1605) (881ae86)
  • deps: update dependency ses to v1.9.0 (75cae74)
  • make policy ordering consistntly manifest itself in json files produced (a149a7d)
  • upgrade ses to v1.11.0 (a12dae1)
  • webpack: import types from ses (78aca55)
  • webpack: prevent toString manipulation on a specifier (1163085)
  • webpack: support regex in scuttling exceptions (#1529) (45c0308)
  • webpack: undo the forced overwrite of parent and top references (#1666) (adec627)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @lavamoat/aa bumped from ^4.3.2 to ^4.3.3
      • lavamoat-core bumped from ^16.4.0 to ^16.5.0
lavamoat: 9.0.10

9.0.10 (2025-06-24)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
  • deps: update babel monorepo (afc9fe5)
  • deps: update dependency corepack to v0.33.0 (#1682) (0de2351)
  • lavamoat-node: support packages with falsy main field (e8c489c), closes #1706

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @lavamoat/aa bumped from ^4.3.2 to ^4.3.3
      • lavamoat-core bumped from ^16.4.0 to ^16.5.0
      • lavamoat-tofu bumped from ^8.0.7 to ^8.0.8
lavamoat-browserify: 18.1.7

18.1.7 (2025-06-24)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
  • deps: update babel monorepo (afc9fe5)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @lavamoat/aa bumped from ^4.3.2 to ^4.3.3
      • @lavamoat/lavapack bumped from ^7.0.9 to ^7.0.10
      • lavamoat-core bumped from ^16.4.0 to ^16.5.0
    • devDependencies
      • lavamoat bumped from 9.0.9 to 9.0.10
lavamoat-core: 16.5.0

16.5.0 (2025-06-24)

Features

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
  • deps: update babel monorepo (afc9fe5)
  • deps: update babel monorepo to v7.27.3 (#1672) (72cb642)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • lavamoat-tofu bumped from ^8.0.7 to ^8.0.8
lavamoat-tofu: 8.0.8

8.0.8 (2025-06-24)

Bug Fixes

  • add Node.js v24.0.0 to supported engines (ad9cdcd)
  • deps: update babel monorepo (afc9fe5)
  • deps: update babel monorepo to v7.27.3 (#1672) (72cb642)
  • deps: update dependency type-fest to v4.41.0 (#1657) (19e9bf1)

Dependencies

  • The following workspace dependencies were updated
    • peerDependencies
      • lavamoat-core bumped from >15.4.0 to >16.5.0

This PR was generated with Release Please. See documentation.

@github-actions github-actions Bot added the autorelease: pending for release bot; do not use label May 5, 2025
@github-actions github-actions Bot force-pushed the release-please--branches--main branch 3 times, most recently from 730ea40 to 94c3d92 Compare May 9, 2025 19:04
@socket-security

socket-security Bot commented May 9, 2025

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedlavamoat-browserify@​18.1.6 ⏵ 18.1.7100 +18100100100 +9100
Updatedlavamoat-core@​16.4.0 ⏵ 16.5.0100 +2100100 +26100 +11100
Updatedlavamoat@​9.0.9 ⏵ 9.0.10100 +18100100100 +9100
Updated@​lavamoat/​lavapack@​7.0.9 ⏵ 7.0.10100 +10100100 +27100 +11100
Updated@​lavamoat/​node@​0.2.0 ⏵ 0.3.0100 +24100100 +1100 +12100
Updated@​lavamoat/​aa@​4.3.2 ⏵ 4.3.3100 +1100100 +26100 +17100
Updatedlavamoat-tofu@​8.0.7 ⏵ 8.0.8100 +2100100 +24100 +12100

View full report

@github-actions github-actions Bot force-pushed the release-please--branches--main branch 7 times, most recently from 7005950 to bff9e0d Compare May 14, 2025 22:31
@github-actions github-actions Bot force-pushed the release-please--branches--main branch 6 times, most recently from 6e196c2 to 716abd0 Compare May 27, 2025 21:06
@github-actions github-actions Bot force-pushed the release-please--branches--main branch 3 times, most recently from 1771232 to 7192a70 Compare June 2, 2025 08:14
@github-actions github-actions Bot force-pushed the release-please--branches--main branch 5 times, most recently from 81cdcf9 to 6a64173 Compare June 5, 2025 19:38
@github-actions github-actions Bot force-pushed the release-please--branches--main branch 5 times, most recently from 1a44095 to a402860 Compare June 13, 2025 20:20
@github-actions github-actions Bot force-pushed the release-please--branches--main branch 3 times, most recently from f78a149 to 6a8d76b Compare June 23, 2025 10:50
@github-actions github-actions Bot force-pushed the release-please--branches--main branch from 6a8d76b to d7f735a Compare June 24, 2025 12:26

@leotm leotm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pending webpack version bump to 1.0.0

Comment thread packages/webpack/package.json Outdated
@leotm leotm mentioned this pull request Jun 24, 2025
2 tasks

@leotm leotm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

react-native-lockdown missing, add to release-please config

update release-please config versions

@github-actions github-actions Bot force-pushed the release-please--branches--main branch from d7f735a to cd61037 Compare June 24, 2025 14:19
@leotm leotm self-requested a review June 24, 2025 14:20
@github-actions github-actions Bot force-pushed the release-please--branches--main branch from cd61037 to fb26c8b Compare June 24, 2025 16:57
Comment on lines +40 to +50
* **deps:** update babel monorepo ([afc9fe5](https://github.com/LavaMoat/LavaMoat/commit/afc9fe5fef98c53abe014ff657a1d4f59883abe8))
* **deps:** update babel monorepo ([e6f4e70](https://github.com/LavaMoat/LavaMoat/commit/e6f4e70cffe8237c27126046bb0cfa5515c2d138))
* **deps:** update babel monorepo to v7.25.8 ([1dcb35e](https://github.com/LavaMoat/LavaMoat/commit/1dcb35e023823710343b5f0a4ca589cdfe647e7d))
* **deps:** update babel monorepo to v7.25.9 ([6d9d5a3](https://github.com/LavaMoat/LavaMoat/commit/6d9d5a3336444fada49e239756ffc3c207d3ff5d))
* **deps:** update babel monorepo to v7.26.7 ([#1524](https://github.com/LavaMoat/LavaMoat/issues/1524)) ([7285fdf](https://github.com/LavaMoat/LavaMoat/commit/7285fdf6ce5c337443840525b79c7653708b541f))
* **deps:** update babel monorepo to v7.26.9 ([6a9dc73](https://github.com/LavaMoat/LavaMoat/commit/6a9dc735f18a5b95e82b86ec2bd466ee4433172f))
* **deps:** update babel monorepo to v7.27.0 ([#1589](https://github.com/LavaMoat/LavaMoat/issues/1589)) ([efd83d7](https://github.com/LavaMoat/LavaMoat/commit/efd83d7ea7a5f5f9d2157248d4e2f8b7f9c48c56))
* **deps:** update dependency json-stable-stringify to v1.3.0 ([#1613](https://github.com/LavaMoat/LavaMoat/issues/1613)) ([f9314d1](https://github.com/LavaMoat/LavaMoat/commit/f9314d1a238d31a0164356c1c6bd6f6e36246d56))
* **deps:** update dependency ses to v1.10.0 ([#1422](https://github.com/LavaMoat/LavaMoat/issues/1422)) ([b6f0589](https://github.com/LavaMoat/LavaMoat/commit/b6f0589cf9730fac8173a3fca0c4a031bd64f12f))
* **deps:** update dependency ses to v1.12.0 [security] ([#1605](https://github.com/LavaMoat/LavaMoat/issues/1605)) ([881ae86](https://github.com/LavaMoat/LavaMoat/commit/881ae86b9a4c27ab60a3c76a4a69f5de246eb2ed))
* **deps:** update dependency ses to v1.9.0 ([75cae74](https://github.com/LavaMoat/LavaMoat/commit/75cae74063c444184fea3370bf9925bc7946846a))

@leotm leotm Jun 24, 2025

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

perhaps we can update release-please config after to filter these under ### Dependencies

and workspace deps under ### Workspace Dependencies

(instead of all nested under ### Bug Fixes)

@leotm leotm self-requested a review June 24, 2025 17:10

### Features

* **react-native-lockdown:** @lavamoat/react-native-lockdown beta ([074c277](https://github.com/LavaMoat/LavaMoat/commit/074c2775093e94f6a81da0890aaa66db2700ac5a))

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
* **react-native-lockdown:** @lavamoat/react-native-lockdown beta ([074c277](https://github.com/LavaMoat/LavaMoat/commit/074c2775093e94f6a81da0890aaa66db2700ac5a))
* **react-native-lockdown:** @lavamoat/react-native-lockdown ([074c277](https://github.com/LavaMoat/LavaMoat/commit/074c2775093e94f6a81da0890aaa66db2700ac5a))

perhaps worth reflecting new package.json version 0.0.1
(to avoid pre-release vers e.g. 0.0.1-beta.0 since unaffected by semver ranges)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nb: release-please config also supports --prerelease

@leotm leotm self-requested a review June 24, 2025 17:30

@leotm leotm left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@leotm

leotm commented Jun 24, 2025

Copy link
Copy Markdown
Member

@boneskull boneskull merged commit a10a1b9 into main Jun 24, 2025
2 checks passed
@boneskull boneskull deleted the release-please--branches--main branch June 24, 2025 20:01
@github-actions

Copy link
Copy Markdown
Contributor Author

@github-actions github-actions Bot added autorelease: tagged for release bot; do not use and removed autorelease: pending for release bot; do not use labels Jun 24, 2025
github-merge-queue Bot pushed a commit to MetaMask/metamask-mobile that referenced this pull request Jul 9, 2025
## **Description**

Introduce Hardened JavaScript now on both iOS (RN JSC) and Android
(Hermes)
via Metro (@lavamoat/react-native-lockdown beta) instead of RN patch
and remove [old iOS
UI](https://github.com/user-attachments/assets/b53be562-bc36-4ff2-a177-ef5c24c44de4)
from: Settings > Experimental > Security

TODO
- [x] Remove stale root SES shim (now via
@lavamoat/react-native-lockdown)
- [x] Remove stale RN iOS patch (now via
@lavamoat/react-native-lockdown)
- [x] Add temp @lavamoat/react-native-lockdown tgz
- [x] Add temp SES patch endojs/endo#2855
- [x] Replace both with official @lavamoat/react-native-lockdown
  - [x] once LavaMoat/LavaMoat#1716 merged
  - [x] released LavaMoat/LavaMoat#1643
- [x] Remove experimental feature toggle UI
  - Ref: #8373
    - preserve react-native-mmkv (we still use it)
    - update UI component snapshot
    - remove stale EN txt (and others?)
- [x] <s>Fix smoke/regression e2e test timeouts</s> passing
- [x] check failing regression e2e tests
  - same ones also failing on `main`
- [x] cursor[bot] feedback

## **Related issues**

Fixes:

## **Manual testing steps**

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I’ve followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile
Coding
Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

---------

Co-authored-by: sethkfman <10342624+sethkfman@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

autorelease: tagged for release bot; do not use

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Lavamoat fails when parsing package manifest with 'main' field set to 'false' remove uses of mathTaming and dateTaming from codebase

2 participants