Skip to content

Cherry-pick deps audit fixes to v12.1.0#26475

Merged
danjm merged 2 commits intoVersion-v12.1.0from
cherry-pick-cad49eb-v12.1.0
Aug 16, 2024
Merged

Cherry-pick deps audit fixes to v12.1.0#26475
danjm merged 2 commits intoVersion-v12.1.0from
cherry-pick-cad49eb-v12.1.0

Conversation

@danjm
Copy link
Copy Markdown
Contributor

@danjm danjm commented Aug 16, 2024

Cherry-pick cad49eb (#26381) to v12.1.0
Cherry-pick f53dc06 (#26202) to v12.1.0

…6381)

<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

We only use this package for its types, so can be treated as a dev
dependency. This will also resolve the audit issue currently seen in
[CI](https://app.circleci.com/pipelines/github/MetaMask/metamask-extension/95274/workflows/b92333ec-1a1c-4ce6-bd7d-7601fe14e1e3/jobs/3546366).

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

[![Open in GitHub
Codespaces](https://github.com/codespaces/badge.svg)](https://codespaces.new/MetaMask/metamask-extension/pull/26381?quickstart=1)

## **Related issues**

Fixes: CI issues, and better reflects the use case of this dependency.

## **Manual testing steps**

Re-test notifications flow

1. Onboard with new or existing wallet
2. Enable notifications
3. Perform a swap on Polygon (a chain we support on-chain notifications
for)
4. See if notifications appear.

For Notification Devs: As there is no feature announcements yet,
manually change the code to point to a portfolio feature announcement.
I've tested and it seems that we still correctly show a feature
announcement to users.

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/develop/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/develop/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
@danjm danjm requested a review from a team as a code owner August 16, 2024 14:50
@github-actions
Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@socket-security
Copy link
Copy Markdown

socket-security bot commented Aug 16, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/fast-xml-parser@4.4.1 None 0 172 kB amitgupta
npm/qs@6.11.0 None 0 229 kB ljharb

🚮 Removed packages: npm/fast-xml-parser@4.3.4, npm/qs@6.11.2

View full report↗︎

@metamaskbot metamaskbot added INVALID-PR-TEMPLATE PR's body doesn't match template team-extension-platform Extension Platform team labels Aug 16, 2024
## **Description**

Fix audit:

```
└─ fast-xml-parser
   ├─ ID: 1098305
   ├─ Issue: fast-xml-parser vulnerable to ReDOS at currency parsing
   ├─ URL: GHSA-mpg4-rc92-vx8v
   ├─ Severity: high
   ├─ Vulnerable Versions: <4.4.1
   │ 
   ├─ Tree Versions
   │  └─ 4.3.4
```

[![Open in GitHub
Codespaces](https://github.com/codespaces/badge.svg)](https://codespaces.new/MetaMask/metamask-extension/pull/26202?quickstart=1)

## **Related issues**



## **Manual testing steps**


## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/develop/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/develop/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
@danjm danjm changed the title Cherry-pick cad49eb (#26381) to v12.1.0 Cherry-pick deps audit fixes to v12.1.0 Aug 16, 2024
@danjm danjm merged commit db5efc0 into Version-v12.1.0 Aug 16, 2024
@danjm danjm deleted the cherry-pick-cad49eb-v12.1.0 branch August 16, 2024 16:06
@github-actions github-actions bot locked and limited conversation to collaborators Aug 16, 2024
@metamaskbot metamaskbot added the release-12.2.0 Issue or pull request that will be included in release 12.2.0 label Aug 28, 2024
@metamaskbot
Copy link
Copy Markdown
Collaborator

No release label on PR. Adding release label release-12.2.0 on PR, as PR was cherry-picked in branch 12.2.0.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

INVALID-PR-TEMPLATE PR's body doesn't match template release-12.2.0 Issue or pull request that will be included in release 12.2.0 team-extension-platform Extension Platform team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants