Skip to content

chore: Test InternalProvider preview builds#36643

Closed
rekmarks wants to merge 2 commits intomainfrom
rekm/test-internal-provider-preview
Closed

chore: Test InternalProvider preview builds#36643
rekmarks wants to merge 2 commits intomainfrom
rekm/test-internal-provider-preview

Conversation

@rekmarks
Copy link
Copy Markdown
Member

@rekmarks rekmarks commented Oct 7, 2025

Description

Open in GitHub Codespaces

Changelog

CHANGELOG entry:

Related issues

Fixes:

Manual testing steps

  1. Go to this page...

Screenshots/Recordings

Before

After

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

@rekmarks rekmarks added the DO-NOT-MERGE Pull requests that should not be merged label Oct 7, 2025
@metamaskbot metamaskbot added the team-ocap-kernel The Ocap Kernel team label Oct 7, 2025
@socket-security
Copy link
Copy Markdown

socket-security bot commented Oct 7, 2025

Caution

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Block High
@metamask/eth-json-rpc-infura@10.3.0 has Unstable ownership.

Author: metamaskbot

From: ?npm/@metamask/selected-network-controller@24.0.0npm/@metamask/eth-json-rpc-infura@10.3.0

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@metamask/eth-json-rpc-infura@10.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
@metamask/eth-json-rpc-infura@10.3.0 has a New author.

New Author: metamaskbot

Previous Author: gudahtt

From: ?npm/@metamask/selected-network-controller@24.0.0npm/@metamask/eth-json-rpc-infura@10.3.0

ℹ Read more on: This package | This alert | What is new author?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Scrutinize new collaborator additions to packages because they now have the ability to publish code into your dependency tree. Packages should avoid frequent or unnecessary additions or changes to publishing rights.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@metamask/eth-json-rpc-infura@10.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@rekmarks rekmarks force-pushed the rekm/test-internal-provider-preview branch from dfcfee9 to 492c157 Compare October 7, 2025 22:28
@rekmarks
Copy link
Copy Markdown
Member Author

rekmarks commented Oct 7, 2025

@metamaskbot update-policies

@metamaskbot
Copy link
Copy Markdown
Collaborator

Policies updated.
👀 Please review the diff for suspicious new powers.

🧠 Learn how: https://lavamoat.github.io/guides/policy-diff/#what-to-look-for-when-reviewing-a-policy-diff

@metamaskbot
Copy link
Copy Markdown
Collaborator

✨ Files requiring CODEOWNER review ✨

🧩 @MetaMask/extension-devs (5 files, +40 -75)
  • 📁 lavamoat/
    • 📁 browserify/
      • 📁 beta/
        • 📄 policy.json +8 -15
      • 📁 experimental/
        • 📄 policy.json +8 -15
      • 📁 flask/
        • 📄 policy.json +8 -15
      • 📁 main/
        • 📄 policy.json +8 -15
    • 📁 webpack/
      • 📄 policy.json +8 -15

📜 @MetaMask/policy-reviewers (5 files, +40 -75)
  • 📁 lavamoat/
    • 📁 browserify/
      • 📁 beta/
        • 📄 policy.json +8 -15
      • 📁 experimental/
        • 📄 policy.json +8 -15
      • 📁 flask/
        • 📄 policy.json +8 -15
      • 📁 main/
        • 📄 policy.json +8 -15
    • 📁 webpack/
      • 📄 policy.json +8 -15

Tip

Follow the policy review process outlined in the LavaMoat Policy Review Process doc before expecting an approval from Policy Reviewers.


🔗 @MetaMask/supply-chain (5 files, +40 -75)
  • 📁 lavamoat/
    • 📁 browserify/
      • 📁 beta/
        • 📄 policy.json +8 -15
      • 📁 experimental/
        • 📄 policy.json +8 -15
      • 📁 flask/
        • 📄 policy.json +8 -15
      • 📁 main/
        • 📄 policy.json +8 -15
    • 📁 webpack/
      • 📄 policy.json +8 -15

@metamaskbot
Copy link
Copy Markdown
Collaborator

❌ test-e2e-chrome-api-specs failed. View the html report here.

@metamaskbot
Copy link
Copy Markdown
Collaborator

📊 Page Load Benchmark Results

Current Commit: 2d166a5 | Date: 10/7/2025

📄 Localhost MetaMask Test Dapp

Samples: 100

Summary

  • pageLoadTime-> current mean value: 1.06s (±75ms) 🟡 | historical mean value: 1.05s ⬆️ (historical data)
  • domContentLoaded-> current mean value: 744ms (±72ms) 🟢 | historical mean value: 738ms ⬆️ (historical data)
  • firstContentfulPaint-> current mean value: 80ms (±10ms) 🟢 | historical mean value: 79ms ⬆️ (historical data)
📈 Detailed Results
Metric Mean Std Dev Min Max P95 P99
pageLoadTime 1.06s 75ms 1.03s 1.37s 1.32s 1.37s
domContentLoaded 744ms 72ms 708ms 1.02s 999ms 1.02s
firstPaint 80ms 10ms 60ms 160ms 88ms 160ms
firstContentfulPaint 80ms 10ms 60ms 160ms 88ms 160ms
largestContentfulPaint 0ms 0ms 0ms 0ms 0ms 0ms

Results generated automatically by MetaMask CI

@metamaskbot
Copy link
Copy Markdown
Collaborator

Builds ready [2d166a5]
UI Startup Metrics (1240 ± 69 ms)
PlatformBuildTypePageMetricMean (ms)Min (ms)Max (ms)Std Dev (ms)P 75 (ms)P 95 (ms)
ChromeBrowserifyHomeuiStartup1240110614446912881350
load107095412346211071188
domContentLoaded106495012266311021183
domInteractive1913139141639
firstPaint71879119943610911144
backgroundConnect2532402908255268
firstReactRender2616208212538
getState1157991125
initialActions51396519
loadScripts81871098163861937
setupStore86314913
WebpackHomeuiStartup19041589239517420352204
load15651343186611316391778
domContentLoaded15511333185811416281768
domInteractive1812107171461
firstPaint2815617564311921568
backgroundConnect3513142193867
firstReactRender56192714164142
getState135173171423
initialActions5013314327
loadScripts15471331185611416241766
setupStore144153161530
FirefoxBrowserifyHomeuiStartup13651189166810514321569
load1178103913928312351326
domContentLoaded1178103913918312351326
domInteractive993125448107228
firstPaintNaNNaNNaNNaNNaNNaN
backgroundConnect27186283244
firstReactRender28244132837
getState739811517
initialActions20253210
loadScripts1157102313758212111300
setupStore947813647
WebpackHomeuiStartup15241343195512415571814
load1326119516569113691528
domContentLoaded1326119416569113691528
domInteractive97303715897296
firstPaintNaNNaNNaNNaNNaNNaN
backgroundConnect301896123450
firstReactRender342482133675
getState63939613
initialActions5015020213
loadScripts1303117916328813471505
setupStore1046914651
Bundle size diffs [🚀 Bundle size reduced!]
  • background: -27.05 KiB (-0.6%)
  • ui: -1 Bytes (0%)
  • common: -2.01 KiB (-0.02%)

@rekmarks rekmarks closed this Oct 28, 2025
@rekmarks rekmarks deleted the rekm/test-internal-provider-preview branch October 28, 2025 17:48
@github-actions github-actions bot locked and limited conversation to collaborators Oct 28, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

DO-NOT-MERGE Pull requests that should not be merged size-XS team-ocap-kernel The Ocap Kernel team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants