fix: bump assets and phishing controller#40132
Conversation
|
CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Builds ready [9197c38]
UI Startup Metrics (1437 ± 103 ms)
Bundle size diffs [🚨 Warning! Bundle size has increased!]
|
81258ae
|
Approved on behalf of policy reviewers |
|
@metamaskbot update-policies |
|
Policies updated. 🧠 Learn how: https://lavamoat.github.io/guides/policy-diff/#what-to-look-for-when-reviewing-a-policy-diff 👀 lavamoat/browserify/beta/policy.json changes differ from main/policy.json policy changes |
|
Builds ready [34d1ba5]
⚡ Performance Benchmarks (1334 ± 120 ms)
🌐 Dapp Page Load BenchmarksCurrent Commit: 📄 Localhost MetaMask Test DappSamples: 100 Summary
📈 Detailed Results
Bundle size diffs [🚀 Bundle size reduced!]
|



Description
Changelog
CHANGELOG entry: bump assets and phishing controllers versions
Related issues
Fixes:
Manual testing steps
Screenshots/Recordings
Before
After
Pre-merge author checklist
Pre-merge reviewer checklist
Note
Medium Risk
Moderate risk due to major-version controller dependency bump and updated LavaMoat policies/state fixtures, which could affect runtime permissions and phishing/asset flows.
Overview
Updates dependencies to
@metamask/assets-controllers@100.0.2and@metamask/phishing-controller@16.3.0, includingyarn.lockrefresh.Extends
MultichainAssetsController’s restricted messenger to permit the newPhishingController:bulkScanTokensaction so the assets controller can request bulk token phishing scans, and updates LavaMoat policies and e2e fixtures/state snapshots for new phishing controller cache state (e.g.addressScanCache).Written by Cursor Bugbot for commit 34d1ba5. This will update automatically on new commits. Configure here.