chore: bump Ledger Bridge to 11.2.0 and Keyring API to 21.4.0#25660
chore: bump Ledger Bridge to 11.2.0 and Keyring API to 21.4.0#25660
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
All alerts resolved. Learn more about Socket for GitHub. This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored. Ignoring alerts on:
|
….com/MetaMask/metamask-mobile into gar/chore/bump-ledger-keyring/11.2.0
|
@SocketSecurity ignore npm/@metamask/eth-ledger-bridge-keyring@11.2.0 |
@metamask/eth-ledger-bridge-keyring to 11.2.0
🔍 Smart E2E Test Selection
click to see 🤖 AI reasoning detailsE2E Test Selection:
Selected tags rationale:
While these are minor version bumps (typically backward-compatible), the wide usage of keyring-api across the codebase and the addition of new dependencies in the update warrant testing core wallet functionality. Performance Test Selection: |
|



Description
Changelog
CHANGELOG entry: null
Related issues
Fixes: https://consensyssoftware.atlassian.net/browse/MUL-1440
Manual testing steps
Screenshots/Recordings
Not applicable
Pre-merge author checklist
Pre-merge reviewer checklist
Note
Medium Risk
Dependency-only change, but it touches hardware wallet/keyring packages where regressions could affect Ledger interactions or signing flows.
Overview
Bumps keyring-related dependencies to pick up upstream changes:
@metamask/eth-ledger-bridge-keyring11.1.0→11.2.0and@metamask/keyring-api21.3.0→21.4.0.Updates
yarn.lockaccordingly, including refreshed transitive dependency versions (notably@metamask/keyring-utils3.1.0→3.2.0and newkeyring-apidependencies likeuuid/async-mutex).Written by Cursor Bugbot for commit fafda4a. This will update automatically on new commits. Configure here.