Skip to content

chore: bump snaps-* deps#461

Merged
ccharly merged 3 commits intomainfrom
cc/chore/bump-snaps-utils
Feb 5, 2026
Merged

chore: bump snaps-* deps#461
ccharly merged 3 commits intomainfrom
cc/chore/bump-snaps-utils

Conversation

@ccharly
Copy link
Contributor

@ccharly ccharly commented Feb 5, 2026

Bumping snaps-* packages.


Note

Medium Risk
Primarily dependency upgrades, but it bumps @metamask/snaps-controllers to a new major version, which can introduce breaking changes in Snap/controller behavior despite no source code changes in this PR.

Overview
Updates Snap-related dependencies across the keyring packages.

@metamask/snaps-controllers is bumped to ^18.0.0 and @metamask/snaps-sdk/@metamask/snaps-utils to ^10.4.0/^12.1.0 in keyring-internal-snap-client and keyring-snap-bridge, and keyring-snap-sdk updates its @metamask/snaps-sdk dependency accordingly. The yarn.lock is refreshed to pull in the new transitive graph (e.g., @metamask/json-rpc-engine 10.2.1, fast-xml-parser 5.x, and newly added @metamask/storage-service via snaps-controllers), and changelogs are updated to reflect the bumps.

Written by Cursor Bugbot for commit 962b22c. This will update automatically on new commits. Configure here.

@ccharly ccharly requested a review from a team as a code owner February 5, 2026 15:15
@socket-security
Copy link

socket-security bot commented Feb 5, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​metamask/​snaps-utils@​11.7.1 ⏵ 12.1.098 +110076 +197 +2100
Updated@​metamask/​snaps-controllers@​17.2.0 ⏵ 18.0.098 -210076 -2496 -450 -50
Updated@​metamask/​snaps-sdk@​10.3.0 ⏵ 10.4.09910078 +194 +2100

View full report

@socket-security
Copy link

socket-security bot commented Feb 5, 2026

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring alerts on:

  • @metamask/snaps-controllers@18.0.0
  • @metamask/snaps-rpc-methods@14.3.0

View full report

@ccharly
Copy link
Contributor Author

ccharly commented Feb 5, 2026

@SocketSecurity ignore npm/@metamask/snaps-controllers
@SocketSecurity ignore npm/@metamask/snaps-rpc-methods

Those are internal packages.

@ccharly
Copy link
Contributor Author

ccharly commented Feb 5, 2026

@SocketSecurity ignore @metamask/snaps-controllers
@SocketSecurity ignore @metamask/snaps-rpc-methods

Those are internal packages.

@ccharly
Copy link
Contributor Author

ccharly commented Feb 5, 2026

@SocketSecurity ignore npm/@metamask/snaps-controllers@18.0.0
@SocketSecurity ignore npm/@metamask/snaps-rpc-methods@14.3.0

Those are internal packages.

This time I should get it right 🙃

@ccharly ccharly enabled auto-merge February 5, 2026 15:36
@ccharly ccharly added this pull request to the merge queue Feb 5, 2026
Merged via the queue into main with commit 6a32fb6 Feb 5, 2026
37 checks passed
@ccharly ccharly deleted the cc/chore/bump-snaps-utils branch February 5, 2026 15:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants