chore: bump @metamask/utils from ^11.11.0 to ^11.12.0 - #10076
Merged
Merged
Conversation
cryptodev-2s
temporarily deployed
to
default-branch
September 2, 2026 13:21 — with
GitHub Actions
Inactive
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Contributor
Author
|
@metamaskbot update-changelogs |
@metamask/utils from ^11.11.0 to ^11.12.0@metamask/utils from ^11.11.0 to ^11.12.0
cryptodev-2s
enabled auto-merge
September 2, 2026 13:31
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Sep 2, 2026
mcmire
approved these changes
Sep 2, 2026
rajanpanth
pushed a commit
to rajanpanth/core
that referenced
this pull request
Sep 3, 2026
## Explanation **Summary** Publish `@metamask/phishing-controller` 17.4.1 and `@metamask/transaction-controller` 69.8.0 so clients can pick up the address-poisoning known-set fix from MetaMask#9943. **Problem** Phishing known recipients were hydrated via `getEffectiveRecipient`, which falls back to `txParams.to` for non-transfers. Confirmed approves and contract interactions therefore seeded token and protocol addresses into the comparison set, and vanity factories could 4+4-match each other (false positives on Permit2 approves). **Solution** - `@metamask/transaction-controller@69.8.0` (minor): export `getSendRecipients` for user-chosen send payees only - `@metamask/phishing-controller@17.4.1` (patch): hydrate known recipients from `getSendRecipients` instead of `getEffectiveRecipient`, plus the pending C2 blocklist Set optimization and transaction-controller range bump to `^69.8.0` Workspace dependents bump their `@metamask/phishing-controller` / `@metamask/transaction-controller` ranges but are not published in this release. **Risk** No breaking API changes. Known-set membership narrows to real send payees (correct for poisoning). Clients still on older phishing-controller keep the old set until they bump. **Intentionally skipped** `@metamask/address-book-controller`, `@metamask/base-controller`, `@metamask/controller-utils`, `@metamask/messenger`, `@metamask/accounts-controller`, `@metamask/approval-controller`, `@metamask/core-backend`, `@metamask/gas-fee-controller`, `@metamask/network-controller`, `@metamask/remote-feature-flag-controller`, and `@metamask/eth-block-tracker` have unrelated unreleased changes and are not required for MetaMask#9943. ### `@metamask/phishing-controller@17.4.1` #### Changed - Optimize C2 domain blocklist lookups by switching internal storage from `Array` to `Set` ([MetaMask#6388](MetaMask#6388)) - Bump `@metamask/transaction-controller` from `^69.5.2` to `^69.8.0` #### Fixed - Restrict address poisoning known recipients to user-chosen send payees ([MetaMask#9943](MetaMask#9943)) ### `@metamask/transaction-controller@69.8.0` #### Added - Export `getSendRecipients` ([MetaMask#9943](MetaMask#9943)) #### Changed - Bump `@metamask/utils` from `^11.11.0` to `^11.12.0` ([MetaMask#10076](MetaMask#10076)) ## References - Related to MetaMask#9943 - Ticket: https://consensyssoftware.atlassian.net/browse/PSAFE-633 - Extension follow-up: MetaMask/metamask-extension#45724 ## Checklist - [x] I've updated the test suite for new or updated code as appropriate - [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [x] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Release packaging and dependency alignment; behavioral fixes ship via already-reviewed controller versions with no additional logic in this PR. > > **Overview** > Cuts **monorepo release 1229.0.0** and publishes **`@metamask/phishing-controller@17.4.1`** and **`@metamask/transaction-controller@69.8.0`**, with version/changelog/`yarn.lock` updates only (no new application source in this diff). > > **`@metamask/transaction-controller@69.8.0`** documents export of **`getSendRecipients`** so callers can resolve user-chosen send payees (simple sends, decoded transfers, swap-and-send, batch sends) without treating `txParams.to` as the payee. > > **`@metamask/phishing-controller@17.4.1`** documents switching address-poisoning “known recipient” hydration to **`getSendRecipients`** instead of **`getEffectiveRecipient`**, plus C2 blocklist storage moved from `Array` to `Set` for O(1) lookups. > > Workspace packages that depend on phishing or transaction-controller bump to **`^17.4.1`** / **`^69.8.0`** (e.g. **`assets-controller`**, bridge, wallet); those packages are not newly published here—only the two security-related controllers and the root monorepo version. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 265147e. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
adonesky1
pushed a commit
to wzrdk3lly/core
that referenced
this pull request
Sep 3, 2026
## Explanation **Summary** Publish `@metamask/analytics-controller@2.1.0` so clients can opt into journey-scoped event fragments from [MetaMask#10055](MetaMask#10055). **Problem** Clients that track multi-step user journeys (signature requests, transaction confirmations, and similar flows) must re-derive the same analytics properties at every step, or build ad hoc state to carry them forward. There is no shared controller primitive for accumulating properties across a journey and optionally closing it with a success or failure event. **Solution** - `@metamask/analytics-controller@2.1.0` (minor): add optional event fragments, disabled by default via `isEventFragmentsEnabled` - Funnel shape: declare `initialEvent`, `successEvent`, and/or `failureEvent`, then call `finalizeEventFragment` - Property-bag shape: declare no event names and read accumulated properties back with `getEventFragmentById` when emitting a custom event - Fragment methods respect the same consent gate as `trackEvent`, return read-only copies from `createEventFragment` / `getEventFragmentById`, and discard stale non-persistent or expired persisted fragments on `init` Workspace dependents bump their `@metamask/analytics-controller` range to `^2.1.0` but are not published in this release: - `@metamask/network-controller` - `@metamask/wallet-cli` **Risk** No breaking API changes. Event fragments are disabled by default, so existing consumers keep current behavior until they opt in with `isEventFragmentsEnabled`. ### `@metamask/analytics-controller@2.1.0` #### Added - Add optional event fragments to `AnalyticsController` (disabled by default via `isEventFragmentsEnabled`), letting clients accumulate analytics properties across a user journey and optionally emit an initial, success, or failure event for it ([MetaMask#10055](MetaMask#10055)) #### Changed - Bump `@metamask/utils` from `^11.11.0` to `^11.12.0` ([MetaMask#10076](MetaMask#10076)) ## References - Related to MetaMask#10055 ## Checklist - [x] I've updated the test suite for new or updated code as appropriate - [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [x] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them Made with [Cursor](https://cursor.com) --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Explanation
This PR bumps
@metamask/utilsto^11.12.0(see CHANGELOG)References
Checklist
Note
Low Risk
Dependency-only bump with no in-repo code changes; risk depends on
@metamask/utils11.12.0 release notes, but scope here is mechanical version alignment.Overview
Bumps the shared
@metamask/utilsdependency from^11.11.0to^11.12.0repo-wide, including the rootpackage.jsonand every affected workspace package that declares it (dependencies or devDependencies).Each touched package gets an [Unreleased] changelog entry (or an updated existing utils bump line) referencing #10076. There are no changes to controller logic, middleware, or tests in this repo—only version alignment and release notes.
Reviewed by Cursor Bugbot for commit a708932. Bugbot is set up for automated code reviews on this repo. Configure here.