Skip to content

chore: bump @metamask/utils from ^11.11.0 to ^11.12.0 - #10076

Merged
cryptodev-2s merged 3 commits into
mainfrom
chore/bump-utils-11.12.0
Sep 2, 2026
Merged

cryptodev-2s merged 3 commits into
mainfrom
chore/bump-utils-11.12.0

Conversation

@cryptodev-2s

@cryptodev-2s cryptodev-2s commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Explanation

This PR bumps @metamask/utils to ^11.12.0 (see CHANGELOG)

References

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Low Risk
Dependency-only bump with no in-repo code changes; risk depends on @metamask/utils 11.12.0 release notes, but scope here is mechanical version alignment.

Overview
Bumps the shared @metamask/utils dependency from ^11.11.0 to ^11.12.0 repo-wide, including the root package.json and every affected workspace package that declares it (dependencies or devDependencies).

Each touched package gets an [Unreleased] changelog entry (or an updated existing utils bump line) referencing #10076. There are no changes to controller logic, middleware, or tests in this repo—only version alignment and release notes.

Reviewed by Cursor Bugbot for commit a708932. Bugbot is set up for automated code reviews on this repo. Configure here.

@socket-security

socket-security Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​metamask/​utils@​11.11.0 ⏵ 11.12.09910094 +193 +5100

View full report

@cryptodev-2s

Copy link
Copy Markdown
Contributor Author

@metamaskbot update-changelogs

@cryptodev-2s cryptodev-2s changed the title chore: bump @metamask/utils from ^11.11.0 to ^11.12.0 chore: bump @metamask/utils from ^11.11.0 to ^11.12.0 Sep 2, 2026
mcmire
mcmire previously approved these changes Sep 2, 2026

@mcmire mcmire left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM.

@cryptodev-2s
cryptodev-2s added this pull request to the merge queue Sep 2, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 2, 2026
@cryptodev-2s
cryptodev-2s added this pull request to the merge queue Sep 2, 2026
Merged via the queue into main with commit 23c2393 Sep 2, 2026
444 of 450 checks passed
@cryptodev-2s
cryptodev-2s deleted the chore/bump-utils-11.12.0 branch September 2, 2026 13:58
@adonesky1 adonesky1 mentioned this pull request Sep 2, 2026
4 tasks
rajanpanth pushed a commit to rajanpanth/core that referenced this pull request Sep 3, 2026
## Explanation

**Summary**

Publish `@metamask/phishing-controller` 17.4.1 and
`@metamask/transaction-controller` 69.8.0 so clients can pick up the
address-poisoning known-set fix from MetaMask#9943.

**Problem**

Phishing known recipients were hydrated via `getEffectiveRecipient`,
which falls back to `txParams.to` for non-transfers. Confirmed approves
and contract interactions therefore seeded token and protocol addresses
into the comparison set, and vanity factories could 4+4-match each other
(false positives on Permit2 approves).

**Solution**

- `@metamask/transaction-controller@69.8.0` (minor): export
`getSendRecipients` for user-chosen send payees only
- `@metamask/phishing-controller@17.4.1` (patch): hydrate known
recipients from `getSendRecipients` instead of `getEffectiveRecipient`,
plus the pending C2 blocklist Set optimization and
transaction-controller range bump to `^69.8.0`

Workspace dependents bump their `@metamask/phishing-controller` /
`@metamask/transaction-controller` ranges but are not published in this
release.

**Risk**

No breaking API changes. Known-set membership narrows to real send
payees (correct for poisoning). Clients still on older
phishing-controller keep the old set until they bump.

**Intentionally skipped**

`@metamask/address-book-controller`, `@metamask/base-controller`,
`@metamask/controller-utils`, `@metamask/messenger`,
`@metamask/accounts-controller`, `@metamask/approval-controller`,
`@metamask/core-backend`, `@metamask/gas-fee-controller`,
`@metamask/network-controller`,
`@metamask/remote-feature-flag-controller`, and
`@metamask/eth-block-tracker` have unrelated unreleased changes and are
not required for MetaMask#9943.

### `@metamask/phishing-controller@17.4.1`

#### Changed

- Optimize C2 domain blocklist lookups by switching internal storage
from `Array` to `Set`
([MetaMask#6388](MetaMask#6388))
- Bump `@metamask/transaction-controller` from `^69.5.2` to `^69.8.0`

#### Fixed

- Restrict address poisoning known recipients to user-chosen send payees
([MetaMask#9943](MetaMask#9943))

### `@metamask/transaction-controller@69.8.0`

#### Added

- Export `getSendRecipients`
([MetaMask#9943](MetaMask#9943))

#### Changed

- Bump `@metamask/utils` from `^11.11.0` to `^11.12.0`
([MetaMask#10076](MetaMask#10076))

## References

- Related to MetaMask#9943
- Ticket: https://consensyssoftware.atlassian.net/browse/PSAFE-633
- Extension follow-up:
MetaMask/metamask-extension#45724

## Checklist

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Release packaging and dependency alignment; behavioral fixes ship via
already-reviewed controller versions with no additional logic in this
PR.
> 
> **Overview**
> Cuts **monorepo release 1229.0.0** and publishes
**`@metamask/phishing-controller@17.4.1`** and
**`@metamask/transaction-controller@69.8.0`**, with
version/changelog/`yarn.lock` updates only (no new application source in
this diff).
> 
> **`@metamask/transaction-controller@69.8.0`** documents export of
**`getSendRecipients`** so callers can resolve user-chosen send payees
(simple sends, decoded transfers, swap-and-send, batch sends) without
treating `txParams.to` as the payee.
> 
> **`@metamask/phishing-controller@17.4.1`** documents switching
address-poisoning “known recipient” hydration to **`getSendRecipients`**
instead of **`getEffectiveRecipient`**, plus C2 blocklist storage moved
from `Array` to `Set` for O(1) lookups.
> 
> Workspace packages that depend on phishing or transaction-controller
bump to **`^17.4.1`** / **`^69.8.0`** (e.g. **`assets-controller`**,
bridge, wallet); those packages are not newly published here—only the
two security-related controllers and the root monorepo version.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
265147e. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@gauthierpetetin gauthierpetetin mentioned this pull request Sep 3, 2026
4 tasks
adonesky1 pushed a commit to wzrdk3lly/core that referenced this pull request Sep 3, 2026
## Explanation

**Summary**

Publish `@metamask/analytics-controller@2.1.0` so clients can opt into
journey-scoped event fragments from
[MetaMask#10055](MetaMask#10055).

**Problem**

Clients that track multi-step user journeys (signature requests,
transaction confirmations, and similar flows) must re-derive the same
analytics properties at every step, or build ad hoc state to carry them
forward. There is no shared controller primitive for accumulating
properties across a journey and optionally closing it with a success or
failure event.

**Solution**

- `@metamask/analytics-controller@2.1.0` (minor): add optional event
fragments, disabled by default via `isEventFragmentsEnabled`
- Funnel shape: declare `initialEvent`, `successEvent`, and/or
`failureEvent`, then call `finalizeEventFragment`
- Property-bag shape: declare no event names and read accumulated
properties back with `getEventFragmentById` when emitting a custom event
- Fragment methods respect the same consent gate as `trackEvent`, return
read-only copies from `createEventFragment` / `getEventFragmentById`,
and discard stale non-persistent or expired persisted fragments on
`init`

Workspace dependents bump their `@metamask/analytics-controller` range
to `^2.1.0` but are not published in this release:

- `@metamask/network-controller`
- `@metamask/wallet-cli`

**Risk**

No breaking API changes. Event fragments are disabled by default, so
existing consumers keep current behavior until they opt in with
`isEventFragmentsEnabled`.

### `@metamask/analytics-controller@2.1.0`

#### Added

- Add optional event fragments to `AnalyticsController` (disabled by
default via `isEventFragmentsEnabled`), letting clients accumulate
analytics properties across a user journey and optionally emit an
initial, success, or failure event for it
([MetaMask#10055](MetaMask#10055))

#### Changed

- Bump `@metamask/utils` from `^11.11.0` to `^11.12.0`
([MetaMask#10076](MetaMask#10076))

## References

- Related to MetaMask#10055

## Checklist

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

Made with [Cursor](https://cursor.com)

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants