Skip to content

fix: bump uuid to ^11.1.1 across the monorepo - #10243

Merged
cryptodev-2s merged 9 commits into
mainfrom
fix/bump-uuid-across-monorepo
Sep 15, 2026
Merged

cryptodev-2s merged 9 commits into
mainfrom
fix/bump-uuid-across-monorepo

Conversation

@cryptodev-2s

@cryptodev-2s cryptodev-2s commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Explanation

Clears GHSA-w5hq-g745-h8pq, which accounts for 25 of the repo's 155 open Dependabot alerts. The advisory is a missing buffer bounds check in v3/v5/v6 when buf is supplied; core only uses v1 and v4, so nothing here was exploitable, but the alerts need clearing.

Dependabot proposed ^14.0.2 in #10147. This goes to ^11.1.1 instead, the lowest patched version, because uuid is ESM-only from v12 onwards and our Jest setup cannot load an ESM-only dependency without transforming it: jest.requireActual('uuid') fails with SyntaxError: Unexpected token 'export'. Moving to v14 is doable but needs transformIgnorePatterns work, which does not belong in a security fix.

Also drops @types/uuid from 11 manifests, since uuid has bundled its own types since v10.

packages/utils/src/fs.test.ts needed a small helper: v4 is overloaded and jest.spyOn resolves to the last overload, which returns Uint8Array rather than string. That is true in both v11 and v14, so it is not specific to the version chosen.

Client impact

Checked against the clients' lockfiles rather than assumed. Both already resolve uuid 11, so this introduces nothing new and core's 9.0.1 copy should collapse into the 11.1.1 already present.

client uuid versions already resolved
metamask-extension 3.2.1, 3.4.0, 8.3.2, 9.0.1, 11.0.3, 11.1.1
metamask-mobile 3.3.2, 7.0.3, 8.3.2, 9.0.0, 9.0.1, 11.0.3, 11.1.0, 14.0.1

Worth noting for anyone tempted by v14 later: metamask-extension has no uuid 14 anywhere and pins a transitive gridplus-sdk/uuid@^13.0.0 back down to ^8.3.2.

References

Supersedes #10147. Part of WPC-1161.

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Low Risk
Monorepo-wide dependency and typing cleanup with no production API changes; usage stays on v4/v1-style imports clients already resolve at 11.x.

Overview
Raises uuid from ^9.0.1 (and changelog references from older ranges) to ^11.1.1 on the root devDependency and across controller/utils packages, with matching yarn.lock and Unreleased changelog entries. This targets the patched line for advisory GHSA-w5hq-g745-h8pq without jumping to ESM-only v12+, which the PR notes would break Jest’s requireActual('uuid') pattern.

@types/uuid is removed from the manifests that had it, since uuid ≥ v10 ships its own types.

The only non-manifest code change is in packages/utils/src/fs.test.ts: tests mock v4 via a jest.fn wrapper and a mockUuidV4 helper instead of jest.spyOn on a namespace import, avoiding v4’s overload typing returning Uint8Array when spied.

Reviewed by Cursor Bugbot for commit 197dee5. Bugbot is set up for automated code reviews on this repo. Configure here.

@cryptodev-2s

Copy link
Copy Markdown
Contributor Author

@metamaskbot update-changelogs

@socket-security

socket-security Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addeduuid@​11.1.110010010089100

View full report

@metamask-ci

metamask-ci Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

✅ Changelogs updated and pushed.

@cryptodev-2s
cryptodev-2s marked this pull request as ready for review September 15, 2026 13:39
@cryptodev-2s
cryptodev-2s requested review from a team as code owners September 15, 2026 13:39
@cryptodev-2s
cryptodev-2s deployed to default-branch September 15, 2026 13:39 — with GitHub Actions Active
@cryptodev-2s cryptodev-2s changed the title fix: bump uuid to ^11.1.1 across the monorepo fix: bump uuid to ^11.1.1 across the monorepo Sep 15, 2026
@cryptodev-2s cryptodev-2s changed the title fix: bump uuid to ^11.1.1 across the monorepo fix: bump uuid to ^11.1.1 across the monorepo Sep 15, 2026
@cryptodev-2s cryptodev-2s mentioned this pull request Sep 15, 2026
1 of 4 tasks
Comment thread packages/utils/src/fs.test.ts
@cryptodev-2s
cryptodev-2s requested a review from mcmire September 15, 2026 15:20

@mcmire mcmire left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Checked over uuid's changelog and there doesn't seem to be any changes that impact us. LGTM.

@cryptodev-2s
cryptodev-2s added this pull request to the merge queue Sep 15, 2026
Merged via the queue into main with commit ea98fef Sep 15, 2026
337 checks passed
@cryptodev-2s
cryptodev-2s deleted the fix/bump-uuid-across-monorepo branch September 15, 2026 16:36
@pedronfigueiredo pedronfigueiredo mentioned this pull request Sep 16, 2026
3 of 4 tasks
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 16, 2026
## Explanation

Creates monorepo release 1258.0.0 with one package release:

- `@metamask/transaction-controller` 70.1.0

This release removes the fixed 21,000 gas-limit shortcut for ordinary
transactions without caller-provided gas. Transaction Controller now
uses the selected network client's existing node/simulation estimation
path, preserving caller-provided gas and existing estimation-failure
behavior. This makes gas-limit estimation node-authoritative across
legacy and EIP-2780-enabled networks without a client-side activation
schedule.

The release also includes the pending `uuid` runtime dependency update
from `^9.0.1` to `^11.1.1`.

## References

- MetaMask#10245
- MetaMask#10243
- [CONF-1995](https://consensyssoftware.atlassian.net/browse/CONF-1995)

## Validation

- `yarn changelog:validate`
- `yarn constraints`
- `yarn install --immutable`
- `yarn workspace @metamask/transaction-controller run test`

## Checklist

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by updating changelogs
for packages I've changed
- [ ] I've introduced breaking changes in this PR and have prepared
draft pull requests for clients and consumer packages to resolve them —
not applicable; this is a minor release without breaking changes


[CONF-1995]:
https://consensyssoftware.atlassian.net/browse/CONF-1995?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Propagates a minor release that changes default gas-limit behavior for
many transaction flows; impact is behavioral rather than mechanical
dependency wiring.
> 
> **Overview**
> Prepares **monorepo release 1258.0.0** by cutting
**`@metamask/transaction-controller` 70.1.0** and aligning dependents on
**`^70.1.0`** (from `^70.0.1`).
> 
> The release documents behavior already shipped in that package:
**plain transfers without caller-supplied gas no longer get a hard-coded
21,000 limit** and instead use the **selected network client’s gas
estimation path**, plus a **`uuid` dependency bump** (`^9.0.1` →
`^11.1.1`). This PR itself is **versioning only**—root `package.json`,
per-package `package.json` / `CHANGELOG.md`, and **`yarn.lock`**—across
assets, bridge, client-utils, EIP-5792 middleware, phishing, wallet, and
other packages that depend on transaction-controller.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
cd730cd. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@gauthierpetetin gauthierpetetin mentioned this pull request Sep 18, 2026
3 of 4 tasks
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 18, 2026
## Explanation

Creates monorepo release 1265.0.0 with one package release:

- `@metamask/analytics-controller` 3.1.0

This release ships independent marketing consent and purpose-aware event
classification. It adds `optedInToMarketing`, `optInToMarketing` /
`optOutOfMarketing` / `resetMarketingConsentDecision`, and a persisted
`eventsConfig` whose unlisted events default to product-only. Named
`track` and `view` payloads are delivered once with their allowed
purposes in `context.consent.categoryPreferences` and their capture-time
config version in `context.eventsConfigVersion`. Queues and fragments
retain capture-time purpose classification so config changes cannot
reclassify captured events. Mixed-purpose fragments classify each
declared lifecycle event independently.

Workspace dependents `@metamask/network-controller` and
`@metamask/wallet-cli` are aligned to `@metamask/analytics-controller`
`^3.1.0`.

The release also includes pending dependency bumps for `uuid` (`^8.3.2`
→ `^11.1.1`) and `@metamask/utils` (`^11.12.0` → `^12.0.0`).

## References

- MetaMask#10232
- MetaMask#10117
- MetaMask#10243
- MetaMask#10192

## Checklist

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

Made with [Cursor](https://cursor.com)

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants