fix: bump uuid to ^11.1.1 across the monorepo - #10243
Merged
Merged
Conversation
Contributor
Author
|
@metamaskbot update-changelogs |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
Contributor
|
✅ Changelogs updated and pushed. |
cryptodev-2s
marked this pull request as ready for review
September 15, 2026 13:39
^11.1.1 across the monorepo
^11.1.1 across the monorepouuid to ^11.1.1 across the monorepo
1 of 4 tasks
cryptodev-2s
enabled auto-merge
September 15, 2026 14:14
mcmire
reviewed
Sep 15, 2026
mcmire
approved these changes
Sep 15, 2026
mcmire
left a comment
Collaborator
There was a problem hiding this comment.
Checked over uuid's changelog and there doesn't seem to be any changes that impact us. LGTM.
Merged
3 of 4 tasks
pull Bot
pushed a commit
to Reality2byte/core
that referenced
this pull request
Sep 16, 2026
## Explanation Creates monorepo release 1258.0.0 with one package release: - `@metamask/transaction-controller` 70.1.0 This release removes the fixed 21,000 gas-limit shortcut for ordinary transactions without caller-provided gas. Transaction Controller now uses the selected network client's existing node/simulation estimation path, preserving caller-provided gas and existing estimation-failure behavior. This makes gas-limit estimation node-authoritative across legacy and EIP-2780-enabled networks without a client-side activation schedule. The release also includes the pending `uuid` runtime dependency update from `^9.0.1` to `^11.1.1`. ## References - MetaMask#10245 - MetaMask#10243 - [CONF-1995](https://consensyssoftware.atlassian.net/browse/CONF-1995) ## Validation - `yarn changelog:validate` - `yarn constraints` - `yarn install --immutable` - `yarn workspace @metamask/transaction-controller run test` ## Checklist - [x] I've updated the test suite for new or updated code as appropriate - [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [x] I've communicated my changes to consumers by updating changelogs for packages I've changed - [ ] I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them — not applicable; this is a minor release without breaking changes [CONF-1995]: https://consensyssoftware.atlassian.net/browse/CONF-1995?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Medium Risk** > Propagates a minor release that changes default gas-limit behavior for many transaction flows; impact is behavioral rather than mechanical dependency wiring. > > **Overview** > Prepares **monorepo release 1258.0.0** by cutting **`@metamask/transaction-controller` 70.1.0** and aligning dependents on **`^70.1.0`** (from `^70.0.1`). > > The release documents behavior already shipped in that package: **plain transfers without caller-supplied gas no longer get a hard-coded 21,000 limit** and instead use the **selected network client’s gas estimation path**, plus a **`uuid` dependency bump** (`^9.0.1` → `^11.1.1`). This PR itself is **versioning only**—root `package.json`, per-package `package.json` / `CHANGELOG.md`, and **`yarn.lock`**—across assets, bridge, client-utils, EIP-5792 middleware, phishing, wallet, and other packages that depend on transaction-controller. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit cd730cd. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Merged
3 of 4 tasks
pull Bot
pushed a commit
to Reality2byte/core
that referenced
this pull request
Sep 18, 2026
## Explanation Creates monorepo release 1265.0.0 with one package release: - `@metamask/analytics-controller` 3.1.0 This release ships independent marketing consent and purpose-aware event classification. It adds `optedInToMarketing`, `optInToMarketing` / `optOutOfMarketing` / `resetMarketingConsentDecision`, and a persisted `eventsConfig` whose unlisted events default to product-only. Named `track` and `view` payloads are delivered once with their allowed purposes in `context.consent.categoryPreferences` and their capture-time config version in `context.eventsConfigVersion`. Queues and fragments retain capture-time purpose classification so config changes cannot reclassify captured events. Mixed-purpose fragments classify each declared lifecycle event independently. Workspace dependents `@metamask/network-controller` and `@metamask/wallet-cli` are aligned to `@metamask/analytics-controller` `^3.1.0`. The release also includes pending dependency bumps for `uuid` (`^8.3.2` → `^11.1.1`) and `@metamask/utils` (`^11.12.0` → `^12.0.0`). ## References - MetaMask#10232 - MetaMask#10117 - MetaMask#10243 - MetaMask#10192 ## Checklist - [x] I've updated the test suite for new or updated code as appropriate - [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [x] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them Made with [Cursor](https://cursor.com) --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Explanation
Clears GHSA-w5hq-g745-h8pq, which accounts for 25 of the repo's 155 open Dependabot alerts. The advisory is a missing buffer bounds check in
v3/v5/v6whenbufis supplied; core only usesv1andv4, so nothing here was exploitable, but the alerts need clearing.Dependabot proposed
^14.0.2in #10147. This goes to^11.1.1instead, the lowest patched version, because uuid is ESM-only from v12 onwards and our Jest setup cannot load an ESM-only dependency without transforming it:jest.requireActual('uuid')fails withSyntaxError: Unexpected token 'export'. Moving to v14 is doable but needstransformIgnorePatternswork, which does not belong in a security fix.Also drops
@types/uuidfrom 11 manifests, since uuid has bundled its own types since v10.packages/utils/src/fs.test.tsneeded a small helper:v4is overloaded andjest.spyOnresolves to the last overload, which returnsUint8Arrayrather thanstring. That is true in both v11 and v14, so it is not specific to the version chosen.Client impact
Checked against the clients' lockfiles rather than assumed. Both already resolve uuid 11, so this introduces nothing new and core's
9.0.1copy should collapse into the11.1.1already present.Worth noting for anyone tempted by v14 later: metamask-extension has no uuid 14 anywhere and pins a transitive
gridplus-sdk/uuid@^13.0.0back down to^8.3.2.References
Supersedes #10147. Part of WPC-1161.
Checklist
Note
Low Risk
Monorepo-wide dependency and typing cleanup with no production API changes; usage stays on
v4/v1-style imports clients already resolve at 11.x.Overview
Raises
uuidfrom^9.0.1(and changelog references from older ranges) to^11.1.1on the root devDependency and across controller/utils packages, with matchingyarn.lockand Unreleased changelog entries. This targets the patched line for advisory GHSA-w5hq-g745-h8pq without jumping to ESM-only v12+, which the PR notes would break Jest’srequireActual('uuid')pattern.@types/uuidis removed from the manifests that had it, sinceuuid≥ v10 ships its own types.The only non-manifest code change is in
packages/utils/src/fs.test.ts: tests mockv4via ajest.fnwrapper and amockUuidV4helper instead ofjest.spyOnon a namespace import, avoidingv4’s overload typing returningUint8Arraywhen spied.Reviewed by Cursor Bugbot for commit 197dee5. Bugbot is set up for automated code reviews on this repo. Configure here.