Skip to content

chore(utils): replace uuid dependency with crypto.randomUUID - #10758

Open
avantikonde wants to merge 1 commit into
MetaMask:mainfrom
avantikonde:remove-uuid-utils
Open

avantikonde wants to merge 1 commit into
MetaMask:mainfrom
avantikonde:remove-uuid-utils

Conversation

@avantikonde

@avantikonde avantikonde commented Oct 8, 2026 •

Copy link
Copy Markdown

Explanation

  • @metamask/utils was declaring uuid as a production dependency solely for generating temporary test directory paths in createSandbox() in src/fs.ts.
  • Replaced uuidV4() with Node's built-in crypto.randomUUID(), which has been standard since Node 14.17 and is natively supported in the required Node version range (^22.14.0 || ^24).
  • Dropped uuid from packages/utils/package.json dependencies, removing an unnecessary package from consumer dependency trees.
  • Updated packages/utils/src/fs.test.ts to mock crypto.randomUUID using jest.spyOn so test sandbox paths remain deterministic.
  • Pruned stale oxlint suppressions and updated packages/utils/CHANGELOG.md.

References

Fixes #10210

Checklist

  • I've updated the test suite for new or updated code as appropriate
  • I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
  • I've communicated my changes to consumers by updating changelogs for packages I've changed
  • I've introduced breaking changes in this PR and have prepared draft pull requests for clients and consumer packages to resolve them

Note

Low Risk
Small dependency swap in Node-only test sandbox path generation; supported Node engines already require versions with crypto.randomUUID().

Overview
Removes the uuid production dependency from @metamask/utils and uses Node’s built-in crypto.randomUUID() when createSandbox() builds unique temp directory names in fs.ts.

Tests in fs.test.ts now stub crypto.randomUUID with jest.spyOn instead of mocking the uuid package. The package changelog documents the removal, package.json / yarn.lock no longer list uuid, and related oxlint suppression counts were trimmed.

Reviewed by Cursor Bugbot for commit 76aa19e. Bugbot is set up for automated code reviews on this repo. Configure here.

@avantikonde
avantikonde requested a review from a team as a code owner October 8, 2026 17:26

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[utils] Replace the uuid dependency with crypto.randomUUID()

1 participant