chore(deps): bump the npm_and_yarn group across 23 directories with 1 update - #9369
Open
dependabot[bot] wants to merge 1 commit into
Open
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b
branch
from
July 6, 2026 13:13
f389732 to
0de147a
Compare
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b
branch
5 times, most recently
from
July 10, 2026 16:21
df9ad1a to
ccde264
Compare
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b
branch
3 times, most recently
from
July 22, 2026 10:38
64dae16 to
fccaf50
Compare
… update Bumps the npm_and_yarn group with 1 update in the /packages/accounts-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/analytics-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/assets-controllers directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/bridge-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/bridge-status-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/core-backend directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/eip-5792-middleware directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/gas-fee-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/keyring-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/logging-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/message-manager directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/multichain-account-service directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/multichain-transactions-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/network-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/notification-services-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/perps-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/polling-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/profile-metrics-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/remote-feature-flag-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/shield-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/signature-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/transaction-controller directory: [uuid](https://github.com/uuidjs/uuid). Bumps the npm_and_yarn group with 1 update in the /packages/user-operation-controller directory: [uuid](https://github.com/uuidjs/uuid). Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) Updates `uuid` from 8.3.2 to 14.0.1 - [Release notes](https://github.com/uuidjs/uuid/releases) - [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md) - [Commits](uuidjs/uuid@v8.3.2...v14.0.1) --- updated-dependencies: - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:development - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:development - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:development - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production - dependency-name: uuid dependency-version: 14.0.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b
branch
from
July 22, 2026 11:33
fccaf50 to
bb3b765
Compare
1 of 4 tasks
pull Bot
pushed a commit
to Reality2byte/core
that referenced
this pull request
Sep 14, 2026
…ask#10225) ## Explanation `expectConsistentDependenciesAndDevDependencies` requires every workspace to use the same version range for a dependency, but it reports through `dependency.error()`, which Yarn has no way to repair. So `yarn constraints --fix` does nothing for it and a human has to hand edit every manifest. That mostly hurts on Dependabot PRs. Dependabot's security updates walk manifests one at a time rather than treating the Yarn workspace as one project, so they routinely bump a dependency in some packages and not others. The result is a red build on a change nobody actually has to think about. PR MetaMask#10147 is a good example: it bumped `uuid` in 22 packages, `uuid` is declared in 24, and the two stragglers fail constraints. Same story on MetaMask#10157, MetaMask#10177 and MetaMask#9369, which is a large part of why `uuid` alone accounts for 25 of our open Dependabot alerts. This makes the rule fixable. When every conflicting range is plain semver, the one permitting the highest minimum version wins and `dependency.update()` aligns the rest, so `yarn constraints --fix` (which `yarn lint:fix` already runs) repairs a partial bump on its own. The previous docstring said it is impossible to compare NPM version ranges, so let the user decide. That is still true in general, and the fallback is unchanged: anything that is not a plain semver range, so aliases like `npm:foo@^1.0.0`, protocols like `workspace:^`, or dist tags, still produces the original "Pick one" error with the same wording. The narrower claim here is only that `semver.minVersion()` is comparable when every range has one, and `getHighestRange` bails out the moment one doesn't. Nothing else in the file changes. `ALLOWED_INCONSISTENT_DEPENDENCIES` and its filter behave exactly as before. ## Verification There is no test harness for `yarn.config.cjs`, so I verified against the monorepo itself: | Case | Result | | --- | --- | | Clean tree | exit 0, no manifests modified | | `uuid` bumped in one package only | `--fix` aligned all 25 manifests, re-check clean | | One range set to `npm:uuid@^14.0.2` | errors with "Pick one", modifies nothing | | One package downgraded to `^8.0.0` | pulled back up to `^9.0.1`, not propagated down | The last one is the safety property worth calling out: a wrong range in one manifest gets corrected upward rather than dragging every other package backwards. Worth knowing that `--fix` also reaches the root `package.json`, which declares some of these dependencies too. ## Trade off Aligning to the highest range is a real dependency change, not a formatting fix. One bump in one package can move the rest onto a new major, and `yarn lint:fix` will do that locally without asking. The argument for it is that the constraint already requires these to move together, so the only open question was who performs the alignment and in which direction, and aligning downward would mean reverting security fixes. ## References Part of [WPC-1161](https://consensyssoftware.atlassian.net/browse/WPC-1161). This is the first step toward dropping the `@metamask/*` allowlist in `.github/dependabot.yml` so we can bump everything, not just MetaMask packages. The follow up is a workflow on bot PRs that runs `yarn constraints --fix`, `yarn dedupe` and `yarn changelog:validate --checkDeps --fix`, modelled on the one snaps already has in `update-pull-request.yml`. Related to MetaMask#10147, MetaMask#10157, MetaMask#10177, MetaMask#9369. ## Checklist - [ ] I've updated the test suite for new or updated code as appropriate (no harness exists for `yarn.config.cjs`, see Verification above) - [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [ ] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) (no published package is touched) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them [WPC-1161]: https://consensyssoftware.atlassian.net/browse/WPC-1161?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ
1 of 4 tasks
pull Bot
pushed a commit
to Reality2byte/core
that referenced
this pull request
Sep 15, 2026
## Explanation Dependabot's pull requests cannot merge on their own. Its security updates walk manifests one at a time rather than treating the Yarn workspace as one project, so a dependency ends up with different ranges in different packages and `yarn constraints` fails. It also does not deduplicate `yarn.lock` and does not write changelog entries. MetaMask#10147, MetaMask#10157, MetaMask#10177 and MetaMask#9369 are all stuck on this. This adds a workflow that repairs all three and pushes the result back. It runs `yarn constraints --fix` with `ALIGN_DEPENDENCY_RANGES=true` (the opt in from MetaMask#10228, whose only intended caller is this workflow), reinstalls, deduplicates, then runs the changelog fixer that already exists. Order matters: aligning ranges rewrites manifests but leaves `yarn.lock` stale. It also adds `@lavamoat/*` to the npm allowlist. Both that and `@metamask/*` are already in `npmPreapprovedPackages`, so neither can trip the Yarn age gate during the repair install. Note that `allow` only governs version updates, so the workflow will also act on security pull requests for other packages, which is where the constraints failures come from. ## Notes - `pull_request`, not `pull_request_target`. Dependabot runs get a read only token and no secrets, so the push is authorised by the OIDC exchange, the same way snaps does it. - `opened` and `reopened` only. The job pushes to the pull request branch, so `synchronize` would loop. - `[dependabot skip]` on the commit, otherwise Dependabot rebases and wipes the repair. ## Verification The workflow cannot run until it is on the default branch. Checked locally: | Check | Result | | --- | --- | | `constraints --fix` leaves `yarn.lock` stale | confirmed, hence the reinstall step | | `ALIGN_DEPENDENCY_RANGES=true yarn constraints --fix` on a split range | aligns all 25 manifests, exit 0 | | Default, without the variable | unchanged, still errors | ## References Follows MetaMask#10225 and MetaMask#10228. Part of WPC-1161. Pattern borrowed from MetaMask/snaps `update-pull-request.yml`. ## Checklist - [ ] I've updated the test suite for new or updated code as appropriate (workflow and config only) - [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate - [ ] I've communicated my changes to consumers by [updating changelogs for packages I've changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md) (no published package is touched) - [ ] I've introduced [breaking changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md) in this PR and have prepared draft pull requests for clients and consumer packages to resolve them <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Changes are limited to Dependabot and CI workflow configuration; no runtime application or auth logic is modified, though the workflow does push commits to Dependabot branches via OIDC token exchange. > > **Overview** > Adds a GitHub Actions workflow that runs when **Dependabot** opens or reopens a PR, then fixes the common reasons those PRs fail CI: misaligned dependency ranges across the Yarn workspace, a stale or duplicated **yarn.lock**, and missing changelog entries. > > The job exchanges an OIDC token for write access (Dependabot’s default token cannot push), runs **`yarn constraints --fix`** with **`ALIGN_DEPENDENCY_RANGES=true`**, reinstalls with **`--no-immutable`**, dedupes, and runs the existing **`changelog:validate --fix`** flow before committing with **`[dependabot skip]`** so Dependabot does not rebase away the repair. It only listens to **`opened`** / **`reopened`** (not **`synchronize`**) to avoid a push loop. > > **Dependabot** config now allows version bumps for **`@lavamoat/*`** npm packages, matching **`@metamask/*`**, so those updates can go through the same repair path without Yarn age-gate issues during install. > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit c90706d. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
1 of 4 tasks
pull Bot
pushed a commit
to Reality2byte/core
that referenced
this pull request
Sep 28, 2026
## Explanation
Renovate opens nothing for security advisories today. Every run logs:
```
WARN: Cannot access vulnerability alerts. Please ensure permissions have been granted. (repository=MetaMask/core)
```
It reads them from `GET /repos/{owner}/{repo}/dependabot/alerts`, so
this grants the token `vulnerability_alerts: read`. That is the
permission name GitHub uses when creating an installation access token,
described as "the level of permission to grant the access token to
manage Dependabot alerts". The UI calls the same thing "Dependabot
alerts".
No Renovate config is needed. The `vulnerabilityAlerts` defaults already
do the right thing here:
| Default | Effect |
| --- | --- |
| `dependencyDashboardApproval: false` | security fixes bypass our
approval gate |
| `minimumReleaseAge: null` | and the three day age gate |
| `prCreation: 'immediate'`, `prConcurrentLimit: 0` | not queued or
capped |
| `rangeStrategy: 'update-lockfile'` | lockfile only, so no changelog
entry is required |
| `commitMessageSuffix: '[SECURITY]'` | visible in the commit |
On whether Dependabot already covers this: there are currently 127 open
alerts, 126 of which have a patched version available, and the only live
Dependabot security pull requests are MetaMask#9369 from July and MetaMask#8849 from
May. Both are stuck, because Dependabot bumps one manifest at a time,
which splits the version range across workspaces and then it refuses to
rebase them.
> [!IMPORTANT]
> Depends on consensys-vertical-apps/token-exchange-service#190, which
allows the permission. It also tests something we cannot check from
outside: if the `metamask-ci` App does not itself hold Dependabot alerts
read, GitHub refuses to mint the token regardless of the policy, exactly
as it did for `statuses: write` in MetaMask#10316. The signature to watch for is
a 500 `Failed to create installation token from GitHub` at the `Get
access token` step. If that happens the App needs the permission
granted, and `osvVulnerabilityAlerts: true` is the fallback that needs
no permission at all.
Dependabot security updates stay on for now, so both bots may raise a
pull request for the same advisory. That overlap is the decision point
for whether Renovate replaces Dependabot here.
## References
Depends on consensys-vertical-apps/token-exchange-service#190. Follows
MetaMask#10495. Part of WPC-1161.
## Checklist
- [ ] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [ ] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **Low Risk**
> Single CI workflow permission change; no application or Renovate
config edits in the diff, though rollout depends on the token exchange
service and GitHub App permissions.
>
> **Overview**
> Renovate was failing to read GitHub Dependabot alerts because the
installation token from **Get access token** did not include
**`vulnerability_alerts: read`**. This PR adds that permission to the
token-exchange `permissions` block in `.github/workflows/renovate.yml`.
>
> With access to `GET /repos/{owner}/{repo}/dependabot/alerts`, Renovate
can open pull requests for security advisories using its existing
**`vulnerabilityAlerts`** defaults (immediate PRs, lockfile updates,
**`[SECURITY]`** suffix), without a **`renovate.json`** change in this
diff.
>
> **Note:** Token minting depends on **token-exchange-service** and the
**`metamask-ci`** app also holding Dependabot alerts read; otherwise the
workflow may fail at **Get access token**.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
9a08eb3. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
This was referenced Sep 29, 2026
This branch was previously deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 1 update in the /packages/accounts-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/analytics-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/assets-controllers directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/bridge-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/bridge-status-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/core-backend directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/eip-5792-middleware directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/gas-fee-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/keyring-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/logging-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/message-manager directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/multichain-account-service directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/multichain-transactions-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/network-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/notification-services-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/perps-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/polling-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/profile-metrics-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/remote-feature-flag-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/shield-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/signature-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/transaction-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/user-operation-controller directory: uuid.
Updates
uuidfrom 8.3.2 to 14.0.1Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.
... (truncated)
Commits
7017780chore(main): release 14.0.1 (#964)f2c3e4bchore: fix release-please workflow (#963)27ffae5fix: add types condition to node export for moduleResolution bundler (#961)664cb31Remove outdated security contact information (#959)d729016fix(ci): checkout PR head commit in browser workflow (#957)89a5ebcWorkflows (#948)196e208chore: fix workflow (#947)95af448chore: update workflows (#946)3b57f95chore: add workflow_dispatch (#944)a433096chore: add 12.x and 13.x maintenance release branches (#941)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
uuidfrom 8.3.2 to 14.0.1Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.
... (truncated)
Commits
7017780chore(main): release 14.0.1 (#964)f2c3e4bchore: fix release-please workflow (#963)27ffae5fix: add types condition to node export for moduleResolution bundler (#961)664cb31Remove outdated security contact information (#959)d729016fix(ci): checkout PR head commit in browser workflow (#957)89a5ebcWorkflows (#948)196e208chore: fix workflow (#947)95af448chore: update workflows (#946)3b57f95chore: add workflow_dispatch (#944)a433096chore: add 12.x and 13.x maintenance release branches (#941)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
uuidfrom 8.3.2 to 14.0.1Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.
... (truncated)
Commits
7017780chore(main): release 14.0.1 (#964)f2c3e4bchore: fix release-please workflow (#963)27ffae5fix: add types condition to node export for moduleResolution bundler (#961)664cb31Remove outdated security contact information (#959)d729016fix(ci): checkout PR head commit in browser workflow (#957)89a5ebcWorkflows (#948)196e208chore: fix workflow (#947)95af448chore: update workflows (#946)3b57f95chore: add workflow_dispatch (#944)a433096chore: add 12.x and 13.x maintenance release branches (#941)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
uuidfrom 8.3.2 to 14.0.1Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.
... (truncated)
Commits
7017780chore(main): release 14.0.1 (#964)f2c3e4bchore: fix release-please workflow (#963)27ffae5fix: add types condition to node export for moduleResolution bundler (#961)664cb31Remove outdated security contact information (#959)d729016fix(ci): checkout PR head commit in browser workflow (#957)89a5ebcWorkflows (#948)196e208chore: fix workflow (#947)95af448chore: update workflows (#946)3b57f95chore: add workflow_dispatch (#944)a433096chore: add 12.x and 13.x maintenance release branches (#941)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
uuidfrom 8.3.2 to 14.0.1Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.
... (truncated)
Commits
7017780chore(main): release 14.0.1 (#964)f2c3e4bchore: fix release-please workflow (#963)27ffae5fix: add types condition to node export for moduleResolution bundler (#961)664cb31Remove outdated security contact information (#959)d729016fix(ci): checkout PR head commit in browser workflow (#957)89a5ebcWorkflows (#948)196e208chore: fix workflow (#947)95af448chore: update workflows (#946)3b57f95chore: add workflow_dispatch (#944)a433096chore: add 12.x and 13.x maintenance release branches (#941)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
uuidfrom 8.3.2 to 14.0.1Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.
... (truncated)
Commits
7017780chore(main): release 14.0.1 (#964)f2c3e4bchore: fix release-please workflow (#963)27ffae5fix: add types condition to node export for moduleResolution bundler (#961)664cb31Remove outdated security contact information (#959)d729016fix(ci): checkout PR head commit in browser workflow (#957)89a5ebcWorkflows (#948)196e208chore: fix workflow (#947)95af448chore: update workflows (#946)3b57f95chore: add workflow_dispatch (#944)a433096chore: add 12.x and 13.x maintenance release branches (#941)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
uuidfrom 8.3.2 to 14.0.1Release notes
Sourced from uuid's releases.
... (truncated)
Changelog
Sourced from uuid's changelog.
... (truncated)
Commits
7017780chore(main): release 14.0.1 (#964)f2c3e4bchore: fix release-please workflow (#963)27ffae5fix: add types condition to node export for moduleResolution bundler (#961)664cb31Remove outdated security contact information (#959)d729016fix(ci): checkout PR head commit in browser workflow (#957)89a5ebcWorkflows (#948)