Skip to content

chore(deps): bump the npm_and_yarn group across 23 directories with 1 update - #9369

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the /packages/accounts-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/analytics-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/assets-controllers directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/bridge-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/bridge-status-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/core-backend directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/eip-5792-middleware directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/gas-fee-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/keyring-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/logging-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/message-manager directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/multichain-account-service directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/multichain-transactions-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/network-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/notification-services-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/perps-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/polling-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/profile-metrics-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/remote-feature-flag-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/shield-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/signature-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/transaction-controller directory: uuid.
Bumps the npm_and_yarn group with 1 update in the /packages/user-operation-controller directory: uuid.

Updates uuid from 8.3.2 to 14.0.1

Release notes

Sourced from uuid's releases.

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates uuid from 8.3.2 to 14.0.1

Release notes

Sourced from uuid's releases.

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates uuid from 8.3.2 to 14.0.1

Release notes

Sourced from uuid's releases.

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates uuid from 8.3.2 to 14.0.1

Release notes

Sourced from uuid's releases.

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates uuid from 8.3.2 to 14.0.1

Release notes

Sourced from uuid's releases.

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates uuid from 8.3.2 to 14.0.1

Release notes

Sourced from uuid's releases.

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for uuid since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates uuid from 8.3.2 to 14.0.1

Release notes

Sourced from uuid's releases.

v14.0.1

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

v14.0.0

14.0.0 (2026-04-19)

⚠ BREAKING CHANGES

  • expect crypto to be global everywhere (requires node@20+) (#935)
  • drop node@18 support (#934)

Features

Bug Fixes

  • expect crypto to be global everywhere (requires node@20+) (#935) (f2c235f)
  • Use GITHUB_TOKEN for release-please and enable npm provenance (#925) (ffa3138)

v13.0.2

13.0.2 (2026-05-04)

Bug Fixes

  • rerelease to fix provenance. (49ccb35)

v13.0.1

13.0.1 (2026-04-27)

Bug Fixes

v13.0.0

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

... (truncated)

Changelog

Sourced from uuid's changelog.

14.0.1 (2026-06-20)

Bug Fixes

  • add types condition to node export for moduleResolution bundler (#961) (27ffae5)

14.0.0 (2026-04-19)

Security

  • Fixes GHSA-w5hq-g745-h8pq: v3(), v5(), and v6() did not validate that writes would remain within the bounds of a caller-supplied buffer, allowing out-of-bounds writes when an invalid offset was provided. A RangeError is now thrown if offset < 0 or offset + 16 > buf.length.

⚠ BREAKING CHANGES

  • crypto is now expected to be globally defined (requires node@20+) (#935)
  • drop node@18 support (#934)
  • upgrade minimum supported TypeScript version to 5.4.3, in keeping with the project's policy of supporting TypeScript versions released within the last two years

13.0.0 (2025-09-08)

⚠ BREAKING CHANGES

  • make browser exports the default (#901)

Bug Fixes

12.0.0 (2025-09-05)

⚠ BREAKING CHANGES

  • update to typescript@5.2 (#887)
  • remove CommonJS support (#886)
  • drop node@16 support (#883)

Features

Bug Fixes

... (truncated)

Commits
  • 7017780 chore(main): release 14.0.1 (#964)
  • f2c3e4b chore: fix release-please workflow (#963)
  • 27ffae5 fix: add types condition to node export for moduleResolution bundler (#961)
  • 664cb31 Remove outdated security contact information (#959)
  • d729016 fix(ci): checkout PR head commit in browser workflow (#957)
  • 89a5ebc Workflows (#948)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 2, 2026
@dependabot
dependabot Bot requested review from a team as code owners July 2, 2026 09:36
@dependabot
dependabot Bot temporarily deployed to default-branch July 2, 2026 09:36 Inactive
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b branch from f389732 to 0de147a Compare July 6, 2026 13:13
@dependabot
dependabot Bot requested a review from a team as a code owner July 6, 2026 13:13
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b branch 5 times, most recently from df9ad1a to ccde264 Compare July 10, 2026 16:21
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b branch 3 times, most recently from 64dae16 to fccaf50 Compare July 22, 2026 10:38
… update

Bumps the npm_and_yarn group with 1 update in the /packages/accounts-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/analytics-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/assets-controllers directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/bridge-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/bridge-status-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/core-backend directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/eip-5792-middleware directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/gas-fee-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/keyring-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/logging-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/message-manager directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/multichain-account-service directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/multichain-transactions-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/network-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/notification-services-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/perps-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/polling-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/profile-metrics-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/remote-feature-flag-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/shield-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/signature-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/transaction-controller directory: [uuid](https://github.com/uuidjs/uuid).
Bumps the npm_and_yarn group with 1 update in the /packages/user-operation-controller directory: [uuid](https://github.com/uuidjs/uuid).


Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

Updates `uuid` from 8.3.2 to 14.0.1
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v8.3.2...v14.0.1)

---
updated-dependencies:
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:development
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:development
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:development
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
- dependency-name: uuid
  dependency-version: 14.0.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/packages/accounts-controller/npm_and_yarn-4419c9509b branch from fccaf50 to bb3b765 Compare July 22, 2026 11:33
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 14, 2026
…ask#10225)

## Explanation

`expectConsistentDependenciesAndDevDependencies` requires every
workspace to use the same version range for a dependency, but it reports
through `dependency.error()`, which Yarn has no way to repair. So `yarn
constraints --fix` does nothing for it and a human has to hand edit
every manifest.

That mostly hurts on Dependabot PRs. Dependabot's security updates walk
manifests one at a time rather than treating the Yarn workspace as one
project, so they routinely bump a dependency in some packages and not
others. The result is a red build on a change nobody actually has to
think about. PR MetaMask#10147 is a good example: it bumped `uuid` in 22
packages, `uuid` is declared in 24, and the two stragglers fail
constraints. Same story on MetaMask#10157, MetaMask#10177 and MetaMask#9369, which is a large
part of why `uuid` alone accounts for 25 of our open Dependabot alerts.

This makes the rule fixable. When every conflicting range is plain
semver, the one permitting the highest minimum version wins and
`dependency.update()` aligns the rest, so `yarn constraints --fix`
(which `yarn lint:fix` already runs) repairs a partial bump on its own.

The previous docstring said it is impossible to compare NPM version
ranges, so let the user decide. That is still true in general, and the
fallback is unchanged: anything that is not a plain semver range, so
aliases like `npm:foo@^1.0.0`, protocols like `workspace:^`, or dist
tags, still produces the original "Pick one" error with the same
wording. The narrower claim here is only that `semver.minVersion()` is
comparable when every range has one, and `getHighestRange` bails out the
moment one doesn't.

Nothing else in the file changes. `ALLOWED_INCONSISTENT_DEPENDENCIES`
and its filter behave exactly as before.

## Verification

There is no test harness for `yarn.config.cjs`, so I verified against
the monorepo itself:

| Case | Result |
| --- | --- |
| Clean tree | exit 0, no manifests modified |
| `uuid` bumped in one package only | `--fix` aligned all 25 manifests,
re-check clean |
| One range set to `npm:uuid@^14.0.2` | errors with "Pick one", modifies
nothing |
| One package downgraded to `^8.0.0` | pulled back up to `^9.0.1`, not
propagated down |

The last one is the safety property worth calling out: a wrong range in
one manifest gets corrected upward rather than dragging every other
package backwards.

Worth knowing that `--fix` also reaches the root `package.json`, which
declares some of these dependencies too.

## Trade off

Aligning to the highest range is a real dependency change, not a
formatting fix. One bump in one package can move the rest onto a new
major, and `yarn lint:fix` will do that locally without asking. The
argument for it is that the constraint already requires these to move
together, so the only open question was who performs the alignment and
in which direction, and aligning downward would mean reverting security
fixes.

## References

Part of
[WPC-1161](https://consensyssoftware.atlassian.net/browse/WPC-1161).
This is the first step toward dropping the `@metamask/*` allowlist in
`.github/dependabot.yml` so we can bump everything, not just MetaMask
packages. The follow up is a workflow on bot PRs that runs `yarn
constraints --fix`, `yarn dedupe` and `yarn changelog:validate
--checkDeps --fix`, modelled on the one snaps already has in
`update-pull-request.yml`.

Related to MetaMask#10147, MetaMask#10157, MetaMask#10177, MetaMask#9369.

## Checklist

- [ ] I've updated the test suite for new or updated code as appropriate
(no harness exists for `yarn.config.cjs`, see Verification above)
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [ ] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
(no published package is touched)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them


[WPC-1161]:
https://consensyssoftware.atlassian.net/browse/WPC-1161?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 15, 2026
## Explanation

Dependabot's pull requests cannot merge on their own. Its security
updates walk manifests one at a time rather than treating the Yarn
workspace as one project, so a dependency ends up with different ranges
in different packages and `yarn constraints` fails. It also does not
deduplicate `yarn.lock` and does not write changelog entries. MetaMask#10147,
MetaMask#10157, MetaMask#10177 and MetaMask#9369 are all stuck on this.

This adds a workflow that repairs all three and pushes the result back.
It runs `yarn constraints --fix` with `ALIGN_DEPENDENCY_RANGES=true`
(the opt in from MetaMask#10228, whose only intended caller is this workflow),
reinstalls, deduplicates, then runs the changelog fixer that already
exists. Order matters: aligning ranges rewrites manifests but leaves
`yarn.lock` stale.

It also adds `@lavamoat/*` to the npm allowlist. Both that and
`@metamask/*` are already in `npmPreapprovedPackages`, so neither can
trip the Yarn age gate during the repair install. Note that `allow` only
governs version updates, so the workflow will also act on security pull
requests for other packages, which is where the constraints failures
come from.

## Notes

- `pull_request`, not `pull_request_target`. Dependabot runs get a read
only token and no secrets, so the push is authorised by the OIDC
exchange, the same way snaps does it.
- `opened` and `reopened` only. The job pushes to the pull request
branch, so `synchronize` would loop.
- `[dependabot skip]` on the commit, otherwise Dependabot rebases and
wipes the repair.

## Verification

The workflow cannot run until it is on the default branch. Checked
locally:

| Check | Result |
| --- | --- |
| `constraints --fix` leaves `yarn.lock` stale | confirmed, hence the
reinstall step |
| `ALIGN_DEPENDENCY_RANGES=true yarn constraints --fix` on a split range
| aligns all 25 manifests, exit 0 |
| Default, without the variable | unchanged, still errors |

## References

Follows MetaMask#10225 and MetaMask#10228. Part of WPC-1161. Pattern borrowed from
MetaMask/snaps `update-pull-request.yml`.

## Checklist

- [ ] I've updated the test suite for new or updated code as appropriate
(workflow and config only)
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [ ] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
(no published package is touched)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Changes are limited to Dependabot and CI workflow configuration; no
runtime application or auth logic is modified, though the workflow does
push commits to Dependabot branches via OIDC token exchange.
> 
> **Overview**
> Adds a GitHub Actions workflow that runs when **Dependabot** opens or
reopens a PR, then fixes the common reasons those PRs fail CI:
misaligned dependency ranges across the Yarn workspace, a stale or
duplicated **yarn.lock**, and missing changelog entries.
> 
> The job exchanges an OIDC token for write access (Dependabot’s default
token cannot push), runs **`yarn constraints --fix`** with
**`ALIGN_DEPENDENCY_RANGES=true`**, reinstalls with
**`--no-immutable`**, dedupes, and runs the existing
**`changelog:validate --fix`** flow before committing with
**`[dependabot skip]`** so Dependabot does not rebase away the repair.
It only listens to **`opened`** / **`reopened`** (not **`synchronize`**)
to avoid a push loop.
> 
> **Dependabot** config now allows version bumps for **`@lavamoat/*`**
npm packages, matching **`@metamask/*`**, so those updates can go
through the same repair path without Yarn age-gate issues during
install.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
c90706d. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
pull Bot pushed a commit to Reality2byte/core that referenced this pull request Sep 28, 2026
## Explanation

Renovate opens nothing for security advisories today. Every run logs:

```
WARN: Cannot access vulnerability alerts. Please ensure permissions have been granted. (repository=MetaMask/core)
```

It reads them from `GET /repos/{owner}/{repo}/dependabot/alerts`, so
this grants the token `vulnerability_alerts: read`. That is the
permission name GitHub uses when creating an installation access token,
described as "the level of permission to grant the access token to
manage Dependabot alerts". The UI calls the same thing "Dependabot
alerts".

No Renovate config is needed. The `vulnerabilityAlerts` defaults already
do the right thing here:

| Default | Effect |
| --- | --- |
| `dependencyDashboardApproval: false` | security fixes bypass our
approval gate |
| `minimumReleaseAge: null` | and the three day age gate |
| `prCreation: 'immediate'`, `prConcurrentLimit: 0` | not queued or
capped |
| `rangeStrategy: 'update-lockfile'` | lockfile only, so no changelog
entry is required |
| `commitMessageSuffix: '[SECURITY]'` | visible in the commit |

On whether Dependabot already covers this: there are currently 127 open
alerts, 126 of which have a patched version available, and the only live
Dependabot security pull requests are MetaMask#9369 from July and MetaMask#8849 from
May. Both are stuck, because Dependabot bumps one manifest at a time,
which splits the version range across workspaces and then it refuses to
rebase them.

> [!IMPORTANT]
> Depends on consensys-vertical-apps/token-exchange-service#190, which
allows the permission. It also tests something we cannot check from
outside: if the `metamask-ci` App does not itself hold Dependabot alerts
read, GitHub refuses to mint the token regardless of the policy, exactly
as it did for `statuses: write` in MetaMask#10316. The signature to watch for is
a 500 `Failed to create installation token from GitHub` at the `Get
access token` step. If that happens the App needs the permission
granted, and `osvVulnerabilityAlerts: true` is the fallback that needs
no permission at all.

Dependabot security updates stay on for now, so both bots may raise a
pull request for the same advisory. That overlap is the decision point
for whether Renovate replaces Dependabot here.

## References

Depends on consensys-vertical-apps/token-exchange-service#190. Follows
MetaMask#10495. Part of WPC-1161.

## Checklist

- [ ] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [ ] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Single CI workflow permission change; no application or Renovate
config edits in the diff, though rollout depends on the token exchange
service and GitHub App permissions.
> 
> **Overview**
> Renovate was failing to read GitHub Dependabot alerts because the
installation token from **Get access token** did not include
**`vulnerability_alerts: read`**. This PR adds that permission to the
token-exchange `permissions` block in `.github/workflows/renovate.yml`.
> 
> With access to `GET /repos/{owner}/{repo}/dependabot/alerts`, Renovate
can open pull requests for security advisories using its existing
**`vulnerabilityAlerts`** defaults (immediate PRs, lockfile updates,
**`[SECURITY]`** suffix), without a **`renovate.json`** change in this
diff.
> 
> **Note:** Token minting depends on **token-exchange-service** and the
**`metamask-ci`** app also holding Dependabot alerts read; otherwise the
workflow may fail at **Get access token**.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
9a08eb3. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

This branch was previously deployed

1 inactive (outdated) deployment
default-branch — f389732e Deployed Jul 2, 2026 by dependabot[bot] via Determine whether this PR is a release PR #1808
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants