Skip to content

chore!: Drop Node 18 and 20 - #9976

Merged
Mrtenz merged 6 commits into
mainfrom
mrtenz/drop-node-20
Sep 9, 2026
Merged

Mrtenz merged 6 commits into
mainfrom
mrtenz/drop-node-20

Conversation

@Mrtenz

@Mrtenz Mrtenz commented Aug 26, 2026 •

Copy link
Copy Markdown
Member

Node 18 and 20 are EOL, we should not support them anymore. This PR makes a breaking change to every single package in the monorepo. This also reduces the number of jobs we need to run in CI.

This change was originally merged into the esm feature branch, but using a stacked pull request seems cleaner here.


Note

Medium Risk
Semver-breaking engines change affects every package consumer and downstream apps still on Node 18/20; test-only crypto polyfill removal assumes CI/dev on Node 22+.

Overview
Breaking: The monorepo no longer supports Node 18 or 20. Root and every package’s engines.node is now ^22.14.0 || ^24, with matching BREAKING changelog entries across published packages.

CI runs fewer jobs: the prepare matrix and per-package test jobs only use 22.x and 24.x (the old test-18 / test-20 jobs are removed), and wallet-cli e2e drops Node 20 from its matrix. @types/node is bumped from 16.x to ^22.13.14 at the root and in packages that depended on the old types; yarn.config.cjs enforces the new engines string uniformly (including @metamask/wallet-cli, which previously allowed >=20).

Because Node 22 exposes Web Crypto globally, custom Jest environments and test beforeAll hooks that polyfilled globalThis.crypto are deleted or trimmed in packages such as keyring-controller, passkey-controller, seedless-onboarding-controller, money-account-upgrade-controller, and wallet tests. Related jest-environment-node devDependencies are dropped where they existed only for those environments.

Reviewed by Cursor Bugbot for commit f27e444. Bugbot is set up for automated code reviews on this repo. Configure here.

@Mrtenz Mrtenz changed the title chore!: Drop Node 18 and 20 (#9168) chore!: Drop Node 18 and 20 Aug 26, 2026
Comment thread package.json
@Mrtenz
Mrtenz force-pushed the mrtenz/drop-node-20 branch 2 times, most recently from 00f0bc1 to beac0dd Compare August 26, 2026 18:49
@socket-security

socket-security Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​types/​node@​16.18.106 ⏵ 22.20.11001008196100

View full report

@Mrtenz
Mrtenz force-pushed the mrtenz/drop-node-20 branch from beac0dd to 8dabedc Compare August 27, 2026 08:50
@Mrtenz
Mrtenz marked this pull request as ready for review August 27, 2026 11:54
@Mrtenz
Mrtenz requested review from a team as code owners August 27, 2026 11:54
@Mrtenz
Mrtenz temporarily deployed to default-branch August 27, 2026 11:54 — with GitHub Actions Inactive
@Mrtenz
Mrtenz requested review from a team as code owners August 27, 2026 11:54
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 5, 2026
Follows from the runtime floor moving to Node 22. Core makes the same bump
in the same PR as its Node drop (MetaMask/core#9976), rather than alongside
the TypeScript change, since the types track the supported runtime.
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 8, 2026
Mirrors MetaMask/core#9976, the bottom of core's foundational stack.

BREAKING: the supported range moves from ^18.18 || ^20.14 || >=22 to
^22.14.0 || ^24, the same range core adopts. The CI matrix drops to 22 and
24, and constraints.pro is updated to match.

This lands before the TypeScript and target/lib changes on purpose. Core
sequenced its stack Node, then ESM, then TypeScript, then target/lib, and
that order is a dependency chain rather than an arbitrary grouping: raising
the runtime floor first is what justifies each step above it, and emitting
a higher target is only defensible once the floor guarantees it.
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 8, 2026
Follows from the runtime floor moving to Node 22. Core makes the same bump
in the same PR as its Node drop (MetaMask/core#9976), rather than alongside
the TypeScript change, since the types track the supported runtime.
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 8, 2026
Mirrors MetaMask/core#9976, the bottom of core's foundational stack.

BREAKING: the supported range moves from ^18.18 || ^20.14 || >=22 to
^22.14.0 || ^24, the same range core adopts. The CI matrix drops to 22 and
24, and constraints.pro is updated to match.

This lands before the TypeScript and target/lib changes on purpose. Core
sequenced its stack Node, then ESM, then TypeScript, then target/lib, and
that order is a dependency chain rather than an arbitrary grouping: raising
the runtime floor first is what justifies each step above it, and emitting
a higher target is only defensible once the floor guarantees it.
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 8, 2026
Follows from the runtime floor moving to Node 22. Core makes the same bump
in the same PR as its Node drop (MetaMask/core#9976), rather than alongside
the TypeScript change, since the types track the supported runtime.
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 9, 2026
Mirrors MetaMask/core#9976, the bottom of core's foundational stack.

BREAKING: the supported range moves from ^18.18 || ^20.14 || >=22 to
^22.14.0 || ^24, the same range core adopts. The CI matrix drops to 22 and
24, and constraints.pro is updated to match.

This lands before the TypeScript and target/lib changes on purpose. Core
sequenced its stack Node, then ESM, then TypeScript, then target/lib, and
that order is a dependency chain rather than an arbitrary grouping: raising
the runtime floor first is what justifies each step above it, and emitting
a higher target is only defensible once the floor guarantees it.
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 9, 2026
Follows from the runtime floor moving to Node 22. Core makes the same bump
in the same PR as its Node drop (MetaMask/core#9976), rather than alongside
the TypeScript change, since the types track the supported runtime.
GuillaumeRx added a commit to MetaMask/metamask-monorepo-template that referenced this pull request Sep 9, 2026
Node 20 is also end of life. This matches MetaMask/core#9976, which drops
Node 18 and 20 from the monorepo.

- `engines.node` becomes `^22.14.0 || ^24`.
- `@types/node` moves from `^16.18.54` to `^22.13.14`.
- The test matrix runs Node 22 and 24.

BREAKING: Packages generated from this template no longer support Node 20.
GuillaumeRx added a commit to MetaMask/metamask-monorepo-template that referenced this pull request Sep 9, 2026
Node 20 is also end of life. This matches MetaMask/core#9976, which drops
Node 18 and 20 from the monorepo.

- `engines.node` becomes `^22.14.0 || ^24`.
- `@types/node` moves from `^16.18.54` to `^22.13.14`.
- The test matrix runs Node 22 and 24.

BREAKING: Packages generated from this template no longer support Node 20.
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 9, 2026
Mirrors MetaMask/core#9976, the bottom of core's foundational stack.

BREAKING: the supported range moves from ^18.18 || ^20.14 || >=22 to
^22.14.0 || ^24, the same range core adopts. The CI matrix drops to 22 and
24, and constraints.pro is updated to match.

This lands before the TypeScript and target/lib changes on purpose. Core
sequenced its stack Node, then ESM, then TypeScript, then target/lib, and
that order is a dependency chain rather than an arbitrary grouping: raising
the runtime floor first is what justifies each step above it, and emitting
a higher target is only defensible once the floor guarantees it.
cryptodev-2s added a commit to MetaMask/utils that referenced this pull request Sep 9, 2026
Follows from the runtime floor moving to Node 22. Core makes the same bump
in the same PR as its Node drop (MetaMask/core#9976), rather than alongside
the TypeScript change, since the types track the supported runtime.
mcmire
mcmire previously approved these changes Sep 9, 2026

@mcmire mcmire left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

FrederikBolding and others added 6 commits September 9, 2026 19:13
Node 18 and 20 are EOL, we should not support them anymore. This PR
makes a breaking change to every single package in the monorepo. This
also reduces the number of jobs we need to run in CI.

<!--
Are there any issues that this pull request is tied to?
Are there other links that reviewers should consult to understand these
changes better?
Are there client or consumer pull requests to adopt any breaking
changes?

For example:

* Fixes #12345
* Related to #67890
-->

- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or
updated code as appropriate
- [x] I've communicated my changes to consumers by [updating changelogs
for packages I've
changed](https://github.com/MetaMask/core/tree/main/docs/processes/updating-changelogs.md)
- [ ] I've introduced [breaking
changes](https://github.com/MetaMask/core/tree/main/docs/processes/breaking-changes.md)
in this PR and have prepared draft pull requests for clients and
consumer packages to resolve them

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **High Risk**
> Semver-breaking platform change across all packages: consumers on Node
18/20 must upgrade before adopting new releases. CI no longer catches
regressions on those versions.
>
> **Overview**
> **BREAKING:** The monorepo now requires **Node.js `^22.14.0 || ^24`**
everywhere. Root and every workspace `package.json` `engines.node` moves
off `^18.18 || >=20`, and `yarn.config.cjs` enforces the same range
(including `@metamask/wallet-cli`, which previously allowed `>=20`).
>
> CI in `lint-build-test.yml` stops testing on **18.x** and **20.x**:
the prepare matrix and per-package test jobs run only **22.x** and
**24.x**, with `test-18` / `test-20` removed and `test-24` added. Each
package’s **Unreleased** changelog records the Node bump.
>
> Because Node 22 exposes **Web Crypto** globally, custom Jest setups
that assigned `crypto.webcrypto` are removed (`keyring-controller`,
`passkey-controller`, `seedless-onboarding-controller`,
`money-account-upgrade-controller`, and partial cleanup in
`notification-services-controller` / `profile-sync-controller`). Related
`jest-environment-node` devDependencies and `Wallet` / encryptor test
`beforeAll` polyfills go away. `platform-api-docs` drops the comment
justifying `fs.cp` on older Node versions.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
50b2f4c. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: Maarten Zuidhoorn <maarten@zuidhoorn.com>
Fix misplaced changelog entries

Add missing changelog entries
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.