Skip to content

chore: bump/resolve some transitive deps (dependabots) - #646

Open
ccharly wants to merge 1 commit into
mainfrom
cc/chore/bump-transitive-deps
Open

ccharly wants to merge 1 commit into
mainfrom
cc/chore/bump-transitive-deps

Conversation

@ccharly

@ccharly ccharly commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumping or using a resolutions for some transitive deps.

Comment thread package.json
"eslint-plugin-import-x": "<=4.6.1",
"napi-postinstall": "npm:npm-empty-package@^1.0.0",
"protobufjs@7.4.0": "^7.6.5",
"tar": "^7.5.16",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Went for the same resolutions than the extension for this one.

@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Warning

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Potential code anomaly (AI signal): npm @protobufjs/codegen is 72.0% likely to have a medium risk anomaly

Notes: No direct malicious behavior (e.g., exfiltration, persistence, or credential theft) is evident in this module. However, it is inherently a dynamic code execution utility: it constructs JavaScript source from caller-influenced templates/body and scope, then executes it using the Function constructor. If any upstream input can influence templates or accumulated body, this module can enable code injection/RCE in the caller’s context. Treat as high-risk when used with untrusted data; otherwise it functions as a formatter/codegen helper.

Confidence: 0.72

Severity: 0.52

From: packages/keyring-eth-trezor/package.json → npm/@trezor/connect-web@9.6.1 → npm/@protobufjs/codegen@2.0.5

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@protobufjs/codegen@2.0.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm protobufjs is 61.0% likely to have a medium risk anomaly

Notes: The analyzed code segment is a standard RPC service wrapper (protobufjs style) with conventional input validation, encoding/decoding, event emission, and end handling. No malicious behavior is evident, and there are no observable security vulnerabilities beyond ordinary library-level error handling. It does not exhibit data exfiltration, backdoors, or other anti-security patterns.

Confidence: 0.61

Severity: 0.55

From: packages/keyring-eth-trezor/package.json → npm/@trezor/connect-web@9.6.1 → npm/protobufjs@7.6.6

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/protobufjs@7.6.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm readable-stream is 68.0% likely to have a medium risk anomaly

Notes: The analyzed code is a standard, legitimate portion of the Node.js readable-stream implementation handling piping, flow control, and lifecycle events. There is no evidence of malicious behavior, data exfiltration, or unsafe operations within this fragment. It does not introduce backdoors or hidden communicative channels. Given the OpenVSX extension context, this fragment alone does not indicate supply chain risk.

Confidence: 0.68

Severity: 0.60

From: packages/keyring-eth-hd/package.json → npm/@metamask/bip39@4.0.0 → npm/@metamask/eth-hd-keyring@4.0.2 → npm/@trezor/connect-web@9.6.1 → npm/ethereumjs-tx@1.3.7 → npm/@keystonehq/bc-ur-registry-eth@0.19.1 → npm/hdkey@2.1.0 → npm/readable-stream@2.3.8

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/readable-stream@2.3.8. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm tar is 66.0% likely to have a medium risk anomaly

Notes: This module acts as a standard tar extraction wrapper using synchronous and asynchronous code paths. There is no evident malicious activity within this fragment. Security risk hinges on the behavior of the Unpack/UnpackSync implementation and how tar entries are written to disk (e.g., path traversal). No hardcoded secrets or network calls are present here. Recommend ensuring tar extraction handles path traversal and destination path sanitization in Unpack, and consider validating opt.file presence and type before streaming.

Confidence: 0.66

Severity: 0.56

From: package.json → npm/ts-jest@29.2.5 → npm/@lavamoat/allow-scripts@3.2.1 → npm/@ledgerhq/hw-app-eth@6.42.2 → npm/@metamask/eth-hd-keyring@4.0.2 → npm/@trezor/connect-web@9.6.1 → npm/ethereumjs-tx@1.3.7 → npm/hdkey@2.1.0 → npm/jest@29.7.0 → npm/tar@7.5.22

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/tar@7.5.22. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

Ignoring alerts on:

  • ripemd160@2.0.3
  • sha.js@2.4.12

View full report

Comment thread package.json
"eslint-import-resolver-typescript": "<=3.7.0",
"eslint-plugin-import-x": "<=4.6.1",
"napi-postinstall": "npm:npm-empty-package@^1.0.0",
"protobufjs@7.4.0": "^7.6.5",

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same as extension, but scoped to 7.X.Y to avoid impacting other majors.

@ccharly

ccharly commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor Author

@SocketSecurity ignore npm/ripemd160@2.0.3
@SocketSecurity ignore npm/sha.js@2.4.12

Both authors are co-maintainers of a lot of JS packages.

@ccharly
ccharly marked this pull request as ready for review September 30, 2026 16:54
@ccharly
ccharly requested a review from a team as a code owner September 30, 2026 16:54
@ccharly
ccharly enabled auto-merge September 30, 2026 17:07

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant