Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[draft] bump version #28830

Closed
wants to merge 3 commits into from
Closed

[draft] bump version #28830

wants to merge 3 commits into from

Conversation

weizman
Copy link
Member

@weizman weizman commented Dec 2, 2024

No description provided.

@metamaskbot metamaskbot added team-lavamoat INVALID-PR-TEMPLATE PR's body doesn't match template labels Dec 2, 2024
Copy link

socket-security bot commented Dec 2, 2024

New dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@metamask/[email protected] environment 0 639 kB metamaskbot

View full report↗︎

@weizman
Copy link
Member Author

weizman commented Dec 2, 2024

@metamaskbot update-policies

@metamaskbot
Copy link
Collaborator

Policies updated.
👀 Please review the diff for suspicious new powers.

🧠 Learn how: https://lavamoat.github.io/guides/policy-diff/#what-to-look-for-when-reviewing-a-policy-diff

@weizman
Copy link
Member Author

weizman commented Dec 2, 2024

What new powers (globals and builtins) do you see? Why should the package be allowed to use these new powers? Explain if possible

I see eth-block-tracker use fetch. it used fetch before via the node-fetch polyfill

What new packages do you see? Did you intend to introduce them? If you didn’t, which package did? (can you see them in packages field in policy of any other package that you updated or introduced?)

@metamask/network-controller>@metamask/eth-block-tracker - it’s a dependency of an update I made to network-controller

passing it on to @...security-liaisons

Copy link
Contributor

@naugtur naugtur left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@weizman policy change ok

@naugtur naugtur closed this Dec 2, 2024
@github-actions github-actions bot locked and limited conversation to collaborators Dec 2, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
INVALID-PR-TEMPLATE PR's body doesn't match template team-lavamoat
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants