Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump snaps packages and remove -flask versions #20984

Merged
merged 10 commits into from
Sep 25, 2023
Merged

Conversation

FrederikBolding
Copy link
Member

Description

Bump snaps packages to latest. The latest packages include both the code previously contained in the -flask packages and the stable code. This lets us deduplicate the snaps packages in use.

@FrederikBolding FrederikBolding added the team-snaps DEPRECATED: Use "team-snaps-platform" or "team-snaps-ecosystem" instead label Sep 21, 2023
@FrederikBolding
Copy link
Member Author

@metamaskbot update-policies

@metamaskbot
Copy link
Collaborator

Policies updated

@FrederikBolding FrederikBolding force-pushed the fb/bump-snaps branch 2 times, most recently from 703a5ef to c21f4b6 Compare September 22, 2023 11:45
@FrederikBolding FrederikBolding marked this pull request as ready for review September 22, 2023 12:21
@FrederikBolding FrederikBolding requested review from a team and kumavis as code owners September 22, 2023 12:21
Comment on lines +29 to +31
// Move to below fence once implemented
'endowment:name-lookup':
'This permission is still in development and therefore not available.',
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why can't we move this now?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IMO it should be disabled until we add an actual integration for it

@metamaskbot
Copy link
Collaborator

Builds ready [197fdb4]
Page Load Metrics (1682 ± 69 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint1091881552412
domContentLoaded14391940168214369
load14391940168214369
domInteractive14391940168214369
Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 2.49 KiB (0.07%)
  • ui: -7.96 KiB (-0.10%)
  • common: 16.01 KiB (0.35%)

@codecov
Copy link

codecov bot commented Sep 22, 2023

Codecov Report

Patch and project coverage have no change.

Comparison is base (25a054d) 68.33% compared to head (dd677d8) 68.34%.
Report is 1 commits behind head on develop.

Additional details and impacted files
@@           Coverage Diff            @@
##           develop   #20984   +/-   ##
========================================
  Coverage    68.33%   68.34%           
========================================
  Files         1007     1007           
  Lines        40254    40254           
  Branches     10761    10761           
========================================
+ Hits         27507    27508    +1     
+ Misses       12747    12746    -1     
Files Changed Coverage Δ
shared/constants/snaps/permissions.ts 100.00% <ø> (ø)

... and 1 file with indirect coverage changes

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@socket-security
Copy link

New, updated, and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Packages Version New capabilities Transitives Size Publisher
@metamask/snaps-controllers 2.0.0 eval, network, shell +16 7.89 MB metamaskbot
@metamask/snaps-utils 2.0.0 filesystem, shell +7 898 kB metamaskbot
@metamask/snaps-ui 2.0.0 None +0 59.2 kB metamaskbot
@metamask/rpc-methods 2.0.0 None +8 1.36 MB metamaskbot
@metamask/post-message-stream 7.0.0 None +0 75.9 kB gudahtt
@metamask/providers 10.2.1...12.0.0 None +0/-9 187 kB metamaskbot

🚮 Removed packages: [email protected]

@socket-security
Copy link

socket-security bot commented Sep 25, 2023

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

Ignoring: [email protected], @metamask/[email protected], @metamask/[email protected], @metamask/[email protected]

Next steps

Take a deeper look at the dependency

Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support [AT] socket [DOT] dev.

Remove the package

If you happen to install a dependency that Socket reports as Known Malware you should immediately remove it and select a different dependency. For other alert types, you may may wish to investigate alternative packages or consider if there are other ways to mitigate the specific risk posed by the dependency.

Mark a package as acceptable risk

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore [email protected] bar@* or ignore all packages with @SocketSecurity ignore-all

@metamaskbot
Copy link
Collaborator

Builds ready [fea7364]
Page Load Metrics (1587 ± 40 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint83142101178
domContentLoaded7413597178
load1462172915878340
domInteractive7413597178
Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 2.49 KiB (0.07%)
  • ui: -7.96 KiB (-0.10%)
  • common: 16.01 KiB (0.35%)

@metamaskbot
Copy link
Collaborator

Builds ready [72c2872]
Page Load Metrics (1492 ± 29 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint791189194
domContentLoaded7211286105
load1412163414926129
domInteractive7211286105
Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 2.49 KiB (0.07%)
  • ui: -7.96 KiB (-0.10%)
  • common: 16.01 KiB (0.35%)

@FrederikBolding
Copy link
Member Author

@SocketSecurity ignore [email protected]

NPM employee.

@SocketSecurity ignore @metamask/[email protected]
@SocketSecurity ignore @metamask/[email protected]
@SocketSecurity ignore @metamask/[email protected]

Ours.

@metamaskbot
Copy link
Collaborator

Builds ready [dd677d8]
Page Load Metrics (2063 ± 79 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint1031841322311
domContentLoaded881811222713
load17322415206316579
domInteractive881811222713
Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 2.49 KiB (0.07%)
  • ui: -7.96 KiB (-0.10%)
  • common: 16.01 KiB (0.35%)

@FrederikBolding FrederikBolding merged commit ccb554a into develop Sep 25, 2023
9 checks passed
@FrederikBolding FrederikBolding deleted the fb/bump-snaps branch September 25, 2023 14:33
@github-actions github-actions bot locked and limited conversation to collaborators Sep 25, 2023
@metamaskbot metamaskbot added the release-11.3.0 Issue or pull request that will be included in release 11.3.0 label Sep 25, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
release-11.3.0 Issue or pull request that will be included in release 11.3.0 team-snaps DEPRECATED: Use "team-snaps-platform" or "team-snaps-ecosystem" instead
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants