MetaMask / core

This monorepo is a collection of packages used across multiple MetaMask clients
MIT License
293 stars 188 forks source link

Merge dependabot security PRs #4847

Open mikesposito opened 1 month ago

mikesposito commented 1 month ago

There are several PR related to security vulnerabilities from dependabot in repos owned by Wallet Framework (for full list, see https://github.com/MetaMask/MetaMask-planning/issues/3540).

In some cases, we should also prioritize release and update of affected packages in their consumers in order to mitigate the security issues, based on their EPSS value.

When to release the package

To get the EPSS value

@mikesposito

@mcmire

@MajorLift

@mcmire