MetaMask / iframe-execution-environment

https://metamask.github.io/iframe-execution-environment/
https://metamask.github.io/iframe-execution-environment
8 stars 13 forks source link

Bump @metamask/snaps-execution-environments from 0.33.1-flask.1 to 0.34.0-flask.1 #171

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps @metamask/snaps-execution-environments from 0.33.1-flask.1 to 0.34.0-flask.1.

Release notes

Sourced from @​metamask/snaps-execution-environments's releases.

0.34.0-flask.1

@​metamask/create-snap

Added

  • Initial release (#1268)

examples

Changed

  • No changes this release.

@​metamask/multichain-provider

Changed

  • No changes this release.

@​metamask/rpc-methods

Changed

  • BREAKING: Rename targetKey to targetName as part of updating PermissionController (#1450)

@​metamask/snaps-browserify-plugin

Changed

  • No changes this release.

@​metamask/snaps-cli

Removed

  • BREAKING: Remove init command (#1268)

@​metamask/snaps-controllers

Changed

  • BREAKING: Rename targetKey to targetName as part of updating PermissionController (#1450)
  • Add SVG validation (#1401)
  • Export permissions specification builders (#1432)
  • Export processSnapPermissions (#1402)

@​metamask/snaps-execution-environments

Changed

@​metamask/snaps-rollup-plugin

Changed

  • No changes this release.

@​metamask/snaps-simulator

... (truncated)

Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
socket-security[bot] commented 1 year ago

New dependency changes detected. Learn more about Socket for GitHub ↗︎


👍 No new dependency issues detected in pull request

Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

Ignoring: fast-xml-parser@4.2.2, strnum@1.0.5

Pull request alert summary
Issue Status
Critical CVE ✅ 0 issues
CVE ✅ 0 issues
Mild CVE ✅ 0 issues
Install scripts ✅ 0 issues
Native code ✅ 0 issues
Bin script confusion ✅ 0 issues
Bin script shell injection ✅ 0 issues
Filesystem access ✅ 0 issues
Network access ✅ 0 issues
Shell access ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
GitHub dependency ✅ 0 issues
No bug tracker ✅ 0 issues
No contributors or author data ✅ 0 issues
No README ✅ 0 issues
Deprecated ✅ 0 issues
New author ✅ 0 issues
Unstable ownership ✅ 0 issues
Non-existent author ✅ 0 issues
Unmaintained ✅ 0 issues
Unpublished package ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues
AI detected security risk ✅ 0 issues
AI warning ✅ 0 issues

📊 Modified Dependency Overview:

⬆️ Updated Package Version Diff Added Capability Access +/- Transitive Count Publisher
@metamask/snaps-execution-environments@0.34.0-flask.1 0.33.1-flask.1...0.34.0-flask.1 None +10/-7 metamaskbot
FrederikBolding commented 1 year ago

@SocketSecurity ignore fast-xml-parser@4.2.2 @SocketSecurity ignore strnum@1.0.5