Skip to content

Release/38.0.0 - #305

Merged
MoMannn merged 2 commits into
mainfrom
release/38.0.0
Sep 29, 2026
Merged

MoMannn merged 2 commits into
mainfrom
release/38.0.0

Conversation

@MoMannn

@MoMannn MoMannn commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

📝 Description

Releases delegation-deployments 2.1.0.

🔄 What Changed?

List the specific changes made:

🚀 Why?

Explain the motivation behind these changes:

🧪 How to Test?

Describe how to test these changes:

  • Manual testing steps:
  • Automated tests added/updated
  • All existing tests pass

⚠️ Breaking Changes

List any breaking changes:

  • No breaking changes
  • Breaking changes (describe below):

📋 Checklist

Check off completed items:

  • Code follows the project's coding standards
  • Self-review completed
  • Documentation updated (if needed)
  • Tests added/updated
  • Changelog updated (if needed)
  • All CI checks pass

🔗 Related Issues

Link to related issues:
Closes #
Related to #

📚 Additional Notes

Any additional information, concerns, or context:


Note

Low Risk
Additive release and dependency pin bumps; consumers pick up new chain deployment metadata without API or auth changes in this diff.

Overview
Release PR that cuts monorepo 38.0.0 and publishes @metamask/delegation-deployments 2.1.0, wiring dependents to the new deployment package.

Root and package changelogs are updated (including 2.1.0 noting Arc Mainnet chain deployment from #304). @metamask/smart-accounts-kit and @metamask/7715-permission-types bump @metamask/delegation-deployments from ^2.0.0 to ^2.1.0, with matching yarn.lock resolution cleanup for transitive deps.

No application logic changes appear in this diff—versioning, changelog links, and lockfile updates only.

Reviewed by Cursor Bugbot for commit 0d782b4. Bugbot is set up for automated code reviews on this repo. Configure here.

@MoMannn
MoMannn requested a review from a team as a code owner September 28, 2026 06:47
@socket-security

socket-security Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Warning

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Warn Low
Potential code anomaly (AI signal): npm @tybys/wasm-util is 65.0% likely to have a medium risk anomaly

Notes: No direct evidence of intentional malware, obfuscation-based payload hiding, or covert network exfiltration in this fragment. The primary security concerns are design/capability risks typical of WASI runtimes: executing externally provided WASM, high-impact filesystem access via injected fs/preopens, environment-variable exposure to the guest, possible host termination via proc_exit, and non-malicious operational risks (busy-wait timer handling and window.prompt stdin blocking; weak RNG fallback to Math.random). Risk is therefore configuration- and trust-boundary-dependent rather than a confirmed implant.

Confidence: 0.65

Severity: 0.52

From: package.json → npm/eslint-plugin-import-x@4.16.1 → npm/@tybys/wasm-util@0.10.3

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tybys/wasm-util@0.10.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Ignoring alerts on:

  • @emnapi/core@1.11.1

View full report

@MoMannn

MoMannn commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

@SocketSecurity ignore npm/@emnapi/core@1.11.1

@V00D00-child V00D00-child left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@MoMannn
MoMannn merged commit 555dd20 into main Sep 29, 2026
16 checks passed
@MoMannn
MoMannn deleted the release/38.0.0 branch September 29, 2026 07:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants