Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: fix trezor audit #30850

Merged
merged 2 commits into from
Mar 7, 2025
Merged

chore: fix trezor audit #30850

merged 2 commits into from
Mar 7, 2025

Conversation

seaona
Copy link
Contributor

@seaona seaona commented Mar 7, 2025

Description

We temporarily ignore the '@trezor/connect-web audit failure to unblock ci, as upgrading to the new version breaks the webpack build.

└─ @trezor/connect-web
   ├─ ID: @trezor/connect-web (deprecation)
   ├─ Issue: This version is no longer supported
   ├─ Severity: moderate
   ├─ Vulnerable Versions: 9.4.7
   │ 
   ├─ Tree Versions
   │  └─ 9.4.7
   │ 
   └─ Dependents
      └─ metamask-crx@workspace:.

This issue is created in order to upgrade to the latest version and remove the entry from the ignore list.

Open in GitHub Codespaces

Related issues

Fixes:

Manual testing steps

  1. Check yarn audit gh action

Screenshots/Recordings

Before

Screenshot from 2025-03-07 09-35-05

After

Screenshot from 2025-03-07 09-40-00

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

Copy link
Contributor

github-actions bot commented Mar 7, 2025

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamaskbot metamaskbot added the team-qa QA team label Mar 7, 2025
FrederikBolding
FrederikBolding previously approved these changes Mar 7, 2025
@chloeYue
Copy link
Contributor

chloeYue commented Mar 7, 2025

Related ticket: #30851

Co-authored-by: Frederik Bolding <[email protected]>
@HowardBraham HowardBraham enabled auto-merge March 7, 2025 08:58
@HowardBraham HowardBraham added this pull request to the merge queue Mar 7, 2025
@metamaskbot
Copy link
Collaborator

Builds ready [5455ebb]
Page Load Metrics (1534 ± 40 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint23417561471296142
domContentLoaded1382172615058440
load1430176215348340
domInteractive237430115
backgroundConnect125930178
firstReactRender1565322110
getState55012136
initialActions00000
loadScripts1035129211136933
setupStore86616178
uiStartup15992062174310651
Bundle size diffs
  • background: 0 Bytes (0.00%)
  • ui: 0 Bytes (0.00%)
  • common: 0 Bytes (0.00%)

Merged via the queue into main with commit bb391c2 Mar 7, 2025
80 checks passed
@HowardBraham HowardBraham deleted the trezor-audit branch March 7, 2025 09:44
@github-actions github-actions bot locked and limited conversation to collaborators Mar 7, 2025
@metamaskbot metamaskbot added the release-12.15.0 Issue or pull request that will be included in release 12.15.0 label Mar 7, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
release-12.15.0 Issue or pull request that will be included in release 12.15.0 team-qa QA team
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants