Skip to content

chore(deps): bump @metamask/snaps-controllers from 19.0.1 to 21.1.1 - #10748

Open
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1
Open

dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps @metamask/snaps-controllers from 19.0.1 to 21.1.1.

Commits
  • f42b562 release: 167.0.0 (#4129)
  • 3737adf fix: Check caveat in invokeKeyring (#4128)
  • 5ee78bd fix: Mirror setTimeout endowment in setInterval (#4127)
  • 9127573 feat: allow for multiple keys in snap_getState (#4125)
  • 7e3d201 fix: Validate date after duration offset (#4124)
  • 2c8a299 chore: Bump lavamoat from 11.1.4 to 11.1.5 (#4114)
  • c5d436c chore(license): update email in license (#4117)
  • d968720 chore: Bump @​metamask/auto-changelog from 6.2.0 to 6.2.1 (#4103)
  • 196ef37 chore: Bump @​metamask/create-release-branch from 4.2.1 to 4.2.2 (#4109)
  • 17c2628 chore: Bump @​metamask/safe-event-emitter from 3.1.2 to 3.1.3 (#4108)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​metamask/snaps-controllers since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 8, 2026
@dependabot
dependabot Bot requested review from a team as code owners October 8, 2026 12:50
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 8, 2026
@dependabot
dependabot Bot deployed to dependabot October 8, 2026 12:50 Active
@dependabot
dependabot Bot deployed to default-branch October 8, 2026 12:51 Active
@socket-security

socket-security Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​metamask/​snaps-controllers@​21.1.183100769750
Updated@​metamask/​snaps-utils@​12.2.1 ⏵ 12.6.19810076 +197 +3100

View full report

@socket-security

socket-security Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Caution

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Priority Alert  (click "▶" to expand/collapse) Action
Medium priority
Publisher changed: npm @endo/immutable-arraybuffer is now published by boneskull

Author: boneskull

From: packages/account-tree-controller/package.json → npm/@metamask/snaps-utils@12.6.1 → npm/@endo/immutable-arraybuffer@2.0.0

ℹ Read more on: This package | This alert | What is unstable ownership?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Try to reduce the number of authors you depend on to reduce the risk to malicious actors gaining access to your supply chain. Packages should remove inactive collaborators with publishing rights from packages on npm.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@endo/immutable-arraybuffer@2.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential security risk (AI signal): npm ses is 72.0% likely risky

Notes: This module is a high-impact evaluator/engine component that dynamically compiles code and executes caller-provided strings via eval(arguments[0]) within multiple nested with scope wrappers. There are no obvious explicit malicious payloads (exfiltration/network/persistence) in this file, but it provides a powerful arbitrary code execution mechanism whenever untrusted input reaches the evaluated string or the generated scope bindings. Strong input trust boundaries and sandboxing/permission controls are required for safe use.

Confidence: 0.72

Severity: 0.78

From: packages/account-tree-controller/package.json → npm/@metamask/snaps-utils@12.6.1 → npm/ses@2.3.0

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ses@2.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Publisher changed: npm @endo/immutable-arraybuffer is now published by boneskull instead of kriskowal

New Author: boneskull

Previous Author: kriskowal

From: packages/account-tree-controller/package.json → npm/@metamask/snaps-utils@12.6.1 → npm/@endo/immutable-arraybuffer@2.0.0

ℹ Read more on: This package | This alert | What is new author?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Scrutinize new collaborator additions to packages because they now have the ability to publish code into your dependency tree. Packages should avoid frequent or unnecessary additions or changes to publishing rights.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@endo/immutable-arraybuffer@2.0.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm ses is 65.0% likely to have a medium risk anomaly

Notes: This module implements a Function-constructor-like capability that converts caller-provided runtime arguments into JavaScript source code (parameters and body) and then compiles/executes it through an injected evaluator. No explicit exfiltration or system-interaction behavior is present in the fragment, but the untrusted-input-to-dynamic-evaluation pathways are inherently high risk if inputs are not strictly controlled and if the evaluator does not enforce strong isolation and policy.

Confidence: 0.65

Severity: 0.62

From: packages/account-tree-controller/package.json → npm/@metamask/snaps-utils@12.6.1 → npm/ses@2.3.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ses@2.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from 7f4204a to 7880f61 Compare October 8, 2026 15:45
@dependabot
dependabot Bot deployed to dependabot October 8, 2026 15:45 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from f834983 to f2cd2ae Compare October 8, 2026 18:32
@dependabot
dependabot Bot deployed to dependabot October 8, 2026 18:32 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from 929b403 to a539500 Compare October 8, 2026 19:32
@dependabot
dependabot Bot deployed to dependabot October 8, 2026 19:32 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from a7866fb to f3e03a9 Compare October 8, 2026 19:46
@dependabot
dependabot Bot deployed to dependabot October 8, 2026 19:47 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from 99ec00a to 7bc5d44 Compare October 8, 2026 20:48
@dependabot
dependabot Bot deployed to dependabot October 8, 2026 20:49 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from 6483cb8 to e542501 Compare October 9, 2026 08:15
@dependabot
dependabot Bot deployed to dependabot October 9, 2026 08:16 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from bdaa21a to ebe5547 Compare October 9, 2026 12:16
@dependabot
dependabot Bot deployed to dependabot October 9, 2026 12:16 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from efb5876 to 0098759 Compare October 9, 2026 13:43
@dependabot
dependabot Bot deployed to dependabot October 9, 2026 13:43 Active
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from 6a90b6d to b0c8bb0 Compare October 9, 2026 14:12
@dependabot
dependabot Bot deployed to dependabot October 9, 2026 14:12 Active
Bumps [@metamask/snaps-controllers](https://github.com/MetaMask/snaps) from 19.0.1 to 21.1.1.
- [Release notes](https://github.com/MetaMask/snaps/releases)
- [Commits](https://github.com/MetaMask/snaps/compare/@metamask/snaps-controllers@19.0.1...@metamask/snaps-controllers@21.1.1)

---
updated-dependencies:
- dependency-name: "@metamask/snaps-controllers"
  dependency-version: 21.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/metamask/snaps-controllers-21.1.1 branch from a7a503d to d43e3e9 Compare October 10, 2026 11:26
@dependabot
dependabot Bot deployed to dependabot October 10, 2026 11:26 Active

This branch was successfully deployed

2 active (outdated) deployments
dependabot — d43e3e99 Deployed Oct 10, 2026 by dependabot[bot] via Repair constraints, lockfile and changelogs #2051
default-branch — 065218fb Deployed Oct 8, 2026 by dependabot[bot] via Determine whether this PR is a release PR #5265
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants