Skip to content

chore: bump @metamask/client-utils to ^2.0.2 - #45484

Merged
n3ps merged 3 commits into
mainfrom
chore/bump-client-utils-2.0.2
Aug 13, 2026
Merged

chore: bump @metamask/client-utils to ^2.0.2#45484
n3ps merged 3 commits into
mainfrom
chore/bump-client-utils-2.0.2

Conversation

@n3ps

@n3ps n3ps commented Aug 12, 2026

Copy link
Copy Markdown
Contributor

Description

Bump @metamask/client-utils to ^2.0.2 (MetaMask/core#9846).

Includes the native zero-address CAIP fallback for chains without slip44 (MetaMask/core#9833).

Changelog

CHANGELOG entry: null

Related issues

Related: MetaMask/core#9846
Related: MetaMask/core#9833
Related: #45239

Manual testing steps

  1. N/A (dependency bump)

Screenshots/Recordings

Before

N/A

After

N/A

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

Made with Cursor

@github-actions

Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@metamask-ci metamask-ci Bot added the team-core-extension-ux Core Extension UX team label Aug 12, 2026
@socket-security

socket-security Bot commented Aug 12, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​metamask/​client-utils@​2.0.0 ⏵ 2.0.2100 +2310079 +198 +1100
Updated@​metamask/​transaction-controller@​69.5.1 ⏵ 69.5.298 +110081 +1100 +1100

View full report

@socket-security

socket-security Bot commented Aug 12, 2026

Copy link
Copy Markdown

Warning

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Warn Low
Potential code anomaly (AI signal): npm @metamask/transaction-controller is 75.0% likely to have a medium risk anomaly

Notes: The code performs straightforward signature verification using ethers.js, returning true when the recovered signer matches the provided publicKey. While generally safe, the silent catch and potential mismatch between data formatting and signing process should be addressed to avoid silent failures. Overall, a benign utility with moderate input-format sensitivity.

Confidence: 0.75

Severity: 0.50

From: package.jsonnpm/@metamask/transaction-controller@69.5.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@metamask/transaction-controller@69.5.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@n3ps
n3ps marked this pull request as ready for review August 13, 2026 17:09
@n3ps
n3ps enabled auto-merge August 13, 2026 17:09
@n3ps
n3ps deployed to pr-comment August 13, 2026 17:09 — with GitHub Actions Active
client-utils 2.0.2 pulled in a nested 69.5.2 copy, which broke LavaMoat
and every e2e job. Hoist it onto the existing 69.x range.

Co-authored-by: Cursor <cursoragent@cursor.com>
@n3ps
n3ps deployed to pr-comment August 13, 2026 17:11 — with GitHub Actions Active
@sonarqubecloud

Copy link
Copy Markdown

@n3ps
n3ps deployed to pr-comment August 13, 2026 17:41 — with GitHub Actions Active
@metamask-ci

metamask-ci Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor
Builds ready [3e67778]
⚡ Performance Benchmarks (Total: 🟢 10 pass · 🟡 11 warn · 🔴 3 fail)

Baseline (latest main): 171ed20 | Date: 7/28/2026 | Pipeline: 31724486840 | Baseline logs

Metricschrome-webpackfirefox-webpack
loadNewAccount
[Sentry log · main/release]
🔴 load_new_account(p95) [CI log]🔴 load_new_account(p95) [CI log]
onboardingNewWallet
[Sentry log · main/release]
🟢 [CI log]🔴 [CI log]

Regressions (🔴 3 failures)

Interaction Benchmarks · Samples: 5 🔴 2
Benchmarkchrome-webpackfirefox-webpack
loadNewAccount
[Sentry log · main/release]
🔴 [CI log]
🔴 load_new_account
🔴 [CI log]
🔴 load_new_account
confirmTx
[Sentry log · main/release]
🟡 [CI log]🟢 [CI log]
bridgeUserActions
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • loadNewAccount/load_new_account: +190%
  • loadNewAccount/total: +190%
  • confirmTx/longTaskTotalDuration: -14%
  • confirmTx/longTaskMaxDuration: +39%
  • confirmTx/tbt: -25%
  • confirmTx/lcp: +12%
  • bridgeUserActions/bridge_load_page: +19%
  • bridgeUserActions/bridge_load_asset_picker: +147%
  • bridgeUserActions/longTaskCount: +11%
  • bridgeUserActions/longTaskMaxDuration: -13%
  • bridgeUserActions/tbt: -41%
  • bridgeUserActions/total: +15%
  • bridgeUserActions/inp: +31%
  • loadNewAccount/load_new_account: +191%
  • loadNewAccount/total: +191%
  • loadNewAccount/inp: -39%
  • loadNewAccount/fcp: -85%
  • loadNewAccount/lcp: +1001%
  • confirmTx/longTaskCount: -100%
  • confirmTx/longTaskTotalDuration: -100%
  • confirmTx/longTaskMaxDuration: -100%
  • confirmTx/tbt: -100%
  • confirmTx/inp: -39%
  • confirmTx/fcp: -54%
  • confirmTx/lcp: +967%
  • bridgeUserActions/bridge_load_page: +86%
  • bridgeUserActions/bridge_load_asset_picker: +54%
  • bridgeUserActions/bridge_search_token: -12%
  • bridgeUserActions/longTaskCount: -100%
  • bridgeUserActions/longTaskTotalDuration: -100%
  • bridgeUserActions/longTaskMaxDuration: -100%
  • bridgeUserActions/tbt: -100%
  • bridgeUserActions/inp: -38%
  • bridgeUserActions/fcp: -86%
  • bridgeUserActions/lcp: +1029%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 confirmTx/FCP: p75 1.8s
Startup Benchmarks · Samples: 100
Benchmarkchrome-webpackfirefox-webpack
startupStandardHome
[Sentry log · main/release]
🟢 [CI log]🟡 [CI log]
🟡 loadScripts
startupPowerUserHome
[Sentry log · main/release]
🟡 [CI log]

📈 Results compared to the previous 5 runs on main

  • startupStandardHome/firstReactRender: -99%
  • startupStandardHome/numNetworkReqs: -14%
  • startupStandardHome/backgroundConnect: +15%
  • startupStandardHome/firstReactRender: -98%
  • startupStandardHome/setupStore: +24%
  • startupStandardHome/numNetworkReqs: -13%
  • startupStandardHome/lcp: +11%
  • startupPowerUserHome/load: +18%
  • startupPowerUserHome/domContentLoaded: +18%
  • startupPowerUserHome/domInteractive: +18%
  • startupPowerUserHome/backgroundConnect: +44%
  • startupPowerUserHome/firstReactRender: -99%
  • startupPowerUserHome/initialActions: +11%
  • startupPowerUserHome/loadScripts: +15%
  • startupPowerUserHome/setupStore: -63%
  • startupPowerUserHome/numNetworkReqs: +10%
  • startupPowerUserHome/fcp: +18%
  • startupPowerUserHome/lcp: +25%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 startupPowerUserHome/LCP: p75 3.6s
User Journey Benchmarks · Samples: 5 · mock API 🔴 1
Benchmarkchrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🟡 [CI log]
🟡 total
🟢 [CI log]
onboardingNewWallet
[Sentry log · main/release]
🟢 [CI log]
🔴 total
🔴 [CI log]
🔴 total
assetDetails
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
solanaAssetDetails
[Sentry log · main/release]
🟡 [CI log]🟡 [CI log]
🟡 assetClickToPriceChart
importSrpHome
[Sentry log · main/release]
🟢 [CI log]🟡 [CI log]
sendTransactions
[Sentry log · main/release]
🟡 [CI log]🟡 [CI log]
swap
[Sentry log · main/release]
🟡 [CI log]
🟡 total
🟡 [CI log]

📈 Results compared to the previous 5 runs on main

  • onboardingImportWallet/srpButtonToSrpForm: +24%
  • onboardingImportWallet/confirmSrpToPwForm: +21%
  • onboardingImportWallet/pwFormToMetricsScreen: +12%
  • onboardingImportWallet/doneButtonToHomeScreen: -78%
  • onboardingImportWallet/openAccountMenuToAccountListLoaded: -92%
  • onboardingImportWallet/longTaskCount: -86%
  • onboardingImportWallet/longTaskTotalDuration: -94%
  • onboardingImportWallet/longTaskMaxDuration: -90%
  • onboardingImportWallet/tbt: -98%
  • onboardingImportWallet/total: -81%
  • onboardingNewWallet/skipBackupToMetricsScreen: -12%
  • onboardingNewWallet/agreeButtonToOnboardingSuccess: -13%
  • onboardingNewWallet/longTaskCount: -69%
  • onboardingNewWallet/longTaskTotalDuration: -74%
  • onboardingNewWallet/longTaskMaxDuration: -39%
  • onboardingNewWallet/tbt: -84%
  • solanaAssetDetails/assetClickToPriceChart: +328%
  • solanaAssetDetails/longTaskCount: -100%
  • solanaAssetDetails/longTaskTotalDuration: -100%
  • solanaAssetDetails/longTaskMaxDuration: -100%
  • solanaAssetDetails/tbt: -100%
  • solanaAssetDetails/total: +328%
  • solanaAssetDetails/fcp: +18%
  • solanaAssetDetails/cls: -59%
  • importSrpHome/loginToHomeScreen: -12%
  • importSrpHome/openAccountMenuAfterLogin: +11%
  • importSrpHome/longTaskCount: -23%
  • importSrpHome/longTaskTotalDuration: -32%
  • importSrpHome/longTaskMaxDuration: -24%
  • importSrpHome/tbt: -44%
  • importSrpHome/inp: -43%
  • importSrpHome/cls: +510%
  • sendTransactions/openSendPageFromHome: +192%
  • sendTransactions/selectTokenToSendFormLoaded: +63%
  • sendTransactions/reviewTransactionToConfirmationPage: -98%
  • sendTransactions/longTaskCount: -100%
  • sendTransactions/longTaskTotalDuration: -100%
  • sendTransactions/longTaskMaxDuration: -100%
  • sendTransactions/tbt: -100%
  • sendTransactions/total: -93%
  • sendTransactions/inp: -37%
  • sendTransactions/fcp: +23%
  • sendTransactions/lcp: -59%
  • sendTransactions/cls: +171%
  • swap/openSwapPageFromHome: +833%
  • swap/fetchAndDisplaySwapQuotes: +127%
  • swap/longTaskCount: +33%
  • swap/tbt: -32%
  • swap/total: +130%
  • swap/inp: +13%
  • swap/lcp: -71%
  • swap/cls: -92%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 solanaAssetDetails/FCP: p75 1.8s
  • 🟡 sendTransactions/FCP: p75 2.0s
  • 🟡 swap/FCP: p75 1.9s
  • 🟡 solanaAssetDetails/FCP: p75 1.9s
  • 🟡 importSrpHome/FCP: p75 2.1s
  • 🟡 sendTransactions/FCP: p75 2.0s
  • 🔴 swap/INP: p75 720ms
  • 🟡 swap/FCP: p75 2.1s
Dapp Page Load Benchmarks · Samples: 100
Benchmarkchrome-webpack
dappPageLoad
[Sentry log · main/release]
🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • dappPageLoad/pageLoadTime: -67%
  • dappPageLoad/domContentLoaded: -24%
  • dappPageLoad/firstPaint: -50%
  • dappPageLoad/firstContentfulPaint: -50%
Bundle size diffs
  • background: 128 Bytes (0%)
  • ui: 149 Bytes (0%)
  • common: 0 Bytes (0%)
  • other: 0 Bytes (0%)
  • contentScripts: 0 Bytes (0%)
  • zip: 59 Bytes (0%)

@n3ps
n3ps added this pull request to the merge queue Aug 13, 2026
Merged via the queue into main with commit b91fc4a Aug 13, 2026
139 checks passed
@n3ps
n3ps deleted the chore/bump-client-utils-2.0.2 branch August 13, 2026 19:52
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 13, 2026
@metamaskbot metamaskbot added the release-13.46.0 Issue or pull request that will be included in release 13.46.0 label Aug 13, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

release-13.46.0 Issue or pull request that will be included in release 13.46.0 risk:low size-XS team-core-extension-ux Core Extension UX team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants