Skip to content

chore: Bump @metamask/chain-agnostic-permission from 1.6.1 to 1.6.2#4036

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/main/metamask/chain-agnostic-permission-1.6.2
Open

chore: Bump @metamask/chain-agnostic-permission from 1.6.1 to 1.6.2#4036
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/main/metamask/chain-agnostic-permission-1.6.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor

Bumps @metamask/chain-agnostic-permission from 1.6.1 to 1.6.2.

Commits
  • 555b77e Release 1037.0.0 (#9103)
  • 0eaa194 ci: use explicit dry-run input for npm publish (#9102)
  • bb53813 chore: bump api-specs to 0.15.0 (#9096)
  • 2ed9206 fix(keyring-controller): remove use of instanceof for `isKeyringNotFoundErr...
  • fdfacdc refactor: make QuoteResponse test mocks type-safe (#9098)
  • 6cfbbac feat(multichain-account-service): add deleteAccount to providers (#8960)
  • b5eb432 feat: add @metamask/wallet-cli package scaffold (#9065)
  • e28b152 perf(multichain-account-service): add isAligned (#9039)
  • ead5a7f chore: initialize @metamask/wallet-cli package (#9079)
  • 04b6ef3 fix: remove Authorization header for unauthenticated payment methods … (#9060)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​metamask/chain-agnostic-permission since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 16, 2026
@dependabot dependabot Bot requested a review from a team as a code owner June 16, 2026 06:06
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 16, 2026
@dependabot dependabot Bot temporarily deployed to default-branch June 16, 2026 06:06 Inactive
@socket-security

socket-security Bot commented Jun 16, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​metamask/​chain-agnostic-permission@​1.6.1 ⏵ 1.6.21001007895 +2100

View full report

@socket-security

socket-security Bot commented Jun 16, 2026

Copy link
Copy Markdown

Caution

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Block Medium
Network access: npm @ethersproject/web in module globalThis["fetch"]

Module: globalThis["fetch"]

Location: Package overview

From: ?npm/@metamask/permission-controller@13.1.1npm/@metamask/chain-agnostic-permission@1.6.2npm/@ethersproject/web@5.8.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@ethersproject/web@5.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Network access: npm @ethersproject/web in module http

Module: http

Location: Package overview

From: ?npm/@metamask/permission-controller@13.1.1npm/@metamask/chain-agnostic-permission@1.6.2npm/@ethersproject/web@5.8.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@ethersproject/web@5.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
Network access: npm @ethersproject/web in module https

Module: https

Location: Package overview

From: ?npm/@metamask/permission-controller@13.1.1npm/@metamask/chain-agnostic-permission@1.6.2npm/@ethersproject/web@5.8.0

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@ethersproject/web@5.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@codecov

codecov Bot commented Jun 16, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.58%. Comparing base (c67053b) to head (5e7ae85).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4036   +/-   ##
=======================================
  Coverage   98.58%   98.58%           
=======================================
  Files         425      425           
  Lines       12410    12410           
  Branches     1969     1969           
=======================================
  Hits        12235    12235           
  Misses        175      175           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Bumps [@metamask/chain-agnostic-permission](https://github.com/MetaMask/core) from 1.6.1 to 1.6.2.
- [Release notes](https://github.com/MetaMask/core/releases)
- [Commits](https://github.com/MetaMask/core/compare/@metamask/chain-agnostic-permission@1.6.1...@metamask/chain-agnostic-permission@1.6.2)

---
updated-dependencies:
- dependency-name: "@metamask/chain-agnostic-permission"
  dependency-version: 1.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/main/metamask/chain-agnostic-permission-1.6.2 branch from 1fd34f4 to 4e4068b Compare June 25, 2026 08:55
@dependabot dependabot Bot temporarily deployed to default-branch June 25, 2026 08:55 Inactive
@dependabot dependabot Bot temporarily deployed to default-branch June 25, 2026 08:56 Inactive
@dependabot dependabot Bot temporarily deployed to default-branch June 25, 2026 08:57 Inactive
@dependabot dependabot Bot temporarily deployed to default-branch June 25, 2026 09:02 Inactive
@dependabot dependabot Bot temporarily deployed to default-branch June 25, 2026 09:02 Inactive
@dependabot dependabot Bot temporarily deployed to default-branch June 25, 2026 09:07 Inactive
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant