Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 11, 2024

This PR contains the following updates:

Package Change Age Confidence
@wagmi/connectors (source) 5.3.35.11.2 age confidence

Release Notes

wevm/wagmi (@​wagmi/connectors)

v5.11.2

Compare Source

Patch Changes

v5.11.1

Compare Source

Patch Changes
  • Updated porto. (41eb70e)

  • Pulled porto connector implementation. (#​4801)

v5.11.0

Compare Source

Minor Changes

v5.10.2

Compare Source

Patch Changes

v5.10.1

Compare Source

Patch Changes

v5.10.0

Compare Source

Minor Changes
Patch Changes

v5.9.9

Compare Source

Patch Changes

v5.9.8

Compare Source

Patch Changes

v5.9.6

Compare Source

Patch Changes

v5.9.5

Compare Source

Patch Changes

v5.9.4

Compare Source

Patch Changes

v5.9.3

Compare Source

Patch Changes

v5.9.2

Compare Source

Patch Changes

v5.9.1

Compare Source

Patch Changes

v5.9.0

Compare Source

Minor Changes
Patch Changes

v5.8.6

Compare Source

Patch Changes

v5.8.5

Compare Source

Patch Changes

v5.8.4

Compare Source

Patch Changes

v5.8.3

Compare Source

Patch Changes

v5.8.2

Compare Source

Patch Changes

v5.8.1

Compare Source

Patch Changes

v5.8.0

Compare Source

Minor Changes

v5.7.13

Compare Source

Patch Changes

v5.7.12

Compare Source

Patch Changes

v5.7.11

Compare Source

Patch Changes

v5.7.10

Compare Source

Patch Changes

v5.7.9

Compare Source

Patch Changes

v5.7.8

Compare Source

Patch Changes

v5.7.7

Compare Source

Patch Changes

v5.7.6

Compare Source

Patch Changes

v5.7.5

Compare Source

Patch Changes

v5.7.4

Compare Source

Patch Changes

v5.7.3

Compare Source

Patch Changes

v5.7.2

Compare Source

Patch Changes

v5.7.1

Compare Source

Patch Changes

v5.7.0

Compare Source

Minor Changes

v5.6.2

Compare Source

Patch Changes

v5.6.1

Compare Source

Patch Changes

v5.6.0

Compare Source

Minor Changes
Patch Changes

v5.5.3

Compare Source

Patch Changes

v5.5.2

Compare Source

Patch Changes

v5.5.0

Compare Source

Minor Changes
Patch Changes

v5.4.0

Compare Source

Minor Changes

v5.3.10

Compare Source

Patch Changes

v5.3.9

Compare Source

Patch Changes

v5.3.8

Compare Source

Patch Changes

v5.3.7

Compare Source

Patch Changes

v5.3.6

Compare Source

Patch Changes

v5.3.5

Compare Source

Patch Changes

v5.3.4

Compare Source

Patch Changes

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@socket-security
Copy link

socket-security bot commented Nov 11, 2024

@socket-security
Copy link

socket-security bot commented Nov 11, 2024

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block High
[email protected] has Telemetry.

Note: Can be disabled by setting the environment variable NEXT_TELEMETRY_DISABLED=1 . See https://nextjs.org/telemetry for more information

From: packages/react-app/package.jsonnpm/[email protected]

ℹ Read more on: This package | This alert | What is telemetry?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Most telemetry comes with settings to disable it. Consider disabling telemetry if you do not want to be tracked.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
[email protected] has Native code.

Location: Package overview

From: ?npm/[email protected]npm/[email protected]npm/@wagmi/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | Why is native code a concern?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Verify that the inclusion of native code is expected and necessary for this package's functionality. If it is unnecessary or unexpected, consider using alternative packages without native code to mitigate potential risks.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Medium
[email protected] has Native code.

Location: Package overview

From: ?npm/[email protected]npm/[email protected]npm/@wagmi/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | Why is native code a concern?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: Verify that the inclusion of native code is expected and necessary for this package's functionality. If it is unnecessary or unexpected, consider using alternative packages without native code to mitigate potential risks.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
[email protected] is a AI-detected potential code anomaly.

Notes: This command is typically benign and used to compile native addons. However, because it builds and may execute native code, it poses greater risk than pure-JS installs: malicious or vulnerable native source could introduce privilege-escalation, arbitrary code execution, or other system-level impacts. Review the native source, build scripts, and any downloaded prebuilt binaries before trusting the package.

Confidence: 1.00

Severity: 0.60

From: ?npm/[email protected]npm/[email protected]npm/@wagmi/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
[email protected] is a AI-detected potential code anomaly.

Notes: The fragment represents a sophisticated Edge VM sandbox aimed at running untrusted code with controlled IO. While not overtly malicious, its capability to patch native constructors, generate and evaluate runtime code, and route network-like fetch events through sandboxed listeners creates meaningful security risks if misused or insufficiently isolated. This warrants thorough threat modeling, strict supply-chain controls, and explicit isolation guarantees in the hosting environment before deploying in production.

Confidence: 1.00

Severity: 0.60

From: packages/react-app/package.jsonnpm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
[email protected] is a AI-detected potential code anomaly.

Notes: This command is typically benign and used to compile native addons. However, because it builds and may execute native code, it poses greater risk than pure-JS installs: malicious or vulnerable native source could introduce privilege-escalation, arbitrary code execution, or other system-level impacts. Review the native source, build scripts, and any downloaded prebuilt binaries before trusting the package.

Confidence: 1.00

Severity: 0.60

From: ?npm/[email protected]npm/[email protected]npm/@wagmi/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
[email protected] is a AI-detected potential code anomaly.

Notes: The code implements a cross-chain deposit flow with proper validations, artifact reads, and on-chain interactions. There is no evidence of hidden backdoors, data exfiltration, or malware. The main security considerations relate to token approval logic and correct configuration of flags to avoid granting excessive allowances. Overall, the module appears legitimate for a bridge deposit flow, with moderate risk primarily around configuration of approvals and correct handling of gas/fees.

Confidence: 1.00

Severity: 0.60

From: ?npm/@wagmi/[email protected]npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 063bab5 to afc428b Compare November 14, 2024 19:55
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.3.7 fix(deps): update dependency @wagmi/connectors to v5.3.8 Nov 14, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from afc428b to fff787f Compare November 16, 2024 01:48
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.3.8 fix(deps): update dependency @wagmi/connectors to v5.3.9 Nov 16, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from fff787f to ee49226 Compare November 17, 2024 06:33
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.3.9 fix(deps): update dependency @wagmi/connectors to v5.3.10 Nov 17, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from ee49226 to b7a0f1f Compare November 18, 2024 19:02
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.3.10 fix(deps): update dependency @wagmi/connectors to v5.4.0 Nov 18, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from b7a0f1f to c88a8ec Compare November 23, 2024 22:45
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.4.0 fix(deps): update dependency @wagmi/connectors to v5.5.0 Nov 23, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from c88a8ec to 4535d4b Compare November 30, 2024 22:53
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.5.0 fix(deps): update dependency @wagmi/connectors to v5.5.2 Nov 30, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 4535d4b to d398c0d Compare December 5, 2024 06:12
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.5.2 fix(deps): update dependency @wagmi/connectors to v5.5.3 Dec 5, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from d398c0d to 0a0beeb Compare December 15, 2024 09:09
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.5.3 fix(deps): update dependency @wagmi/connectors to v5.6.0 Dec 15, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 0a0beeb to 32e92e9 Compare December 15, 2024 15:33
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.6.0 fix(deps): update dependency @wagmi/connectors to v5.6.1 Dec 15, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 32e92e9 to 0a82aba Compare December 19, 2024 22:33
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.6.1 fix(deps): update dependency @wagmi/connectors to v5.6.2 Dec 19, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 0a82aba to 41bf8ad Compare December 20, 2024 02:04
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.6.2 fix(deps): update dependency @wagmi/connectors to v5.7.0 Dec 20, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 41bf8ad to 3844a84 Compare December 24, 2024 01:43
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.7.0 fix(deps): update dependency @wagmi/connectors to v5.7.1 Dec 24, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 3844a84 to 34884b1 Compare December 26, 2024 20:21
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.7.1 fix(deps): update dependency @wagmi/connectors to v5.7.2 Dec 26, 2024
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 34884b1 to 395250c Compare December 27, 2024 09:11
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.7.2 fix(deps): update dependency @wagmi/connectors to v5.7.3 Dec 27, 2024
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.8.5 fix(deps): update dependency @wagmi/connectors to v5.8.6 Jul 19, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from f6f956a to 877d76e Compare July 22, 2025 19:14
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.8.6 fix(deps): update dependency @wagmi/connectors to v5.9.0 Jul 22, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 877d76e to 8bc0992 Compare August 3, 2025 19:15
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.9.0 fix(deps): update dependency @wagmi/connectors to v5.9.1 Aug 3, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 8bc0992 to e3b203b Compare August 11, 2025 23:08
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.9.1 fix(deps): update dependency @wagmi/connectors to v5.9.2 Aug 11, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from e3b203b to 924b2c6 Compare August 14, 2025 23:07
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.9.2 fix(deps): update dependency @wagmi/connectors to v5.9.3 Aug 14, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 924b2c6 to bab8677 Compare August 21, 2025 20:26
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.9.3 fix(deps): update dependency @wagmi/connectors to v5.9.4 Aug 21, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from bab8677 to 752c605 Compare August 27, 2025 18:42
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.9.4 fix(deps): update dependency @wagmi/connectors to v5.9.5 Aug 27, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 752c605 to 8686bff Compare August 31, 2025 12:03
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.9.5 fix(deps): update dependency @wagmi/connectors to v5.9.8 Aug 31, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 8686bff to 152e66c Compare September 2, 2025 01:33
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.9.8 fix(deps): update dependency @wagmi/connectors to v5.9.9 Sep 2, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 152e66c to e013a9f Compare September 20, 2025 21:49
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.9.9 fix(deps): update dependency @wagmi/connectors to v5.10.0 Sep 20, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from e013a9f to 5bc5edc Compare September 22, 2025 19:33
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.10.0 fix(deps): update dependency @wagmi/connectors to v5.10.1 Sep 22, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 5bc5edc to a31090f Compare September 25, 2025 17:45
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.10.1 fix(deps): update dependency @wagmi/connectors to v5.10.2 Sep 25, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from a31090f to ab410aa Compare September 28, 2025 02:46
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.10.2 fix(deps): update dependency @wagmi/connectors to v5.11.0 Sep 28, 2025
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from ab410aa to 8b299ed Compare September 28, 2025 06:15
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.11.0 fix(deps): update dependency @wagmi/connectors to v5.11.1 Sep 28, 2025
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot force-pushed the renovate/wagmi-connectors-5.x branch from 8b299ed to 7b168c4 Compare September 28, 2025 22:44
@renovate renovate bot changed the title fix(deps): update dependency @wagmi/connectors to v5.11.1 fix(deps): update dependency @wagmi/connectors to v5.11.2 Sep 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant