Skip to content

Conversation

@Gudahtt
Copy link
Member

@Gudahtt Gudahtt commented Jul 21, 2025

Description

Update form-data package to address this advisory: GHSA-fjxv-7rqg-78g4

Open in GitHub Codespaces

Changelog

CHANGELOG entry: null

Related issues

N/A

Manual testing steps

N/A

Screenshots/Recordings

N/A

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

Update `form-data` package to address this advisory: GHSA-fjxv-7rqg-78g4
@Gudahtt
Copy link
Member Author

Gudahtt commented Jul 21, 2025

@metamaskbot update-policies

@socket-security
Copy link

socket-security bot commented Jul 21, 2025

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedes-set-tostringtag@​2.0.3 ⏵ 2.1.06710083 +452100
Updatedform-data@​4.0.0 ⏵ 4.0.499100 +75100 +197100

View full report

@metamaskbot
Copy link
Collaborator

Policies updated.
👀 Please review the diff for suspicious new powers.

🧠 Learn how: https://lavamoat.github.io/guides/policy-diff/#what-to-look-for-when-reviewing-a-policy-diff

@metamaskbot
Copy link
Collaborator

✨ Files requiring CODEOWNER review ✨

🧩 @MetaMask/extension-devs (5 files, +21 -20)
  • 📁 lavamoat/
    • 📁 browserify/
      • 📁 beta/
        • 📄 policy.json +3 -3
      • 📁 experimental/
        • 📄 policy.json +3 -3
      • 📁 flask/
        • 📄 policy.json +3 -3
      • 📁 main/
        • 📄 policy.json +3 -3
    • 📁 build-system/
      • 📄 policy.json +9 -8

📜 @MetaMask/policy-reviewers (5 files, +21 -20)
  • 📁 lavamoat/
    • 📁 browserify/
      • 📁 beta/
        • 📄 policy.json +3 -3
      • 📁 experimental/
        • 📄 policy.json +3 -3
      • 📁 flask/
        • 📄 policy.json +3 -3
      • 📁 main/
        • 📄 policy.json +3 -3
    • 📁 build-system/
      • 📄 policy.json +9 -8

Tip

Follow the policy review process outlined in the LavaMoat Policy Review Process doc before expecting an approval from Policy Reviewers.


🔗 @MetaMask/supply-chain (5 files, +21 -20)
  • 📁 lavamoat/
    • 📁 browserify/
      • 📁 beta/
        • 📄 policy.json +3 -3
      • 📁 experimental/
        • 📄 policy.json +3 -3
      • 📁 flask/
        • 📄 policy.json +3 -3
      • 📁 main/
        • 📄 policy.json +3 -3
    • 📁 build-system/
      • 📄 policy.json +9 -8

@metamaskbot
Copy link
Collaborator

Builds ready [b161b89]
UI Startup Metrics (1243 ± 56 ms)
PlatformBuildTypePageMetricMean (ms)Min (ms)Max (ms)Std Dev (ms)P 75 (ms)P 95 (ms)
ChromeBrowserifyHomeuiStartup1243113514515612741339
load106597312935611001147
domContentLoaded105896612895610931141
domInteractive18134881639
firstPaint76070129941610831146
backgroundConnect2091962387211230
firstReactRender21144462335
getState1033161424
initialActions507110519
loadScripts856761108155891937
setupStore74273815
WebpackHomeuiStartup23841923279713624582584
load18861445234615019592147
domContentLoaded18791439233415019512143
domInteractive2112272291563
firstPaint1576347270173284
backgroundConnect3411289453287
firstReactRender1718738772208329
getState194279421441
initialActions11217924835
loadScripts18751435232114919442138
setupStore166240291622
FirefoxBrowserifyHomeuiStartup15501359223614616101850
load1328118916948413701505
domContentLoaded1328118916948413701505
domInteractive1073550165110216
firstPaintNaNNaNNaNNaNNaNNaN
backgroundConnect3116140203260
firstReactRender28226873034
getState153244351045
initialActions6115216417
loadScripts1304116816688213441479
setupStore114183191128
WebpackHomeuiStartup17591545251319818352144
load14931297203114715691808
domContentLoaded14921296203014715691807
domInteractive107345327694322
firstPaintNaNNaNNaNNaNNaNNaN
backgroundConnect3016157173358
firstReactRender52416765662
getState133269351326
initialActions8127329422
loadScripts14691275200714415481772
setupStore15427538928
Benchmark value 1243 exceeds gate value 1234 for chrome browserify home mean uiStartup
Benchmark value 210 exceeds gate value 10 for chrome browserify home mean backgroundConnect
Benchmark value 6 exceeds gate value 1 for chrome browserify home mean initialActions
Benchmark value 856 exceeds gate value 830 for chrome browserify home mean loadScripts
Benchmark value 231 exceeds gate value 18 for chrome browserify home p95 backgroundConnect
Benchmark value 19 exceeds gate value 1.2 for chrome browserify home p95 initialActions
Benchmark value 2385 exceeds gate value 2192 for chrome webpack home mean uiStartup
Benchmark value 1887 exceeds gate value 1711 for chrome webpack home mean load
Benchmark value 1880 exceeds gate value 1704 for chrome webpack home mean domContentLoaded
Benchmark value 22 exceeds gate value 21 for chrome webpack home mean domInteractive
Benchmark value 11 exceeds gate value 7 for chrome webpack home mean initialActions
Benchmark value 1875 exceeds gate value 1699 for chrome webpack home mean loadScripts
Benchmark value 2585 exceeds gate value 2454 for chrome webpack home p95 uiStartup
Benchmark value 2147 exceeds gate value 2030 for chrome webpack home p95 load
Benchmark value 2144 exceeds gate value 2005 for chrome webpack home p95 domContentLoaded
Benchmark value 63 exceeds gate value 57 for chrome webpack home p95 domInteractive
Benchmark value 35 exceeds gate value 7 for chrome webpack home p95 initialActions
Benchmark value 2138 exceeds gate value 1970 for chrome webpack home p95 loadScripts
Benchmark value 1551 exceeds gate value 1405 for firefox browserify home mean uiStartup
Benchmark value 1329 exceeds gate value 1245 for firefox browserify home mean load
Benchmark value 1328 exceeds gate value 1239 for firefox browserify home mean domContentLoaded
Benchmark value 32 exceeds gate value 25 for firefox browserify home mean backgroundConnect
Benchmark value 29 exceeds gate value 25 for firefox browserify home mean firstReactRender
Benchmark value 15 exceeds gate value 11 for firefox browserify home mean getState
Benchmark value 6 exceeds gate value 1 for firefox browserify home mean initialActions
Benchmark value 1304 exceeds gate value 1230 for firefox browserify home mean loadScripts
Benchmark value 12 exceeds gate value 9 for firefox browserify home mean setupStore
Benchmark value 1850 exceeds gate value 1660 for firefox browserify home p95 uiStartup
Benchmark value 1505 exceeds gate value 1495 for firefox browserify home p95 load
Benchmark value 1505 exceeds gate value 1495 for firefox browserify home p95 domContentLoaded
Benchmark value 216 exceeds gate value 195 for firefox browserify home p95 domInteractive
Benchmark value 45 exceeds gate value 24 for firefox browserify home p95 getState
Benchmark value 17 exceeds gate value 2 for firefox browserify home p95 initialActions
Benchmark value 1479 exceeds gate value 1475 for firefox browserify home p95 loadScripts
Benchmark value 28 exceeds gate value 27 for firefox browserify home p95 setupStore
Benchmark value 1760 exceeds gate value 1615 for firefox webpack home mean uiStartup
Benchmark value 1493 exceeds gate value 1380 for firefox webpack home mean load
Benchmark value 1493 exceeds gate value 1380 for firefox webpack home mean domContentLoaded
Benchmark value 107 exceeds gate value 100 for firefox webpack home mean domInteractive
Benchmark value 30 exceeds gate value 26 for firefox webpack home mean backgroundConnect
Benchmark value 52 exceeds gate value 38 for firefox webpack home mean firstReactRender
Benchmark value 9 exceeds gate value 1 for firefox webpack home mean initialActions
Benchmark value 1470 exceeds gate value 1360 for firefox webpack home mean loadScripts
Benchmark value 15 exceeds gate value 13 for firefox webpack home mean setupStore
Benchmark value 2144 exceeds gate value 1935 for firefox webpack home p95 uiStartup
Benchmark value 1808 exceeds gate value 1660 for firefox webpack home p95 load
Benchmark value 1807 exceeds gate value 1660 for firefox webpack home p95 domContentLoaded
Benchmark value 322 exceeds gate value 156 for firefox webpack home p95 domInteractive
Benchmark value 58 exceeds gate value 49 for firefox webpack home p95 backgroundConnect
Benchmark value 62 exceeds gate value 50 for firefox webpack home p95 firstReactRender
Benchmark value 22 exceeds gate value 2 for firefox webpack home p95 initialActions
Benchmark value 1772 exceeds gate value 1630 for firefox webpack home p95 loadScripts
Sum of mean exceeds: 1898ms | Sum of p95 exceeds: 1944.8ms
Sum of all benchmark exceeds: 3842.8ms

Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 38 Bytes (0%)
  • ui: 0 Bytes (0%)
  • common: 7 Bytes (0%)

@Gudahtt Gudahtt marked this pull request as ready for review July 21, 2025 21:42
@Gudahtt Gudahtt requested review from a team as code owners July 21, 2025 21:42
@Gudahtt Gudahtt enabled auto-merge July 21, 2025 22:00
@Gudahtt Gudahtt added this pull request to the merge queue Jul 21, 2025
Merged via the queue into main with commit f628bc6 Jul 21, 2025
274 of 276 checks passed
@Gudahtt Gudahtt deleted the update-form-data branch July 21, 2025 22:59
@github-actions github-actions bot locked and limited conversation to collaborators Jul 21, 2025
@metamaskbot metamaskbot added the release-13.1.0 Issue or pull request that will be included in release 13.1.0 label Jul 21, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

release-13.1.0 Issue or pull request that will be included in release 13.1.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants