chore: Bump @lavamoat/allow-scripts from 3.4.0 to 3.4.1
Bumps @lavamoat/allow-scripts from 3.4.0 to 3.4.1.
Release notes
Sourced from @lavamoat/allow-scripts's releases.
allow-scripts: v3.4.1
3.4.1 (2025-11-19)
Bug Fixes
Commits
3a2edd4chore: release main (#1849)5ba0f2dfix(deps): fix npm audit issues (#1853)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
[!NOTE] Updates @lavamoat/allow-scripts from 3.4.0 to 3.4.1 in root and all packages, refreshing yarn.lock with related transitive dependency upgrades.
- Dependencies:
- Bump
@lavamoat/allow-scriptsdevDependency from^3.4.0to^3.4.1across the monorepo (root and all workspaces).- Refresh
yarn.lock, updating transitive packages (e.g.,@npmcli/*,make-fetch-happen,cacache,node-gyp,tar,which, etc.).Written by Cursor Bugbot for commit ffb78924c9c23085efd5de11bcd0f9ab17aff30d. This will update automatically on new commits. Configure here.
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
| Diff | Package | Supply Chain Security |
Vulnerability | Quality | Maintenance | License |
|---|---|---|---|---|---|---|
| @lavamoat/allow-scripts@3.4.0 ⏵ 3.4.1 |
[!CAUTION] MetaMask internal reviewing guidelines:
- Do not ignore-all
- Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
- Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
@SocketSecurity ignore npm/PACKAGE@VERSION
| Action | Severity | Alert (click "▶" to expand/collapse) |
|---|---|---|
| Block | Network access: npm
|
|
| Warn | Potential code anomaly (AI signal): npm
|
Codecov Report
:white_check_mark: All modified and coverable lines are covered by tests.
:white_check_mark: Project coverage is 98.28%. Comparing base (fc9ab36) to head (0b4d0d6).
Additional details and impacted files
@@ Coverage Diff @@
## main #3744 +/- ##
=======================================
Coverage 98.28% 98.28%
=======================================
Files 420 420
Lines 12211 12211
Branches 1889 1889
=======================================
Hits 12002 12002
Misses 209 209
:umbrella: View full report in Codecov by Sentry.
:loudspeaker: Have feedback on the report? Share it here.
:rocket: New features to boost your workflow:
- :snowflake: Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
- :package: JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.