Skip to content

fix: move ethers from dependencies to devDependencies - #358

Closed
dawsbot wants to merge 1 commit into
masterfrom
fix/ethers-to-devdeps
Closed

dawsbot wants to merge 1 commit into
masterfrom
fix/ethers-to-devdeps

Conversation

@dawsbot

@dawsbot dawsbot commented Jul 6, 2026

Copy link
Copy Markdown
Owner

Summary

ethers@^5.7.2 was listed in dependencies, so every consumer of essential-eth installs ethers transitively — ironic for a library whose pitch is being 10x smaller than ethers.

Verified with grep: ethers is imported nowhere in src/ or test/. Its only use is scripts/update-bundle-sizes.sh (bundle-size comparisons), which is dev-only tooling. This PR moves it to devDependencies.

Changes

  • package.json: ethers moved from dependencies to devDependencies
  • package-lock.json: regenerated (ethers subtree now marked dev; consumers no longer pull it)
  • readme.md: bundle-size table refresh — auto-generated by the repo's own pre-commit hook

Verification

  • vitest run: 174 passed / 33 failed — the 33 failures are identical on unmodified master (integration tests failing with "Must be authenticated!" because no ALCHEMY_API_KEY is set locally). Zero regressions from this change.
  • tsup build: success
  • eslint: 0 errors (pre-existing warnings only)
  • scripts/update-bundle-sizes.sh still works (it ran via the pre-commit hook and produced this PR's readme update)

🤖 Generated with Claude Code

ethers@^5.7.2 was listed as a runtime dependency, but it is not
imported anywhere in src/ or test/ — its only use is in
scripts/update-bundle-sizes.sh for bundle-size comparisons.

For a library whose whole pitch is being 10x smaller than ethers,
shipping ethers as a transitive install to every consumer defeats
the purpose. Moving it to devDependencies keeps the bundle-size
script working while removing it from consumer install trees.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
essential-eth Ready Ready Preview Sep 22, 2026 6:08am UTC

@dawsbot
dawsbot force-pushed the fix/ethers-to-devdeps branch from a6d15d4 to acdf95f Compare September 22, 2026 06:01
dawsbot added a commit that referenced this pull request Sep 23, 2026
…ry) (#373)

ethers was a runtime dependency but is never imported. Every reference to
it in src/ is a JSDoc comment ("Similar to X in ethers.js"), and the built
dist/ contains no import or require of it -- all 15 matches there are
comments and doc URLs. scripts/update-bundle-sizes.sh does use ethers, but
it `bun install`s its own ethers@6 into a temp dir, so it does not rely on
this entry either.

Consequence: every consumer of essential-eth was installing ethers 5.8.0 and
its whole @ethersproject tree for nothing -- and inheriting its advisories:

  ws 8.18.0 (high)  GHSA-96hv-2xvq-fx4p memory-exhaustion DoS, fixed in
                    8.21.0, reached consumers via
                    ethers -> @ethersproject/providers -> ws
  plus 12 low @ethersproject/* advisories

Moving it to devDependencies removes all of that from the install tree of
anyone depending on this package. This is also what PR #358 proposed; that
branch has rewrite-era conflicts, so this is the same change on a clean base
and #358 can be closed.

Verified:
  - npm audit --omit=dev: 0 vulnerabilities (was 1 high + 12 low)
  - npm ls ws --omit=dev: empty
  - build exits 0; ESM, CJS and DTS all emit
  - tests byte-identical to master: 9 files / 33 tests failed, 174 passed,
    the same pre-existing failures from unset RPC keys

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@dawsbot

dawsbot commented Sep 23, 2026

Copy link
Copy Markdown
Owner Author

Superseded by #373, which is now merged to master.

This branch carried conflicts from the September history rewrite, so rather than untangle them I applied the same change on a clean base. #373 moves ethers to devDependencies and verifies it's safe: every reference in src/ is a JSDoc comment, the built dist/ has no import or require of it, and scripts/update-bundle-sizes.sh installs its own ethers@6 into a temp dir.

Result: npm audit --omit=dev is now 0 vulnerabilities — this also removed the high-severity ws advisory (GHSA-96hv-2xvq-fx4p) from every consumer's install tree.

Thanks for filing it — the diagnosis here was right.

@dawsbot dawsbot closed this Sep 23, 2026

This branch was successfully deployed

1 active deployment
Preview — acdf95fb Deployed Sep 22, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant