Repository navigation
Conversation
ethers@^5.7.2 was listed as a runtime dependency, but it is not imported anywhere in src/ or test/ — its only use is in scripts/update-bundle-sizes.sh for bundle-size comparisons. For a library whose whole pitch is being 10x smaller than ethers, shipping ethers as a transitive install to every consumer defeats the purpose. Moving it to devDependencies keeps the bundle-size script working while removing it from consumer install trees. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
dawsbot
force-pushed
the
fix/ethers-to-devdeps
branch
from
September 22, 2026 06:01
a6d15d4 to
acdf95f
Compare
dawsbot
added a commit
that referenced
this pull request
Sep 23, 2026
…ry) (#373) ethers was a runtime dependency but is never imported. Every reference to it in src/ is a JSDoc comment ("Similar to X in ethers.js"), and the built dist/ contains no import or require of it -- all 15 matches there are comments and doc URLs. scripts/update-bundle-sizes.sh does use ethers, but it `bun install`s its own ethers@6 into a temp dir, so it does not rely on this entry either. Consequence: every consumer of essential-eth was installing ethers 5.8.0 and its whole @ethersproject tree for nothing -- and inheriting its advisories: ws 8.18.0 (high) GHSA-96hv-2xvq-fx4p memory-exhaustion DoS, fixed in 8.21.0, reached consumers via ethers -> @ethersproject/providers -> ws plus 12 low @ethersproject/* advisories Moving it to devDependencies removes all of that from the install tree of anyone depending on this package. This is also what PR #358 proposed; that branch has rewrite-era conflicts, so this is the same change on a clean base and #358 can be closed. Verified: - npm audit --omit=dev: 0 vulnerabilities (was 1 high + 12 low) - npm ls ws --omit=dev: empty - build exits 0; ESM, CJS and DTS all emit - tests byte-identical to master: 9 files / 33 tests failed, 174 passed, the same pre-existing failures from unset RPC keys Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Owner
Author
|
Superseded by #373, which is now merged to This branch carried conflicts from the September history rewrite, so rather than untangle them I applied the same change on a clean base. #373 moves Result: Thanks for filing it — the diagnosis here was right. |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
ethers@^5.7.2was listed independencies, so every consumer of essential-eth installs ethers transitively — ironic for a library whose pitch is being 10x smaller than ethers.Verified with grep: ethers is imported nowhere in
src/ortest/. Its only use isscripts/update-bundle-sizes.sh(bundle-size comparisons), which is dev-only tooling. This PR moves it todevDependencies.Changes
package.json:ethersmoved fromdependenciestodevDependenciespackage-lock.json: regenerated (ethers subtree now marked dev; consumers no longer pull it)readme.md: bundle-size table refresh — auto-generated by the repo's own pre-commit hookVerification
vitest run: 174 passed / 33 failed — the 33 failures are identical on unmodifiedmaster(integration tests failing with "Must be authenticated!" because noALCHEMY_API_KEYis set locally). Zero regressions from this change.tsupbuild: successeslint: 0 errors (pre-existing warnings only)scripts/update-bundle-sizes.shstill works (it ran via the pre-commit hook and produced this PR's readme update)🤖 Generated with Claude Code