Skip to content

fix(deps): move ethers to devDependencies (clears last runtime advisory) - #373

Merged
dawsbot merged 1 commit into
masterfrom
fix/ethers-devdeps
Sep 23, 2026
Merged

dawsbot merged 1 commit into
masterfrom
fix/ethers-devdeps

Conversation

@dawsbot

@dawsbot dawsbot commented Sep 23, 2026

Copy link
Copy Markdown
Owner

ethers was a runtime dependency but is never imported.

  • Every reference in src/ is a JSDoc comment ("Similar to X in ethers.js")
  • The built dist/ has no import or require of it — all 15 matches are comments and doc URLs
  • scripts/update-bundle-sizes.sh does use ethers, but bun installs its own ethers@6 into a temp dir, so it doesn't rely on this entry either

Impact

Every consumer of essential-eth was installing ethers 5.8.0 and its whole @ethersproject tree for nothing — and inheriting its advisories:

Advisory Severity Path
GHSA-96hv-2xvq-fx4p — ws memory-exhaustion DoS (fixed 8.21.0) high ethers → @ethersproject/providers → ws@8.18.0
12 × @ethersproject/* low direct

Moving it to devDependencies removes all of that from the install tree of anyone depending on this package.

Verification

Check Result
npm audit --omit=dev 0 vulnerabilities (was 1 high + 12 low)
npm ls ws --omit=dev empty
npm run build exit 0 — ESM, CJS and DTS all emit
npx vitest run 9 files / 33 tests failed, 174 passed — byte-identical to master, same pre-existing failures from unset RPC keys

Notes

🤖 Generated with Claude Code

ethers was a runtime dependency but is never imported. Every reference to
it in src/ is a JSDoc comment ("Similar to X in ethers.js"), and the built
dist/ contains no import or require of it -- all 15 matches there are
comments and doc URLs. scripts/update-bundle-sizes.sh does use ethers, but
it `bun install`s its own ethers@6 into a temp dir, so it does not rely on
this entry either.

Consequence: every consumer of essential-eth was installing ethers 5.8.0 and
its whole @ethersproject tree for nothing -- and inheriting its advisories:

  ws 8.18.0 (high)  GHSA-96hv-2xvq-fx4p memory-exhaustion DoS, fixed in
                    8.21.0, reached consumers via
                    ethers -> @ethersproject/providers -> ws
  plus 12 low @ethersproject/* advisories

Moving it to devDependencies removes all of that from the install tree of
anyone depending on this package. This is also what PR #358 proposed; that
branch has rewrite-era conflicts, so this is the same change on a clean base
and #358 can be closed.

Verified:
  - npm audit --omit=dev: 0 vulnerabilities (was 1 high + 12 low)
  - npm ls ws --omit=dev: empty
  - build exits 0; ESM, CJS and DTS all emit
  - tests byte-identical to master: 9 files / 33 tests failed, 174 passed,
    the same pre-existing failures from unset RPC keys

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 23, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
essential-eth Ready Ready Preview Sep 23, 2026 4:28pm UTC

@dawsbot
dawsbot merged commit b637183 into master Sep 23, 2026
2 of 7 checks passed
@dawsbot
dawsbot deleted the fix/ethers-devdeps branch September 23, 2026 16:36

This branch was successfully deployed

1 active deployment
Preview — 9dc14ae9 Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant