Repository navigation
fix(deps): move ethers to devDependencies (clears last runtime advisory) - #373
Merged
Merged
Conversation
ethers was a runtime dependency but is never imported. Every reference to
it in src/ is a JSDoc comment ("Similar to X in ethers.js"), and the built
dist/ contains no import or require of it -- all 15 matches there are
comments and doc URLs. scripts/update-bundle-sizes.sh does use ethers, but
it `bun install`s its own ethers@6 into a temp dir, so it does not rely on
this entry either.
Consequence: every consumer of essential-eth was installing ethers 5.8.0 and
its whole @ethersproject tree for nothing -- and inheriting its advisories:
ws 8.18.0 (high) GHSA-96hv-2xvq-fx4p memory-exhaustion DoS, fixed in
8.21.0, reached consumers via
ethers -> @ethersproject/providers -> ws
plus 12 low @ethersproject/* advisories
Moving it to devDependencies removes all of that from the install tree of
anyone depending on this package. This is also what PR #358 proposed; that
branch has rewrite-era conflicts, so this is the same change on a clean base
and #358 can be closed.
Verified:
- npm audit --omit=dev: 0 vulnerabilities (was 1 high + 12 low)
- npm ls ws --omit=dev: empty
- build exits 0; ESM, CJS and DTS all emit
- tests byte-identical to master: 9 files / 33 tests failed, 174 passed,
the same pre-existing failures from unset RPC keys
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
etherswas a runtime dependency but is never imported.src/is a JSDoc comment ("Similar to X in ethers.js")dist/has no import or require of it — all 15 matches are comments and doc URLsscripts/update-bundle-sizes.shdoes use ethers, butbun installs its ownethers@6into a temp dir, so it doesn't rely on this entry eitherImpact
Every consumer of essential-eth was installing ethers 5.8.0 and its whole
@ethersprojecttree for nothing — and inheriting its advisories:wsmemory-exhaustion DoS (fixed 8.21.0)ethers → @ethersproject/providers → ws@8.18.0@ethersproject/*Moving it to
devDependenciesremoves all of that from the install tree of anyone depending on this package.Verification
npm audit --omit=devnpm ls ws --omit=devnpm run buildnpx vitest runNotes
readme.mdis in the diff because thepre-commithook re-ranupdate-bundle-sizes.sh. It only refreshes the comparison libraries (ethers 6.16→6.17, viem 2.46→2.56, ox 0.12→1.8). essential-eth's own numbers are unchanged apart from 24.8→24.9 kB. Unrelated to this fix, but harmless to carry.🤖 Generated with Claude Code