Skip to content

fix(deps): update ethereumjs-ethereumjs-monorepo to v10 - #10519

Open
metamask-ci[bot] wants to merge 2 commits into
mainfrom
renovate/major-ethereumjs-ethereumjs-monorepo
Open

metamask-ci[bot] wants to merge 2 commits into
mainfrom
renovate/major-ethereumjs-ethereumjs-monorepo

Conversation

@metamask-ci

@metamask-ci metamask-ci Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@ethereumjs/common (source) ^4.4.0 → ^10.1.3 age confidence
@ethereumjs/rlp (source) ^5.0.2 → ^10.1.3 age confidence
@ethereumjs/tx (source) ^5.4.0 → ^10.1.3 age confidence
@ethereumjs/util (source) ^9.1.0 → ^10.1.3 age confidence

Release Notes

ethereumjs/ethereumjs-monorepo (@​ethereumjs/common)

v10.1.3: @​ethereumjs/common v10.1.3

Compare Source

Release round overview

Welcome to 10.1.3 — a coordinated release across all active @ethereumjs/* libraries on the 10.1.x line. If you have been experimenting with the upcoming Amsterdam hardfork, this is our close-to-ready preview: the full 14-EIP Hardfork.Amsterdam bundle is implemented and aligned with tests-glamsterdam-devnet@v8.1.0 and glamsterdam-devnet-8. Public APIs and spec alignment are largely stable — a good time to try BAL builder/validator flows, two-dimensional block gas, builder requests, and the rest of the Amsterdam surface — but Amsterdam remains experimental and must not be used in production; spec or API shifts can still happen in later 10.1.x patches.

The sections below cover this package only; for the full EIP list, examples, and release ↔ spec tracking, see the @​ethereumjs/vm Amsterdam overview. On Osaka or earlier hardforks? Nothing changes unless you explicitly select Hardfork.Amsterdam.

@ethereumjs/common

@ethereumjs/common is the fork and parameter engine. Within the 10.1.3 round, Hardfork.Amsterdam expands from nine to fourteen EIPs and picks up the revised glamsterdam-devnet gas schedule — the single switch every downstream package inherits when you set hardfork: Hardfork.Amsterdam.

At a glance
  • Hardfork.Amsterdam now activates EIPs 2780, 7708, 7843, 7778, 7928, 7954, 7976, 7981, 7997, 8024, 8037, 8038, 8246, and 8282.
  • Revised gasPrices / gasConfig / vm params for glamsterdam-devnet v8.1.0 (EIP-8038 state-access costs, EIP-2780 intrinsic constants, …).
  • Spec snapshot: tests-glamsterdam-devnet@v8.1.0.
Amsterdam (experimental)

Behaviour may still change in subsequent 10.1.x patch releases.
Spec snapshot: tests-glamsterdam-devnet@v8.1.0 · Testnet: glamsterdam-devnet-8
Execution details: Amsterdam hardfork (experimental)

import { Common, Hardfork, Mainnet } from '@ethereumjs/common'

const common = new Common({ chain: Mainnet, hardfork: Hardfork.Amsterdam })

common.isActivatedEIP(8282) // true — builder deposit/exit requests
common.isActivatedEIP(8038) // true — state-access gas schedule
common.isActivatedEIP(2780) // true — revised intrinsic gas base
Changes
  • Expand Amsterdam to the full 14-EIP bundle (2780, 7997, 8038, 8246, 8282, …), see PR #​4361, #​4362, #​4364
  • Align Amsterdam gas schedule with glamsterdam-devnet v8.1.0, see PR #​4337, #​4364

v10.1.2: @​ethereumjs/common v10.1.2

Compare Source

Release round overview

Welcome to 10.1.2 — a coordinated release across all active @ethereumjs/* libraries on the 10.1.x line. If you have been following the upcoming Amsterdam hardfork, this is our first experimental preview ready to try out: a largely complete nine-EIP Hardfork.Amsterdam bundle, currently aligned with tests-bal@v7.1.0 and BAL devnet-7.

Amsterdam is still in flux — please do not use this in production yet — and we expect further 10.1.x releases as the spec and official tests evolve. The sections below cover this package only; for the full fork picture (EIP list, examples, release ↔ spec tracking), see the @​ethereumjs/vm Amsterdam overview. On Osaka or earlier hardforks? Nothing changes unless you explicitly select Hardfork.Amsterdam.

@ethereumjs/common

@ethereumjs/common is the fork and parameter engine: it answers “which EIPs are active?”, “what is maxCodeSize?”, and “what gas schedule applies?” for every other library. Within the 10.1.2 round, Amsterdam lands here as a new Hardfork.Amsterdam entry that activates the full nine-EIP bundle together — the same bundling execution-spec-tests and devnets use, so you should not cherry-pick individual Amsterdam EIPs in isolation when reproducing fixtures.

For integrators, the practical effect is a single switch: construct your Common with hardfork: Hardfork.Amsterdam and all downstream packages (@ethereumjs/evm, @ethereumjs/vm, @ethereumjs/tx, …) inherit consistent activation and parameter values.

At a glance
  • Add experimental Hardfork.Amsterdam with EIPs 7708, 7843, 7778, 7928, 7954, 7976, 7981, 8024, and 8037.
  • Updated gasPrices, gasConfig, and vm parameters for Amsterdam (7954 size limits, 7976/7981 floor pricing constants, 8037 state-gas dimensions, …).
Amsterdam (experimental)

Behaviour may change in subsequent 10.1.x patch releases.
Spec snapshot: tests-bal@v7.1.0 · Testnet: BAL devnet-7
Execution details: Amsterdam hardfork (experimental)

import { Common, Hardfork, Mainnet } from '@ethereumjs/common'

const common = new Common({ chain: Mainnet, hardfork: Hardfork.Amsterdam })

// Amsterdam raises max code / initcode size (EIP-7954)
common.param('maxCodeSize') // 51200 (vs 24576 pre-Amsterdam)

// EIP active checks drive behaviour in EVM, VM, Tx, Block
common.isActivatedEIP(7928) // true — BAL accumulation in VM/EVM
common.isActivatedEIP(8037) // true — two-dimensional block gas

The Supported EIPs section lists every Amsterdam EIP with links to the package that implements execution semantics.

Changes

v10.1.1: @​ethereumjs/common v10.1.1

Compare Source

  • Fix custom hardforks implementation to properly return hardforks list, see PR #​4216
  • Deprecate Node.js 18 support, minimum Node.js version is now 20, see PR #​4180
  • Add Node.js 24 support, see PR #​4194

v10.1.0: @​ethereumjs/common v10.1.0

Compare Source

  • Improve paramsCache updates, PR #​4091
  • Improve nextHardforkBlockOrTimestamp method, PR #​4080
  • Remove Verkle package support, PR #​4145
EIP-7594 - PeerDAS - Peer Data Availability Sampling

This release adds support for EIP-7594 PeerDAS, which extends EIP-4844 blob transactions with data availability sampling capabilities. The Common library now includes EIP-7594 configuration and activation for the Osaka hardfork, enabling support for PeerDAS blob transactions with cell proofs and network wrapper version 1.

EIP-7823 - Set upper bounds for MODEXP

EIP-7823 support has been added, introducing an upper bound of 8192 bits (1024 bytes) on each input field (base, exponent, modulus) of the MODEXP precompile. The Common library includes the EIP configuration and activation for Osaka, ensuring MODEXP calls exceeding these limits are properly rejected.

EIP-7825 - Transaction Gas Limit Cap

Support for EIP-7825 has been implemented, introducing a protocol-level cap of 16,777,216 gas (2^24) for individual transactions. The Common library includes the EIP configuration and activation for Osaka, enabling transaction validation against this gas limit cap.

EIP-7883 - ModExp Gas Cost Increase

EIP-7883 support has been added, which increases the gas cost of the MODEXP precompile. The Common library includes the EIP configuration and activation for Osaka, ensuring MODEXP operations use the updated pricing algorithm with increased minimum gas cost and adjusted complexity calculations.

EIP-7918 - Blob base fee bounded by execution cost

EIP-7918 support has been implemented, which imposes that the price of GAS_PER_BLOB blob gas is greater than the price of BLOB_BASE_COST execution gas. The Common library includes the EIP configuration and activation for Osaka, ensuring proper blob fee market functionality.

EIP-7934 - RLP Execution Block Size Limit

Support for EIP-7934 has been added, introducing a protocol-level cap on the maximum RLP-encoded block size to 10 MiB (with a 2 MiB margin for beacon block size). The Common library includes the EIP configuration and activation for Osaka, enabling block size validation.

EIP-7939 - Count leading zeros (CLZ) opcode

EIP-7939 support has been implemented, adding a new opcode CLZ (0x1e) that counts the number of leading zero bits in a 256-bit word. The Common library includes the EIP configuration and activation for Osaka, enabling the use of the CLZ opcode in EVM execution.

EIP-7951 - Precompile for secp256r1 Curve Support

EIP-7951 support has been added, introducing a new precompile at address 0x100 (P256VERIFY) for ECDSA signature verification over the secp256r1 curve. The Common library includes the EIP configuration and activation for Osaka, enabling native support for secp256r1 signatures from modern secure hardware devices.

EIP-7892 - Blob Parameter Only Hardforks

Support for Blob Parameter Only (BPO) hardforks has been implemented according to EIP-7892. BPO hardforks are lightweight protocol upgrades that modify only blob-related parameters (target, max, and blobGasPriceUpdateFraction) without requiring code changes, enabling rapid scaling of blob capacity in response to network demand.

Two BPO hardforks are scheduled alongside Fusaka:

  • BPO 1: Increases blob target to 10 and max to 15 blobs per block
  • BPO 2: Further increases blob target to 14 and max to 21 blobs per block

The Common library now includes BPO hardfork definitions and activation timestamps for testnets (Holešky, Sepolia, Hoodi). The getBlobGasSchedule() method returns the appropriate blob gas schedule parameters based on the active hardfork, automatically handling BPO transitions.

import { Common, Hardfork, Mainnet } from @ethereumjs/common

// Common instance with BPO1 active
const common = new Common({ chain: Mainnet, hardfork: Hardfork.Bpo1 })

// Get blob gas schedule parameters
const schedule = common.getBlobGasSchedule()
// schedule.targetBlobGasPerBlock = 1310720 (10 * 131072)
// schedule.maxBlobGasPerBlock = 1966080 (15 * 131072)
// schedule.blobGasPriceUpdateFraction = 8346193

v10.0.0: @​ethereumjs/common v10.0.0

Compare Source

Overview

This release is part of the v10 breaking release round making the EthereumJS libraries compatible with the Pectra hardfork going live on Ethereum mainnet on May 7 2025. Beside the hardfork update these releases mark a milestone in our release history since they - for the first time ever - bring the full Ethereum protocol stack - including the EVM - to the browser without any restrictions anymore, coming along with other substantial updates regarding library security and functionality.

Some highlights:

  • 🌴 Introduction of a tree-shakeable API
  • 👷🏼 Substantial dependency reduction to a "controlled dependency set" (no more than 10 + @Noble crypto)
  • 📲 EIP-7702 readiness
  • 🛵 Substantial bundle size reductions for all libraries
  • 🏄🏾‍♂️ All libraries now pure JS being WASM-free by default
  • 🦋 No more propriatary Node.js primitives

So: All libraries now work in the browser "out of the box".

Release Notes

Major release notes for this release can be found in the alpha.1 release notes here, with some additions along with the RC.1 releases, see here.

Changes since RC.1
  • Add mainnet Prague timestamp & fork hash, PR #​3971
  • GethGenesis TypeScript interface, PR #​3973

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.


Note

High Risk
Major-version EthereumJS upgrades on transaction encoding (transaction-controller, @metamask/utils, keyring tests) touch signing and tx handling; v10 includes breaking API and crypto stack changes despite no local code edits in this PR.

Overview
Upgrades the monorepo to EthereumJS v10.1.3 across several @metamask/* packages, with no source changes in this diff—only package.json, changelogs, and yarn.lock.

@ethereumjs/util ^9.1.0 → ^10.1.3 is applied in accounts-controller, assets-controller, assets-controllers, keyring-controller (runtime dep), and multichain-account-service.

Full EthereumJS stack on v10 in transaction-controller: @ethereumjs/common, rlp, tx, and util all move to ^10.1.3. keyring-controller bumps util in dependencies and aligns @ethereumjs/common / tx devDependencies to ^10.1.3. @metamask/utils bumps @ethereumjs/tx to ^10.1.3.

The lockfile adds the v10 @ethereumjs/* tree (including @noble/curves / @noble/hashes v2 as transitive deps for tx/util).

Reviewed by Cursor Bugbot for commit fd1fe80. Bugbot is set up for automated code reviews on this repo. Configure here.

@metamask-ci
metamask-ci Bot requested review from a team as code owners September 28, 2026 12:57
@metamask-ci
metamask-ci Bot deployed to default-branch September 28, 2026 12:57 Active
@metamask-ci
metamask-ci Bot deployed to dependabot September 28, 2026 12:57 Active
@socket-security

socket-security Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Added@​ethereumjs/​tx@​10.1.31001001008770
Added@​ethereumjs/​util@​10.1.31001001008770
Added@​ethereumjs/​rlp@​10.1.31001001008770
Added@​ethereumjs/​common@​10.1.310010010087100

View full report

@metamask-ci

metamask-ci Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@metamask-ci
metamask-ci Bot force-pushed the renovate/major-ethereumjs-ethereumjs-monorepo branch from 2a479ca to f27e598 Compare October 7, 2026 14:59
@metamask-ci
metamask-ci Bot deployed to dependabot October 7, 2026 15:00 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-ethereumjs-ethereumjs-monorepo branch from f523471 to e539e3c Compare October 7, 2026 20:08
@metamask-ci
metamask-ci Bot deployed to dependabot October 7, 2026 20:08 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-ethereumjs-ethereumjs-monorepo branch from 7d40b08 to c6c5b2d Compare October 8, 2026 06:35
@metamask-ci
metamask-ci Bot deployed to dependabot October 8, 2026 06:35 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-ethereumjs-ethereumjs-monorepo branch from 6f583a1 to f9a85c2 Compare October 8, 2026 20:16
@metamask-ci
metamask-ci Bot deployed to dependabot October 8, 2026 20:16 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-ethereumjs-ethereumjs-monorepo branch from f0fb443 to d1d3ef8 Compare October 9, 2026 06:26
@metamask-ci
metamask-ci Bot deployed to dependabot October 9, 2026 06:26 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-ethereumjs-ethereumjs-monorepo branch from 7d9d7c4 to 3274e53 Compare October 9, 2026 13:07
@metamask-ci
metamask-ci Bot deployed to dependabot October 9, 2026 13:07 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-ethereumjs-ethereumjs-monorepo branch from 2e7b0a5 to 4682a25 Compare October 10, 2026 06:24
@metamask-ci
metamask-ci Bot deployed to dependabot October 10, 2026 06:24 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-ethereumjs-ethereumjs-monorepo branch from 63db24c to a19662a Compare October 11, 2026 06:23
@metamask-ci
metamask-ci Bot deployed to dependabot October 11, 2026 06:24 Active

This branch was successfully deployed

2 active (outdated) deployments
default-branch — 387f8602 Deployed Sep 28, 2026 by metamask-ci[bot] via Determine whether this PR is a release PR #4763
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants