Skip to content

fix(deps): update dependency @oclif/core to v5 - #10595

Open
metamask-ci[bot] wants to merge 2 commits into
mainfrom
renovate/major-oclif-core
Open

metamask-ci[bot] wants to merge 2 commits into
mainfrom
renovate/major-oclif-core

Conversation

@metamask-ci

@metamask-ci metamask-ci Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@oclif/core ^4.10.5 → ^5.1.2 age confidence

Release Notes

oclif/core (@​oclif/core)

v5.1.2

Compare Source

Bug Fixes
  • deps: bump browserslist from 4.28.2 to 4.28.9 (1ba8dfd)

v5.1.1

Compare Source

Bug Fixes
  • feedback from code review (W-24099831) (b36c51b)
  • resolved autofixable eslint violations (W-24099831) (b9eabd3)
  • resolved busted interoperability tests (W-24099831) (b6866f0)
  • resolved circular eslint fixes (W-24099831) (d0935c1)

v5.1.0

Compare Source

Bug Fixes
  • rename boolean var to satisfy unicorn/consistent-boolean-name (a1316cc)
Features

5.0.1 (2026-09-23)

Bug Fixes
  • getting CI/CD green again (W-24099831) (3c01350)

v5.0.1

Compare Source

Bug Fixes
  • getting CI/CD green again (W-24099831) (3c01350)

v5.0.0

Compare Source

  • feat!: require Node >=22 (940ad2d)
  • feat!: upgrade core to V5 (01d00b9)
BREAKING CHANGES
  • drop EOL Node versions
  • require Node >=22, drop EOL Node versions

v4.14.0

Compare Source

Features
  • bumping to eslint v10 (W-23473845) (248de04)

4.13.5 (2026-08-14)

Bug Fixes
  • replaced require with dynamic import (W-23807278) (d35e325)

4.13.4 (2026-08-14)

Bug Fixes
  • resolved security vulnerability in powershell path (W-23807278) (911e9d2)

4.13.3 (2026-08-04)

Bug Fixes
  • deps: bump ip-address from 10.2.0 to 10.4.0 (e13240b)

4.13.2 (2026-07-27)

Bug Fixes
  • deps: bump postcss from 8.5.10 to 8.5.23 (169b09a)

4.13.1 (2026-07-27)

Bug Fixes
  • deps: bump tar from 7.5.16 to 7.5.22 (bc0d2d2)

v4.13.5

Compare Source

Bug Fixes
  • replaced require with dynamic import (W-23807278) (d35e325)

v4.13.4

Compare Source

Bug Fixes
  • resolved security vulnerability in powershell path (W-23807278) (911e9d2)

v4.13.3

Compare Source

Bug Fixes
  • deps: bump ip-address from 10.2.0 to 10.4.0 (e13240b)

v4.13.2

Compare Source

Bug Fixes
  • deps: bump postcss from 8.5.10 to 8.5.23 (169b09a)

v4.13.1

Compare Source

Bug Fixes
  • deps: bump tar from 7.5.16 to 7.5.22 (bc0d2d2)

v4.13.0

Compare Source

Features
  • expose root help formatter (644c4aa)

v4.12.0

Compare Source

Features
  • add Args.option() for typed arg options (93139f7)

4.11.14 (2026-07-02)

Bug Fixes

4.11.13 (2026-07-02)

Bug Fixes
  • deps: bump sigstore from 4.1.0 to 4.1.1 (5d7fe54)

4.11.12 (2026-07-02)

Bug Fixes

4.11.11 (2026-06-23)

Bug Fixes
  • deps: bump undici from 6.25.0 to 6.27.0 (319945a)

4.11.10 (2026-06-22)

Bug Fixes
  • deps: bump tinyglobby from 0.2.16 to 0.2.17 (f941872)

4.11.9 (2026-06-21)

Bug Fixes
  • deps: bump tar from 7.5.12 to 7.5.16 (153400e)

4.11.8 (2026-06-21)

Bug Fixes

4.11.7 (2026-06-17)

Bug Fixes

4.11.6 (2026-06-15)

Bug Fixes

4.11.5 (2026-06-15)

Bug Fixes

4.11.4 (2026-05-23)

Bug Fixes
  • deps: bump semver from 7.8.0 to 7.8.1 (65e054c)

4.11.3 (2026-05-15)

Bug Fixes
  • updating tinyglobby dependency [skip-validate-pr] (1dc29ff)

4.11.2 (2026-05-09)

Bug Fixes
  • deps: bump semver from 7.7.4 to 7.8.0 (1471fe3)

4.11.1 (2026-05-07)

Bug Fixes
  • deps: bump ip-address from 10.1.0 to 10.2.0 (e36a6d8)

v4.11.14

Compare Source

Bug Fixes

v4.11.13

Compare Source

Bug Fixes
  • deps: bump sigstore from 4.1.0 to 4.1.1 (5d7fe54)

v4.11.12

Compare Source

Bug Fixes

v4.11.11

Compare Source

Bug Fixes
  • deps: bump undici from 6.25.0 to 6.27.0 (319945a)

v4.11.10

Compare Source

Bug Fixes
  • deps: bump tinyglobby from 0.2.16 to 0.2.17 (f941872)

v4.11.9

Compare Source

Bug Fixes
  • deps: bump tar from 7.5.12 to 7.5.16 (153400e)

v4.11.8

Compare Source

Bug Fixes

v4.11.7

Compare Source

Bug Fixes

v4.11.6

Compare Source

Bug Fixes

v4.11.5

Compare Source

Bug Fixes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.


Note

Medium Risk
Major oclif upgrade can change CLI parsing, help, and error behavior without code edits; risk is mitigated by aligned Node 22 requirement but still warrants smoke-testing mm commands.

Overview
Upgrades @oclif/core in @metamask/wallet-cli from ^4.10.5 to ^5.1.2, documenting the change in the package changelog and refreshing yarn.lock.

There are no CLI source changes in this PR; it is a dependency-only bump for the oclif framework that powers mm (execute, Command, Flags, Args). The lockfile shifts include oclif’s updated transitive deps (e.g. ejs ^6, wsl-utils ^0.4.0) and removal of packages no longer pulled by the older oclif tree.

Note: oclif v5 requires Node ≥22, which matches the wallet-cli’s existing minimum Node bump on the unreleased changelog.

Reviewed by Cursor Bugbot for commit 41428aa. Bugbot is set up for automated code reviews on this repo. Configure here.

@metamask-ci
metamask-ci Bot requested a review from a team as a code owner September 30, 2026 06:20
@metamask-ci
metamask-ci Bot deployed to dependabot September 30, 2026 06:20 Active
@metamask-ci
metamask-ci Bot deployed to default-branch September 30, 2026 06:20 Active
@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​oclif/​core@​4.11.4 ⏵ 5.1.29810010097 +2100

View full report

@socket-security

socket-security Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Caution

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Potential security risk (AI signal): npm powershell-utils is 70.0% likely risky

Notes: This file does not contain explicit malware logic (no exfiltration/persistence in the snippet), but it implements a high-impact dual-use primitive: it base64-encodes caller-provided commands into PowerShell '-EncodedCommand' and executes them with '-ExecutionPolicy Bypass'. If upstream inputs are not tightly controlled, this can be used to run arbitrary PowerShell on the host and is therefore a significant supply-chain security concern at the module API level.

Confidence: 0.70

Severity: 0.75

From: packages/wallet-cli/package.json → npm/@oclif/core@5.1.2 → npm/powershell-utils@0.1.0

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/powershell-utils@0.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
System shell access: npm powershell-utils in module node:child_process

Module: node:child_process

Location: Package overview

From: packages/wallet-cli/package.json → npm/@oclif/core@5.1.2 → npm/powershell-utils@0.1.0

ℹ Read more on: This package | This alert | What is shell access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should avoid accessing the shell which can reduce portability, and make it easier for malicious shell access to be introduced.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/powershell-utils@0.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
System shell access: npm wsl-utils in module node:child_process

Module: node:child_process

Location: Package overview

From: packages/wallet-cli/package.json → npm/@oclif/core@5.1.2 → npm/wsl-utils@0.4.0

ℹ Read more on: This package | This alert | What is shell access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should avoid accessing the shell which can reduce portability, and make it easier for malicious shell access to be introduced.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/wsl-utils@0.4.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm ejs is 66.0% likely to have a medium risk anomaly

Notes: No explicit malicious payload (exfiltration, backdoor, persistence, command execution outside template compilation) is evident in this fragment. However, it has inherently high-risk capabilities: it compiles and executes attacker-influenced templates using new Function, and it can synchronously read additional templates from the filesystem based on resolved include paths/options. If an application supplies untrusted templates, locals that can affect control flow, or unvalidated include paths/views/root, this module can enable serious impact (e.g., code execution via template tags and/or unauthorized file reads depending on path validation). Debug options can also leak generated source via logs.

Confidence: 0.66

Severity: 0.58

From: packages/wallet-cli/package.json → npm/@oclif/core@5.1.2 → npm/ejs@6.0.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ejs@6.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Environment variable access: npm powershell-utils reads SYSTEMROOT

Env Vars: SYSTEMROOT

Location: Package overview

From: packages/wallet-cli/package.json → npm/@oclif/core@5.1.2 → npm/powershell-utils@0.1.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/powershell-utils@0.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Environment variable access: npm powershell-utils reads windir

Env Vars: windir

Location: Package overview

From: packages/wallet-cli/package.json → npm/@oclif/core@5.1.2 → npm/powershell-utils@0.1.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/powershell-utils@0.1.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

@metamask-ci

metamask-ci Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@metamask-ci
metamask-ci Bot force-pushed the renovate/major-oclif-core branch from 43704c7 to 3f1cc2d Compare October 7, 2026 14:54
@metamask-ci
metamask-ci Bot deployed to dependabot October 7, 2026 14:54 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-oclif-core branch from f36a09d to 611ed68 Compare October 8, 2026 06:32
@metamask-ci
metamask-ci Bot deployed to dependabot October 8, 2026 06:32 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-oclif-core branch from 0afa727 to 9a141b4 Compare October 8, 2026 20:12
@metamask-ci
metamask-ci Bot deployed to dependabot October 8, 2026 20:12 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-oclif-core branch from d2b319c to d8a61f1 Compare October 9, 2026 13:05
@metamask-ci
metamask-ci Bot deployed to dependabot October 9, 2026 13:05 Active
@metamask-ci
metamask-ci Bot force-pushed the renovate/major-oclif-core branch from 5e8caf5 to 1d4028f Compare October 11, 2026 06:22
@metamask-ci
metamask-ci Bot deployed to dependabot October 11, 2026 06:22 Active

This branch was successfully deployed

2 active (outdated) deployments
default-branch — 19dfbefe Deployed Sep 30, 2026 by metamask-ci[bot] via Determine whether this PR is a release PR #4917
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants