Skip to content

deps(npm-dependencies): update npm dependencies - #278

Closed
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/npm-dependencies
Closed

deps(npm-dependencies): update npm dependencies#278
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/npm-dependencies

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@0x/contract-artifacts-v2 (source) ^2.2.2^3.0.0 age adoption passing confidence
@nomicfoundation/hardhat-verify (source) ^2.0.1^3.0.0 age adoption passing confidence
@nomiclabs/hardhat-waffle 2.0.52.0.6 age adoption passing confidence
@safe-global/api-kit ^1.3.0^5.0.0 age adoption passing confidence
@safe-global/protocol-kit ^1.2.0^8.0.0 age adoption passing confidence
@safe-global/safe-core-sdk-types ^2.2.0^5.0.0 age adoption passing confidence
@slack/web-api (source) ^6.9.0^8.0.0 age adoption passing confidence
@tenderly/hardhat-tenderly (source) ~1.1.6~2.6.0 age adoption passing confidence
@types/chai (source) ^4.3.4^5.0.0 age adoption passing confidence
@types/chai-as-promised (source) ^7.1.5^8.0.0 age adoption passing confidence
@types/debug (source) 4.1.74.1.13 age adoption passing confidence
@types/mocha (source) 10.0.110.0.10 age adoption passing confidence
@types/node (source) ^18.15.11^26.0.0 age adoption passing confidence
@types/sinon (source) ^10.0.13^22.0.0 age adoption passing confidence
@types/yargs (source) 17.0.2417.0.35 age adoption passing confidence
@typescript-eslint/eslint-plugin (source) ^5.58.0^8.0.0 age adoption passing confidence
@typescript-eslint/parser (source) ^5.58.0^8.0.0 age adoption passing confidence
chai (source) ^4.3.7^6.0.0 age adoption passing confidence
chai-as-promised ^7.1.1^8.0.0 age adoption passing confidence
chalk ^4.1.2^6.0.0 age adoption passing confidence
debug 4.3.44.4.3 age adoption passing confidence
dotenv ^16.0.3^17.0.0 age adoption passing confidence
eslint (source) ^8.38.0^10.0.0 age adoption passing confidence
eslint-config-prettier ^8.8.0^10.0.0 age adoption passing confidence
eslint-plugin-import 2.27.52.32.0 age adoption passing confidence
eslint-plugin-no-only-tests 3.1.03.4.0 age adoption passing confidence
eslint-plugin-prettier ^4.2.1^5.0.0 age adoption passing confidence
ethereum-waffle ^3.4.4^4.0.0 age adoption passing confidence
ethers (source) ^5.4.0^5.4.0 || ^6.0.0 age adoption passing confidence
ethers (source) ^5.7.2^6.0.0 age adoption passing confidence
globby ^11.0.4^16.0.0 age adoption passing confidence
hardhat (source) ^2.13.1^3.0.0 age adoption passing confidence
hardhat-deploy (source) ^0.11.26^2.0.0 age adoption passing confidence
hardhat-gas-reporter ^1.0.9^2.0.0 age adoption passing confidence
prettier (source) ^2.8.7^3.0.0 age adoption passing confidence
prettier-plugin-solidity ^1.1.3^2.0.0 age adoption passing confidence
sinon (source) ^15.0.3^22.0.0 age adoption passing confidence
solhint (source) ^5.0.0^6.0.0 age adoption passing confidence
solhint-plugin-prettier ^0.0.5^0.1.0 age adoption passing confidence
solidity-coverage 0.8.20.8.17 age adoption passing confidence
ts-node (source) 10.9.110.9.2 age adoption passing confidence
typescript (source) ^5.0.4^7.0.0 age adoption passing confidence
yargs (source) ^17.7.1^18.0.0 age adoption passing confidence

Release Notes

0xProject/protocol (@​0x/contract-artifacts-v2)

v3.19.0

Compare Source

v3.18.3

Compare Source

v3.18.2

Compare Source

v3.18.1

Compare Source

v3.18.0

Compare Source

v3.17.0

Compare Source

v3.16.0

Compare Source

v3.15.1

Compare Source

v3.15.0

Compare Source

v3.14.2

Compare Source

v3.14.1

Compare Source

v3.14.0

Compare Source

v3.13.0

Compare Source

v3.12.0

Compare Source

v3.11.1

Compare Source

v3.11.0

Compare Source

v3.10.0

Compare Source

v3.9.1

Compare Source

v3.9.0

Compare Source

v3.8.2

Compare Source

v3.8.1

Compare Source

v3.8.0

Compare Source

v3.7.1

Compare Source

v3.7.0

Compare Source

v3.6.1

Compare Source

v3.6.0

Compare Source

v3.5.0

Compare Source

v3.4.1

Compare Source

v3.4.0

Compare Source

v3.3.0

Compare Source

v3.2.0

Compare Source

v3.1.0

Compare Source

v3.0.0

Compare Source

NomicFoundation/hardhat (@​nomicfoundation/hardhat-verify)

v3.0.22

Compare Source

Patch Changes

v3.0.21

Compare Source

Patch Changes

v3.0.20

Compare Source

Patch Changes
  • #​8374 c67a5bb Thanks @​gultekinmakif! - Running verify against local development networks (chain IDs 31337 and 1337) now fails with a clear NETWORK_NOT_SUPPORTED error.

v3.0.19

Compare Source

Patch Changes

v3.0.18

Compare Source

Patch Changes

v3.0.17

Compare Source

Patch Changes

v3.0.16

Compare Source

Patch Changes

v3.0.15

Compare Source

Patch Changes

v3.0.14

Compare Source

Patch Changes

v3.0.13

Compare Source

Patch Changes

v3.0.12

Compare Source

Patch Changes

v3.0.11

Compare Source

Patch Changes
  • 6674b00: Bump hardhat-utils major

v3.0.10

Compare Source

Patch Changes
  • 577e516: Expose an Etherscan instance through the verification property on network.connect() for advanced use cases. This version also adds a customApiCall method to the Etherscan instance, allowing custom requests to the Etherscan API (#​7644)

v3.0.9

Compare Source

Patch Changes

v3.0.8

Compare Source

Patch Changes

v3.0.7

Compare Source

Patch Changes
  • 29acf32: Added fallback for chains not included in chain descriptors (#​7657)

v3.0.6

Compare Source

Patch Changes

v3.0.5

Compare Source

Patch Changes
  • d45234d: Fixed Etherscan verification failures by removing hardcoded v1 API URLs from chain descriptors (#​7623). Also enhanced config resolution to support partial overrides in block explorer configurations for future extensibility.
  • 558ac5b: Update installation and config instructions

v3.0.4

Compare Source

Patch Changes
  • cbcb5ce: Fixed hardhat-verify by using apiUrl from etherscanConfig for verification (#​7509)

v3.0.3

Compare Source

Patch Changes
  • d25eec4: Fixed a bug that prevented verification of contracts imported from npm modules (#​7442)

v3.0.2

Compare Source

Patch Changes
  • a475780: Added automatic proxy detection for hardhat-verify and fixed case-insensitive proxy environment variables for network requests (#​7407)

v3.0.1

Compare Source

Patch Changes

v3.0.0

Compare Source

Major Changes
  • 29cc141: First release of Hardhat 3!

v2.1.3

Compare Source

v2.1.2

Compare Source

This release is a small bug fix for Sourcify verification.

Changes
  • 2dccd4e: Pass all sources in the contract metadata for verification in Sourcify. Thanks @​natanasow! (#​7070)
  • 9d10226: Links in the code and READMEs updated to point to the Hardhat 2 documentation and resources

💡 The Nomic Foundation is hiring! Check our open positions.


v2.1.1

Compare Source

Patch Changes
  • [11ee260

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, on day 1 of the month (* 0-3 1 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 1, 2026 01:21
@socket-security

socket-security Bot commented Sep 1, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​safe-global/​safe-core-sdk-types@​2.2.0 ⏵ 5.1.098 +210081 +1250100
Updated@​typescript-eslint/​parser@​5.58.0 ⏵ 8.69.09910072 +298100
Updatedsolhint-plugin-prettier@​0.0.5 ⏵ 0.1.0971007479100
Updated@​types/​chai-as-promised@​7.1.5 ⏵ 8.0.2100 +11007480100
Updated@​types/​yargs@​17.0.24 ⏵ 17.0.35100 +11007583100
Updated@​types/​sinon@​10.0.13 ⏵ 22.0.01001007688 +7100
Updated@​types/​chai@​4.3.4 ⏵ 5.2.31001007681100
Updated@​types/​mocha@​10.0.1 ⏵ 10.0.101001007780100
Updated@​nomiclabs/​hardhat-waffle@​2.0.5 ⏵ 2.0.69710092 +180100
Updatedhardhat-gas-reporter@​1.0.9 ⏵ 2.3.098 -1100100 +180100
Updated@​typescript-eslint/​eslint-plugin@​5.58.0 ⏵ 8.69.09910080 +298100
Updatedethereum-waffle@​3.4.4 ⏵ 4.0.109710010080100
Updated@​tenderly/​hardhat-tenderly@​1.1.6 ⏵ 2.6.081 -7100100 +194 +3100 +31
Updated@​types/​debug@​4.1.7 ⏵ 4.1.1310010087 -281100
Updated@​types/​node@​8.10.66 ⏵ 26.4.010010081 +396100
Updated@​0x/​contract-artifacts@​2.2.2 ⏵ 3.19.081 +210095 +486 +1100
Updatedts-node@​10.9.1 ⏵ 10.9.29610010082100
Updatedhardhat@​2.13.1 ⏵ 3.15.099 +810082 -696100 +20
Updatedchai-as-promised@​7.1.1 ⏵ 8.0.2100 +1100100 +183100
Updatedchai@​4.3.7 ⏵ 6.2.2100 +110010083 -2100
Updatedeslint-plugin-no-only-tests@​3.1.0 ⏵ 3.4.0100100100 +1083100
Updatedeslint-config-prettier@​8.8.0 ⏵ 10.1.8100 +1100100 +2983 -3100
Updatedeslint-plugin-import@​2.27.5 ⏵ 2.32.098 +1110010083100
Updatedsolidity-coverage@​0.8.2 ⏵ 0.8.1798100100 +184100
Updatedchalk@​1.1.3 ⏵ 6.0.0100 +1100100 +184100
Updatedethers@​5.7.2 ⏵ 5.8.099 +1100100 +186100
Updateddotenv@​16.0.3 ⏵ 17.4.299100100 +187100
Updatedyargs@​17.7.1 ⏵ 18.1.099 +1100100 +188 -1100
Updated@​safe-global/​api-kit@​1.3.0 ⏵ 5.0.399 +110088 -1294 +4100
Updatedtypescript@​5.0.4 ⏵ 7.0.29910089 -1100 +5100 +10
Updatedglobby@​11.0.4 ⏵ 16.2.499100100 +190 +7100
Updatedeslint-plugin-prettier@​4.2.1 ⏵ 5.5.6100 +110010091100
See 9 more rows in the dashboard

View full report

@socket-security

socket-security Bot commented Sep 1, 2026

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @noble/hashes is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: yarn.locknpm/solidity-coverage@0.8.17npm/@safe-global/protocol-kit@8.0.6npm/@safe-global/api-kit@5.0.3npm/hardhat-gas-reporter@2.3.0npm/@noble/hashes@1.8.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@noble/hashes@1.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @noble/hashes is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: yarn.locknpm/solidity-coverage@0.8.17npm/@safe-global/protocol-kit@8.0.6npm/@safe-global/api-kit@5.0.3npm/hardhat-gas-reporter@2.3.0npm/@noble/hashes@1.8.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@noble/hashes@1.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm encoding-down is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: yarn.locknpm/ethereum-waffle@4.0.10npm/encoding-down@6.3.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/encoding-down@6.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/npm-dependencies branch from 0cfe0b9 to 622d528 Compare September 1, 2026 10:58
@renovate

renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@igorroncevic

Copy link
Copy Markdown
Contributor

Closing, as we will not update major version of dev or NPM packages. New PR to enforce that rule is coming.

@github-actions github-actions Bot locked and limited conversation to collaborators Sep 1, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant