Skip to content

Upgrade noble and scure dependencies to v2.2#4588

Open
paulmillr wants to merge 1 commit into
wevm:mainfrom
paulmillr:main
Open

Upgrade noble and scure dependencies to v2.2#4588
paulmillr wants to merge 1 commit into
wevm:mainfrom
paulmillr:main

Conversation

@paulmillr
Copy link
Copy Markdown
Contributor

@paulmillr paulmillr commented May 8, 2026

See #4575. Feel free to copy / edit / incorporate into your own branch. Feel free to delay until v3 (this is compat-breaking because of node.js >=20.19 requirement) is released.

Duplicating text from 4575:

We now have stable noble v2.2.x.

  • Reason 1: The packages had undergone through a very detailed self-audit, which found more minor & medium-severity issues than all previous third party audits combined.

  • Reason 2: Because of the LLMs, attackers are having a breakthrough and it would be great to have Viem line up with the latest, and the only security-relevant noble versions. Older versions would degrade and probably get broken sooner.

  • hashes

  • curves

@vercel
Copy link
Copy Markdown

vercel Bot commented May 8, 2026

@paulmillr is attempting to deploy a commit to the Wevm Team on Vercel.

A member of the Team first needs to authorize it.

@changeset-bot
Copy link
Copy Markdown

changeset-bot Bot commented May 8, 2026

⚠️ No Changeset found

Latest commit: a32044d

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​paulmillr/​trusted-setups@​0.1.2 ⏵ 0.3.08110094 +284 +4100
Updatedmicro-eth-signer@​0.14.0 ⏵ 0.18.1100 +110010084100
Added@​scure/​bip39@​2.2.010010010086100
Added@​scure/​bip32@​2.2.010010010087100
Updated@​noble/​hashes@​1.7.2 ⏵ 2.2.0100 +110010088100
Updated@​noble/​curves@​1.8.2 ⏵ 2.2.010010010089100

View full report

@pkg-pr-new
Copy link
Copy Markdown

pkg-pr-new Bot commented May 8, 2026

Open in StackBlitz

npm i https://pkg.pr.new/viem@4588

commit: a32044d

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant