Skip to content

fix: update dependencies#20997

Merged
alexghr merged 7 commits intomerge-train/spartanfrom
nikita/update-dependencies
Mar 5, 2026
Merged

fix: update dependencies#20997
alexghr merged 7 commits intomerge-train/spartanfrom
nikita/update-dependencies

Conversation

@deffrian
Copy link
Collaborator

@deffrian deffrian commented Mar 2, 2026

Ref: A-459

Most packages are updated via resolutions. Except minimatch, it's used by multiple dependencies with different major versions.

boxes/yarn.lock still has minimatch 9.0.3 pinned by @typescript-eslint/typescript-estree@6.21.0 (from
boxes/boxes/react using @typescript-eslint v6). Fixing this requires upgrading boxes/react to @typescript-eslint v8.

yarn.lock Package Old Version New Version
yarn-project/yarn.lock rollup 4.52.3 4.59.0
boxes/yarn.lock rollup 4.41.1 4.59.0
playground/yarn.lock rollup 4.50.1 4.59.0
barretenberg/acir_tests/yarn.lock basic-ftp 5.0.5 5.2.0
docs/yarn.lock h3 1.15.4 1.15.5
barretenberg/docs/yarn.lock h3 1.15.3 1.15.5
yarn-project/yarn.lock systeminformation 5.23.8 5.31.1
yarn-project/yarn.lock node-forge 1.3.1 1.3.3
boxes/yarn.lock node-forge 1.3.1 1.3.3
docs/yarn.lock node-forge 1.3.1 1.3.3
barretenberg/acir_tests/yarn.lock node-forge 1.3.1 1.3.3
barretenberg/docs/yarn.lock node-forge 1.3.1 1.3.3
yarn-project/yarn.lock koa 2.16.2 2.16.4
yarn-project/yarn.lock serve 14.2.4 14.2.6
boxes/yarn.lock serve 14.2.4 14.2.6
barretenberg/acir_tests/yarn.lock serve 14.2.4 14.2.6
yarn-project/yarn.lock minimatch 3.1.2 3.1.5
boxes/yarn.lock minimatch 3.1.2 3.1.5
docs/yarn.lock minimatch 3.1.2 3.1.5
playground/yarn.lock minimatch 3.1.2 3.1.5
barretenberg/docs/yarn.lock serve-handler 6.1.6 6.1.7
docs/yarn.lock serve-handler 6.1.6 6.1.7
docs/yarn.lock minimatch 3.1.2 3.1.5
yarn-project/yarn.lock minimatch 5.1.6 5.1.9
boxes/yarn.lock minimatch 5.1.6 5.1.9
docs/yarn.lock minimatch 5.1.6 5.1.9
yarn-project/yarn.lock minimatch 9.0.5 9.0.9
docs/yarn.lock minimatch 9.0.5 9.0.9
barretenberg/acir_tests/yarn.lock minimatch 9.0.5 9.0.9
boxes/yarn.lock minimatch 9.0.5 9.0.9
yarn-project/yarn.lock serialize-javascript 6.0.2 7.0.4
boxes/yarn.lock serialize-javascript 6.0.2 7.0.4
docs/yarn.lock serialize-javascript 6.0.2 7.0.4
barretenberg/acir_tests/yarn.lock serialize-javascript 6.0.2 7.0.4
barretenberg/docs/yarn.lock serialize-javascript 6.0.2 7.0.4
boxes/yarn.lock axios 1.12.2 1.13.6
docs/yarn.lock axios 1.12.2 1.13.6

@socket-security
Copy link

socket-security bot commented Mar 2, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​serve@​14.2.4 ⏵ 14.2.699100100 +186100
Updatednpm/​koa@​2.16.2 ⏵ 2.16.498 +1100 +18100 +195 -1100

View full report

@mralj
Copy link
Contributor

mralj commented Mar 5, 2026

Went through the diff, additions are just resolutions and some vestion bumps, lgtm :)

@alexghr alexghr mentioned this pull request Mar 5, 2026
@alexghr alexghr merged commit 215ac2d into merge-train/spartan Mar 5, 2026
10 checks passed
@alexghr alexghr deleted the nikita/update-dependencies branch March 5, 2026 14:04
AztecBot pushed a commit that referenced this pull request Mar 6, 2026
Ref: A-459

Most packages are updated via resolutions. Except `minimatch`, it's used by multiple dependencies with different major versions.

boxes/yarn.lock still has minimatch 9.0.3 pinned by @typescript-eslint/typescript-estree@6.21.0 (from
boxes/boxes/react using @typescript-eslint v6). Fixing this requires upgrading boxes/react to @typescript-eslint v8.

| yarn.lock                         | Package              | Old Version | New Version |
|-----------------------------------|----------------------|-------------|-------------|
| yarn-project/yarn.lock            | rollup               | 4.52.3      | 4.59.0      |
| boxes/yarn.lock                   | rollup               | 4.41.1      | 4.59.0      |
| playground/yarn.lock              | rollup               | 4.50.1      | 4.59.0      |
| barretenberg/acir_tests/yarn.lock | basic-ftp            | 5.0.5       | 5.2.0       |
| docs/yarn.lock                    | h3                   | 1.15.4      | 1.15.5      |
| barretenberg/docs/yarn.lock       | h3                   | 1.15.3      | 1.15.5      |
| yarn-project/yarn.lock            | systeminformation    | 5.23.8      | 5.31.1      |
| yarn-project/yarn.lock            | node-forge           | 1.3.1       | 1.3.3       |
| boxes/yarn.lock                   | node-forge           | 1.3.1       | 1.3.3       |
| docs/yarn.lock                    | node-forge           | 1.3.1       | 1.3.3       |
| barretenberg/acir_tests/yarn.lock | node-forge           | 1.3.1       | 1.3.3       |
| barretenberg/docs/yarn.lock       | node-forge           | 1.3.1       | 1.3.3       |
| yarn-project/yarn.lock            | koa                  | 2.16.2      | 2.16.4      |
| yarn-project/yarn.lock            | serve                | 14.2.4      | 14.2.6      |
| boxes/yarn.lock                   | serve                | 14.2.4      | 14.2.6      |
| barretenberg/acir_tests/yarn.lock | serve                | 14.2.4      | 14.2.6      |
| yarn-project/yarn.lock            | minimatch            | 3.1.2       | 3.1.5       |
| boxes/yarn.lock                   | minimatch            | 3.1.2       | 3.1.5       |
| docs/yarn.lock                    | minimatch            | 3.1.2       | 3.1.5       |
| playground/yarn.lock              | minimatch            | 3.1.2       | 3.1.5       |
| barretenberg/docs/yarn.lock       | serve-handler        | 6.1.6       | 6.1.7       |
| docs/yarn.lock                    | serve-handler        | 6.1.6       | 6.1.7       |
| docs/yarn.lock                    | minimatch            | 3.1.2       | 3.1.5       |
| yarn-project/yarn.lock            | minimatch            | 5.1.6       | 5.1.9       |
| boxes/yarn.lock                   | minimatch            | 5.1.6       | 5.1.9       |
| docs/yarn.lock                    | minimatch            | 5.1.6       | 5.1.9       |
| yarn-project/yarn.lock            | minimatch            | 9.0.5       | 9.0.9       |
| docs/yarn.lock                    | minimatch            | 9.0.5       | 9.0.9       |
| barretenberg/acir_tests/yarn.lock | minimatch            | 9.0.5       | 9.0.9       |
| boxes/yarn.lock                   | minimatch            | 9.0.5       | 9.0.9       |
| yarn-project/yarn.lock            | serialize-javascript | 6.0.2       | 7.0.4       |
| boxes/yarn.lock                   | serialize-javascript | 6.0.2       | 7.0.4       |
| docs/yarn.lock                    | serialize-javascript | 6.0.2       | 7.0.4       |
| barretenberg/acir_tests/yarn.lock | serialize-javascript | 6.0.2       | 7.0.4       |
| barretenberg/docs/yarn.lock       | serialize-javascript | 6.0.2       | 7.0.4       |
| boxes/yarn.lock                   | axios                | 1.12.2      | 1.13.6      |
| docs/yarn.lock                    | axios                | 1.12.2      | 1.13.6      |
@AztecBot
Copy link
Collaborator

AztecBot commented Mar 6, 2026

✅ Successfully backported to backport-to-v4-staging #21187.

github-merge-queue bot pushed a commit that referenced this pull request Mar 6, 2026
BEGIN_COMMIT_OVERRIDE
test: update proving-real test to mbps (#20991)
chore: epoch proving log analyzer (#21033)
chore: update pause script to allow resume (#21032)
feat: price bump for RPC transaction replacement (#20806)
refactor: remove update checker, retain version checks (#20898)
fix: (A-592) p2p client proposal tx collector test (#20998)
refactor: use publishers-per-pod in deployments (#21039)
chore: web3signer refreshes keystore (#21045)
feat(sequencer): set block building limits from checkpoint limits
(#20974)
chore(e2e): fix e2e bot L1 tx nonce reuse (#21052)
feat: Update L1 to L2 message APIs (#20913)
fix: (A-589) epochs l1 reorgs test (#20999)
feat(sequencer): add SEQ_MAX_TX_PER_CHECKPOINT config (#21016)
fix: drop --pid=host from docker_isolate (#21081)
feat: standby mode for prover broker (#21098)
fix(p2p): remove default block handler in favor of block handler
(#21105)
feat(validator): add VALIDATOR_ env vars for independent block limits
(#21060)
refactor(p2p): decouple proposal validators from base class via
composition (#21075)
feat: additional validation in public setup allowlist (onlySelf + null
msg sender) (#21122)
fix: (A-591) aztecProofSubmissionEpochs incorrectly named as
aztecProofSubmissionWindow (#21108)
refactor(sequencer): rename SEQ_GAS_PER_BLOCK_ALLOCATION_MULTIPLIER to
SEQ_PER_BLOCK_ALLOCATION_MULTIPLIER (#21125)
fix: unbound variable in check_doc_references.sh with set -u (#21126)
feat: calldata length validation of public setup function allowlist
(#21139)
fix: include mismatched values in tx metadata validation errors (#21147)
feat: single-node implementation of slash-protection signer (#20894)
feat: Remove non-protocol contracts from public setup allowlist (#21154)
chore: More updated Alpha configuration (#21155)
chore: tally slashing pruning improvements (#21161)
fix: update dependencies (#20997)
fix: omit bigint priceBumpPercentage from IPC config in testbench worker
(#21169)
refactor(p2p): (A-588) maintain sorted array in tx pool instead of
sorting on read (#21079)
fix(p2p): report most severe failure in runValidations (#21185)
fix: use dedicated L1 account for bot bridge resume tests to avoid nonce
race (#21148)
fix: parse error.message in formatViemError (#21163)
fix: bump lighthouse consensus client v7.1.0 -> v8.0.1 (#21170)
chore: code decuplication + refactor (public setup allowlist) (#21200)
END_COMMIT_OVERRIDE
ludamad added a commit that referenced this pull request Mar 10, 2026
BEGIN_COMMIT_OVERRIDE
chore: chonk proof compression poc (#20645)
feat: Update L1 to L2 message APIs (#20913)
fix: adapt chonk proof compression for v4 Translator layout (#21067)
fix: omit bigint priceBumpPercentage from IPC config in testbench worker
(#21086)
feat: standby mode for prover broker (#21098)
fix(p2p): remove default block handler in favor of block handler
(#21105)
chore: prepare barretenberg-rs for crates.io publishing (#20496)
feat: reenable function selectors + additional validation in public
setup allowlist (backport #20909, #21122) (#21129)
chore: remove stale aes comments (#21133)
chore: remove auto-tag job (#21127)
feat: calldata length validation of public setup function allowlist
(#21139)
feat: run AVM NAPI simulations on dedicated threads instead of libuv
pool (#21138)
feat: Remove non-protocol contracts from public setup allowlist (#21154)
feat!: Expose offchain effects when simulating/sending txs (backport
#20563) (#21110)
chore: bump minor version (#21171)
chore: backport #21161 (tally slashing pruning improvements) to v4
(#21166)
chore: More updated Alpha configuration (backport #21155) (#21165)
fix(p2p): report most severe failure in runValidations (#21185)
feat: add ergonomic conversions for Noir's `Option<T>` (#21107)
docs: clarifying Noir fields vs struct fields in event metadata (#21172)
fix: bump lighthouse consensus client v7.1.0 -> v8.0.1 (#21170)
fix: update dependencies (#20997)
chore: New alpha-net environment (#20800) (#21202)
chore: code decuplication + refactor (public setup allowlist) (#21200)
feat: mask all ciphertext fields with Poseidon2-derived values (backport
#21009) (#21140)
chore: disable sponsored FPC in testnet (#21235)
feat!: exposing pub event pagination on wallet (#21197)
refactor(pxe): narrow tryGetPublicKeysAndPartialAddress return type
(backport #21208) (#21236)
feat: orchestrator enqueues via serial queue (#21247)
feat: rollup mana limit gas validation (#21219)
chore: deploy SPONSORED_FPC in test networks (#21254)
fix(sequencer): fix log when not enough txs (#21297)
END_COMMIT_OVERRIDE

---------

Co-authored-by: ledwards2225 <ledwards2225@users.noreply.github.com>
Co-authored-by: PhilWindle <PhilWindle@users.noreply.github.com>
Co-authored-by: ludamad <adam.domurad@gmail.com>
Co-authored-by: mrzeszutko <mrzeszutko@users.noreply.github.com>
Co-authored-by: spalladino <spalladino@users.noreply.github.com>
Co-authored-by: johnathan79717 <johnathan79717@users.noreply.github.com>
Co-authored-by: nventuro <nventuro@users.noreply.github.com>
Co-authored-by: alexghr <alexghr@users.noreply.github.com>
Co-authored-by: AztecBot <AztecBot@users.noreply.github.com>
Co-authored-by: Martin Verzilli <martin@aztec-labs.com>
Co-authored-by: PhilWindle <60546371+PhilWindle@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: mverzilli <mverzilli@users.noreply.github.com>
Co-authored-by: benesjan <benesjan@users.noreply.github.com>
Co-authored-by: danielntmd <danielntmd@users.noreply.github.com>
Co-authored-by: deffrian <deffrian@users.noreply.github.com>
Co-authored-by: benesjan <janbenes1234@gmail.com>
ludamad added a commit that referenced this pull request Mar 11, 2026
BEGIN_COMMIT_OVERRIDE
chore: chonk proof compression poc (#20645)
feat: Update L1 to L2 message APIs (#20913)
fix: adapt chonk proof compression for v4 Translator layout (#21067)
fix: omit bigint priceBumpPercentage from IPC config in testbench worker
(#21086)
feat: standby mode for prover broker (#21098)
fix(p2p): remove default block handler in favor of block handler
(#21105)
chore: prepare barretenberg-rs for crates.io publishing (#20496)
feat: reenable function selectors + additional validation in public
setup allowlist (backport #20909, #21122) (#21129)
chore: remove stale aes comments (#21133)
chore: remove auto-tag job (#21127)
feat: calldata length validation of public setup function allowlist
(#21139)
feat: run AVM NAPI simulations on dedicated threads instead of libuv
pool (#21138)
feat: Remove non-protocol contracts from public setup allowlist (#21154)
feat!: Expose offchain effects when simulating/sending txs (backport
#20563) (#21110)
chore: bump minor version (#21171)
chore: backport #21161 (tally slashing pruning improvements) to v4
(#21166)
chore: More updated Alpha configuration (backport #21155) (#21165)
fix(p2p): report most severe failure in runValidations (#21185)
feat: add ergonomic conversions for Noir's `Option<T>` (#21107)
docs: clarifying Noir fields vs struct fields in event metadata (#21172)
fix: bump lighthouse consensus client v7.1.0 -> v8.0.1 (#21170)
fix: update dependencies (#20997)
chore: New alpha-net environment (#20800) (#21202)
chore: code decuplication + refactor (public setup allowlist) (#21200)
feat: mask all ciphertext fields with Poseidon2-derived values (backport
#21009) (#21140)
chore: disable sponsored FPC in testnet (#21235)
feat!: exposing pub event pagination on wallet (#21197)
refactor(pxe): narrow tryGetPublicKeysAndPartialAddress return type
(backport #21208) (#21236)
feat: orchestrator enqueues via serial queue (#21247)
feat: rollup mana limit gas validation (#21219)
chore: deploy SPONSORED_FPC in test networks (#21254)
fix(sequencer): fix log when not enough txs (#21297)
fix: Simulate gas in n tps test. Set min txs per block to 1 (backport
#21312) (#21329)
fix(log): do not log validation error if unregistered handler (#21111)
fix(node): fix index misalignment in findLeavesIndexes (#21327)
fix: limit parallel blocks in prover to max AVM parallel simulations
(#21320)
fix: use native sha256 to speed up proving job id generation (#21292)
fix(validator): wait for l1 sync before processing block proposals
(#21336)
fix(txpool): cap priority fee with max fees when computing priority
(#21279)
chore: reduce severity of errors due to HA node not acquiring signature
(#21311)
fix: (A-643) add buffer to maxFeePerBlobGas for gas estimation and fix
bump loop truncation (#21323)
END_COMMIT_OVERRIDE
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants