Skip to content

Conversation

@Dargon789
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade viem from 2.13.1 to 2.38.3.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 252 versions ahead of your current version.

  • The recommended version was released a month ago.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade viem from 2.13.1 to 2.38.3.

See this package in yarn:
viem

See this project in Snyk:
https://app.snyk.io/org/apichanmittare/project/2749ecc3-509c-4550-ba7a-f6f899e9eb4c?utm_source=github&utm_medium=referral&page=upgrade-pr
@snyk-io
Copy link

snyk-io bot commented Nov 12, 2025

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@gemini-code-assist
Copy link

Summary of Changes

Hello @Dargon789, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request focuses on a critical dependency upgrade for the viem library, moving from version 2.13.1 to 2.38.3. This automated update, initiated by Snyk, is essential for maintaining the project's security posture and ensuring compatibility with the latest features and bug fixes from the viem ecosystem. The changes primarily involve updating version specifications in package.json and regenerating yarn.lock to reflect the new dependency tree.

Highlights

  • Viem Dependency Upgrade: The viem library has been upgraded from version 2.13.1 to 2.38.3. This is a significant update, spanning 252 versions, and aims to keep the project's dependencies current.
  • Automated Dependency Management: This pull request was automatically generated by Snyk to ensure dependencies are up-to-date, which helps in fixing existing vulnerabilities and quickly addressing new ones.
  • Sub-dependency Updates: Alongside the viem upgrade, several related sub-dependencies in yarn.lock have been updated, including @adraffy/ens-normalize, @noble/curves, @noble/hashes, @scure/bip32, @scure/bip39, abitype, isows, ox, and ws.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

Copy link

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request, automatically generated by Snyk, upgrades the viem package from version 2.13.1 to 2.38.3. This is a significant update, spanning 252 versions. While Snyk has marked this as a non-breaking change, the large version jump warrants careful testing to ensure no regressions are introduced. The yarn.lock file has been updated accordingly, reflecting changes in transitive dependencies. A notable point is that this project will now have two different versions of viem in its dependency tree, which could increase bundle size. It might be beneficial to investigate if @safe-global/safe-apps-sdk can be updated to use a newer version of viem to deduplicate this dependency.

"rehype-raw": "^7.0.0",
"sharp": "^0.32.6",
"viem": "^2.13.1",
"viem": "^2.38.3",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

This is a very large version jump for viem (from 2.13.1 to 2.38.3). Although it's not a major version change and Snyk reports no breaking changes, it's critical to perform thorough regression testing to ensure the application continues to function as expected. Given the extensive changes across 252 versions, there's a high risk of subtle bugs or performance regressions.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants