Skip to content

[Snyk] Security upgrade wagmi from 2.16.3 to 3.0.0 - #71

Closed
Dargon789 wants to merge 1 commit into
mainfrom
snyk-fix-7133526b0072a1712b335f0ce445eb5e
Closed

Dargon789 wants to merge 1 commit into
mainfrom
snyk-fix-7133526b0072a1712b335f0ce445eb5e

Conversation

@Dargon789

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the pnpm dependencies of this project.

Snyk changed the following file(s):

  • packages/miniapp-manifest-generator/package.json
⚠️ Warning
Failed to update the pnpm-lock.yaml, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Access of Resource Using Incompatible Type ('Type Confusion')
SNYK-JS-PREACT-14897824
  853  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Access of Resource Using Incompatible Type ('Type Confusion')

@vercel

vercel Bot commented Jan 11, 2026

Copy link
Copy Markdown

Deployment failed with the following error:

Resource is limited - try again in 16 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/dargon789-forge?upgradeToPro=build-rate-limit

@snyk-io

snyk-io Bot commented Jan 11, 2026

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@gemini-code-assist

Copy link
Copy Markdown

Summary of Changes

Hello @Dargon789, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request, automatically generated by Snyk, aims to enhance the project's security posture by upgrading the wagmi dependency to its latest major version, 3.0.0. This upgrade specifically targets and resolves a critical 'Type Confusion' vulnerability. Reviewers should pay close attention to potential breaking changes introduced by the major version bump and ensure the pnpm-lock.yaml is manually updated.

Highlights

  • Security Vulnerability Fix: This PR addresses a critical security vulnerability, "Access of Resource Using Incompatible Type ('Type Confusion')" (SNYK-JS-PREACT-14897824), identified by Snyk with a score of 853.
  • Dependency Upgrade: The wagmi package has been upgraded from version 2.16.3 to 3.0.0 in packages/miniapp-manifest-generator/package.json to remediate the vulnerability.
  • Manual Lockfile Update Required: Snyk was unable to automatically update the pnpm-lock.yaml file, requiring a manual update before merging this PR.
  • Potential Breaking Changes: The upgrade to wagmi version 3.0.0 is a major version bump, which may introduce breaking changes that need to be verified.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request from Snyk aims to fix a security vulnerability by upgrading wagmi from version 2 to 3. However, this is a major version upgrade with breaking changes that will break the application. The primary issue is a peer dependency conflict with @coinbase/onchainkit, which requires wagmi v2. This is likely why the pnpm-lock.yaml file failed to update. Additionally, the PR lacks the necessary code changes to adapt to wagmi v3's new APIs. I've added a critical review comment suggesting to revert this change until a comprehensive migration plan is in place.

"react-dom": "19.1.0",
"viem": "^2.31.6",
"wagmi": "^2.16.3"
"wagmi": "^3.0.0"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

critical

This major version upgrade of wagmi from v2 to v3 will break the application. The PR metadata itself flags this as a breaking change (isBreakingChange:true). There are two critical issues:

  1. Peer Dependency Conflict: The @coinbase/onchainkit package, which this package depends on, has a peer dependency on wagmi@^2.x. Upgrading wagmi to ^3.0.0 creates a dependency conflict. This is almost certainly why pnpm-lock.yaml failed to update, as mentioned in the PR description.

  2. Breaking API Changes: A major version upgrade implies breaking changes. Code using wagmi APIs, such as the useSignMessage hook in src/hooks/useSignManifest.ts, would need to be refactored to work with wagmi v3. This PR does not include these necessary code updates.

Because of these issues, this change will break the application. I recommend reverting this upgrade. A proper fix would involve finding a version of @coinbase/onchainkit that supports wagmi v3, upgrading both, and refactoring the code that uses them.

Suggested change
"wagmi": "^3.0.0"
"wagmi": "^2.16.3"

@github-actions

Copy link
Copy Markdown

Stale pull request message

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants