Skip to content

release: 13.43.0 - #45055

Merged
tommasini merged 167 commits into
stablefrom
release/13.43.0
Aug 12, 2026
Merged

tommasini merged 167 commits into
stablefrom
release/13.43.0

Conversation

@metamaskbot

@metamaskbot metamaskbot commented Jul 30, 2026 •

Copy link
Copy Markdown
Collaborator

🚀 v13.43.0 Testing & Release Quality Process

Hi Team,
As part of our new MetaMask Release Quality Process, here’s a quick overview of the key processes, testing strategies, and milestones to ensure a smooth and high-quality deployment.


📋 Key Processes

Testing Strategy

  • Developer Teams:
    Conduct regression and exploratory testing for your functional areas, including automated and manual tests for critical workflows.
  • QA Team:
    Focus on exploratory testing across the wallet, prioritize high-impact areas, and triage any Sentry errors found during testing.
  • Customer Success Team:
    Validate new functionalities and provide feedback to support release monitoring.

GitHub Signoff

  • Each team must sign off on the Release Candidate (RC) via GitHub by the end of the validation timeline (Tuesday EOD PT).
  • Ensure all tests outlined in the Testing Plan are executed, and any identified issues are addressed.

Issue Resolution

  • Resolve all Release Blockers (Sev0 and Sev1) by Tuesday EOD PT.
  • For unresolved blockers, PRs may be reverted, or feature flags disabled to maintain release quality and timelines.

Cherry-Picking Criteria

  • Only critical fixes meeting outlined criteria will be cherry-picked.
  • Developers must ensure these fixes are thoroughly reviewed, tested, and merged by Tuesday EOD PT.

🗓️ Timeline and Milestones

  1. Today (Friday): Begin Release Candidate validation.
  2. Tuesday EOD PT: Finalize RC with all fixes and cherry-picks.
  3. Wednesday: Buffer day for final checks.
  4. Thursday: Submit release to app stores and begin rollout to 1% of users.
  5. Monday: Scale deployment to 10%.
  6. Tuesday: Full rollout to 100%.

✅ Signoff Checklist

Each team is responsible for signing off via GitHub. Use the checkbox below to track signoff completion:

Team sign-off checklist

  • Accounts
  • Assets
  • Bots Team
  • Confirmations
  • Core Extension UX
  • Core Platform
  • Delegation
  • Design System
  • Engagement
  • Extension Platform
  • MetaMask Delivery
  • Money Movement
  • Networks
  • Onboarding
  • Perps
  • Swaps and Bridge
  • Transactions

This process is a major step forward in ensuring release stability and quality. Let’s stay aligned and make this release a success! 🚀

Feel free to reach out if you have questions or need clarification.

Many thanks in advance

Reference

MetaMask Bot and others added 30 commits July 23, 2026 19:30
## Version Bump After Release

This PR bumps the main branch version from 13.42.0 to 13.43.0 after
cutting the release branch.

### Why this is needed:
- **Nightly builds**: Each nightly build needs to be one minor version
ahead of the current release candidate
- **Version conflicts**: Prevents conflicts between nightlies and
release candidates
- **Platform alignment**: Maintains version alignment between MetaMask
mobile and extension
- **Update systems**: Ensures nightlies are accepted by app stores and
browser update systems

### What changed:
- Version bumped from `13.42.0` to `13.43.0`
- Platform: `extension`
- Files updated by `set-semvar-version.sh` script

### Next steps:
This PR should be **manually reviewed and merged by the release
manager** to maintain proper version flow.

### Related:
- Release version: 13.42.0
- Release branch: release/13.42.0
- Platform: extension
- Test mode: false

---
*This PR was automatically created by the
`create-platform-release-pr.sh` script.*

Co-authored-by: metamaskbot <metamaskbot@users.noreply.github.com>
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

upgrade bridge packages to latest versions

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: null

## **Related issues**

Fixes: https://consensyssoftware.atlassian.net/browse/SWAPS-4817

## **Manual testing steps**

1. Go to this page...
2.
3.

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Dependency-only change, but bridge controllers sit on quote, swap, and
cross-chain transaction paths—regressions would surface at runtime
rather than in this diff.
> 
> **Overview**
> Bumps MetaMask bridge dependencies so the extension picks up the
latest bridge package releases, with no application source changes in
this PR.
> 
> **`@metamask/bridge-controller`** goes from **77.5.0** to **^77.8.0**,
and **`@metamask/bridge-status-controller`** from **74.3.0** to
**^74.4.0**. Yarn resolutions still apply the existing
**`@metamask/bridge-controller`** patch, now pinned to **77.8.0**
(including an added resolution entry for **^77.7.0**). The lockfile
refresh also updates transitive versions pulled in by those packages
(e.g. **`@metamask/transaction-controller`** **^69.2.1** inside the
bridge stack).
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
ee326a3. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: MetaMask Bot <metamaskbot@users.noreply.github.com>
Co-authored-by: Maxime OUAIRY <maxime.ouairy-ext@consensys.net>
…ggregated balance cp-13.41.0 (#44796)

<!-- CURSOR_AGENT_PR_BODY_BEGIN -->
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

The aggregated (portfolio) balance drops tokens whose human-readable
balance is greater than or equal to `10^decimals` — e.g. a 54.06B
TangYuan balance with 9 decimals on BNB Chain (#44786).

**Root cause:** The `getAggregatedBalanceForAccount` selector in
`@metamask/assets-controller` contains a `scaleToHumanIfRaw` heuristic
that guesses whether a balance amount from `assetsBalance` state is in
raw base units or human-readable form based on its magnitude: whenever
the asset has `decimals` metadata and the amount is `>= 10^decimals`,
the amount is assumed to be raw and divided by `10^decimals`. Since
TangYuan's human-readable balance (54.06B) exceeds `10^9`, it gets
wrongly divided down to ~54 tokens, its fiat contribution rounds to ~$0,
and it effectively disappears from the aggregated total — while
individual token rows (which do not apply this heuristic) show the
correct fiat value.

The heuristic is unnecessary: all `AssetsController` data sources (RPC,
Accounts API, WebSocket) convert balances to human-readable form before
writing them to state, so amounts in `assetsBalance` are always
human-readable. Guessing raw vs. human by magnitude cannot be done
correctly and corrupts legitimately large balances.

**Solution (extension-repo only, no dependency changes):** In
`aggregateGroupBalance` (`ui/selectors/assets.balance-utils.ts`), the
state passed to `getAggregatedBalanceForAccount` is augmented with an
empty `assetsInfo`. The heuristic only fires when `decimals` metadata is
present, and metadata is otherwise only copied into the selector's
returned `entries`, which this call site discards (only
`totalBalanceInFiat` and `pricePercentChange1d` are consumed). Stripping
the metadata therefore disables the rescaling with no other behavioral
change to the totals. This single code point covers both
`selectBalanceForAllWallets` and the balance-change selectors, which are
the only consumers of the package's aggregation in the extension.

Tests:
- `ui/selectors/assets.balance-utils.aggregation.test.ts` — end-to-end
regression test through the real (unmocked) package selector with a
54.06B-token / 9-decimals balance; it fails without the fix and passes
with it.
- `ui/selectors/assets.balance-utils.test.ts` — pins the augmentation:
asserts the state handed to the aggregation selector has empty
`assetsInfo` while `assetsBalance`/`assetsPrice`/`assetPreferences` pass
through untouched.

The proper fix should also be upstreamed to `MetaMask/core`
(`packages/assets-controller/src/selectors/balance.ts`, where
`scaleToHumanIfRaw` still exists on `main`); once a fixed version is
adopted the augmentation can be removed.

## **Changelog**

CHANGELOG entry: Fixed the aggregated account balance excluding tokens
whose balance is very large relative to their decimals (e.g. 54B
TangYuan with 9 decimals)

## **Related issues**

Fixes: #44786

## **Manual testing steps**

1. Run the extension with a wallet that holds a token whose
human-readable balance is at least `10^decimals` — e.g. swap into
TangYuan (9 decimals) on BNB Chain so the balance is in the billions of
tokens.
2. Go to the homepage / asset list and note the fiat value shown on the
token's own row.
3. Verify the aggregated account balance at the top of the wallet
includes that token's fiat value (previously it was missing, making the
total far too low).
4. Verify tokens with ordinary balances (e.g. POSI with 18 decimals) are
still priced correctly and the total matches the sum of the individual
token rows.

## **Screenshots/Recordings**

### **Before**
See issue - `TangYuan` was not added to aggregate calculation

### **After**
<img width="524" height="624" alt="Screenshot 2026-07-23 at 20 38 24"
src="https://github.com/user-attachments/assets/ba84a9a4-e839-46ed-aac9-e2b27558ffb4"
/>

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
<!-- CURSOR_AGENT_PR_BODY_END -->

<div><a
href="https://cursor.com/agents/bc-c121dd8a-01f5-43f9-a8a8-b56931f842b8"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-web-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-web-light.png"><img
alt="Open in Web" width="114" height="28"
src="https://cursor.com/assets/images/open-in-web-dark.png"></picture></a>&nbsp;<a
href="https://cursor.com/background-agent?bcId=bc-c121dd8a-01f5-43f9-a8a8-b56931f842b8"><picture><source
media="(prefers-color-scheme: dark)"
srcset="https://cursor.com/assets/images/open-in-cursor-dark.png"><source
media="(prefers-color-scheme: light)"
srcset="https://cursor.com/assets/images/open-in-cursor-light.png"><img
alt="Open in Cursor" width="131" height="28"
src="https://cursor.com/assets/images/open-in-cursor-dark.png"></picture></a>&nbsp;</div>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
## **Description**

Update cla.yml with more Cursor names.

## **Changelog**

CHANGELOG entry: null

<!--## **Related issues**
## **Manual testing steps**
## **Screenshots/Recordings**
## **Pre-merge author checklist**
## **Pre-merge reviewer checklist**-->

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Single CI configuration change with no runtime, auth, or data-handling
impact.
> 
> **Overview**
> Updates the **CLA Signature Bot** workflow allowlist so additional
Cursor-related GitHub actors are exempt from CLA checks.
> 
> The `allowlist` in `.github/workflows/cla.yml` now includes
**`cursorbot`** and **`cursor[bot]`** alongside the existing
**`cursoragent`** entry, so automated Cursor PRs are treated like other
trusted bots (e.g. Dependabot, Copilot).
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
aabb4fa. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
## **Description**

Flips `MM_PURE_BLACK_PREVIEW` from `false` to `true` in `builds.yml` and
`.metamaskrc.dist` so that the pure black (OLED) dark mode is enabled
for all users in the build.

This gives us a week of testing in 13.42.x before the feature ships
permanently in 13.43.0.

## **Changelog**

CHANGELOG entry: Enabled pure black (OLED) dark mode for users with dark
theme active.

## **Related issues**

Fixes: TMCU-1166

## **Manual testing steps**

1. Run `yarn start` (no `.metamaskrc` change needed — the flag is now
`true` by default in the build).
2. Enable dark theme in Settings → Preferences and display → Theme →
Dark.
3. Confirm pure black (`#000000`) background is applied throughout the
extension.
4. Toggle back to light or system theme and confirm no visual
regressions.
5. Check the popup flash (`popup-init.html`), side menu, modals, and
popovers for correct elevation surfaces.

## **Screenshots/Recordings**

### **Before**

<!-- Pure black was opt-in via .metamaskrc -->

### **After**

<!-- Pure black enabled for all dark mode users -->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
## **Description**

Fixes the background flash sequence system-dark users see when opening
the extension in pure black mode. There are three moments where a
background color is visible before the full UI renders, and they all
need to agree:

1. **\`popup-init.html\`** — a static redirect page with no JavaScript.
Uses \`prefers-color-scheme: dark\` to set an initial background while
it redirects to \`popup.html\`. Changed from \`#121314\` to \`#000000\`.

2. **\`:root\` in \`base-styles.scss\`** — the \`light-dark()\` fallback
that fires immediately on \`popup.html\` parse, before JavaScript has
applied \`data-theme\` or \`data-pure-black\` attributes. Because no
data attributes exist at this point, a CSS selector cannot be used —
brand color tokens are the only option. Changed from
\`--brand-colors-grey-grey1000\` to \`--brand-colors-black\`.

3. **\`html[data-theme='dark'][data-pure-black='true']\`** (already in
\`base-styles.scss\`) — applies after JavaScript sets theme attributes.
Unchanged; this continues to own the post-JS state via the semantic
token.

Without both changes, fixing only \`popup-init.html\` would swap one
mismatch for another: \`#000000\` init flash → \`grey-grey1000\` root
frame → \`#000000\` themed.

> **Note:** Both changes affect all system-dark users, not just pure
black users, since neither \`prefers-color-scheme\` nor \`:root\` can
read MetaMask theme settings. They should not be merged until the
\`MM_PURE_BLACK_PREVIEW\` feature flag ships in 13.43.0.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes: TMCU-1158

## **Manual testing steps**

1. Enable \`MM_PURE_BLACK_PREVIEW=true\` in \`.metamaskrc\` and run
\`yarn start\`.
2. Enable dark theme in Settings → Preferences and display → Theme →
Dark.
3. Click the extension icon — the flash from \`popup-init.html\`, the
\`:root\` frame on \`popup.html\`, and the final themed background
should all be pure black with no visible transition.
4. Toggle to light theme and verify the white background still appears
at each stage.

## **Screenshots/Recordings**

### **Before**

Flash sequence: #121314 (popup-init) → #24272A (root) → #000000 (themed)


https://github.com/user-attachments/assets/27c3b95a-c36d-4e31-8b2a-e60ebe1bf6db

### **After**

Flash sequence: #000000 → #000000 → #000000 — seamless


https://github.com/user-attachments/assets/0e5d7183-b1bc-42f1-b161-623b99d9b7ef

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->
RC Slack was gated on full main `success`, so “Builds ready” on the PR
could exist while Slack never posted (e.g. 13.42.0). Slack now posts
when `Publish prerelease` succeeds on a release main run, even if other
jobs failed.
## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: null

## **Related issues**

Fixes: [Slack
thread](https://consensys.slack.com/archives/C0BJLRDCADT/p1784847360954639?thread_ts=1784847158.875339&cid=C0BJLRDCADT)

## **Manual testing steps**

1. Go to this page...
2.
3.

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> CI notification gating only; no runtime, auth, or release artifact
logic changes beyond when Slack is sent.
> 
> **Overview**
> **RC Slack notifications** now fire when release **Main** finishes
with **Builds ready** (`Publish prerelease / Publish prerelease`
succeeded), instead of requiring the entire **Main** workflow to be
green.
> 
> The `workflow_run` trigger still runs on completed **Main** for
`release/*`, but the job `if` accepts **success** or **failure**
conclusions. A new gate step uses `gh run view` (with **`actions:
read`**) to require the inner **Publish prerelease** job succeeded and
an open **release → stable** PR before posting. Comments in
`rc-slack-notify.yml` and `slack-rc-notification.mts` describe this
behavior.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
35b5992. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

Adds an E2E metrics test that asserts Wallet Setup Started (historically
Wallet Setup Selected) is sent with the expected onboarding properties
when a user creates a wallet with SRP and opts into MetaMetrics.

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: null

## **Related issues**

Fixes:
https://consensyssoftware.atlassian.net/browse/MMQA-2060

## **Manual testing steps**

CI should pass
Use the below command to execute the test locally 
yarn start:test
yarn test:e2e:single test/e2e/tests/metrics/wallet-setup-started.spec.ts
--browser=chrome

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Test-only change with no production or analytics implementation
modifications.
> 
> **Overview**
> Adds E2E coverage for the **Wallet Setup Started** Segment track event
during onboarding.
> 
> The new `wallet-setup-started.spec.ts` runs the create-wallet-with-SRP
flow with MetaMetrics opted in, mocks Segment via the shared metrics
mock helper, and asserts exactly one track event with expected
properties (`account_type`, `category`, `locale`, `chain_id`,
`environment_type`).
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
8dfb722. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Migrates Core UX-owned ButtonSecondary usages to the MMDS Button
component with variant={ButtonVariant.Secondary}. This removes
deprecated ButtonSecondary / ButtonSecondarySize imports from the
targeted owned files and updates the affected network, token, NFT
import, and import-account flows to use the current design system API.

## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: null

## **Related issues**

Fixes:

## **Manual testing steps**

1. Go to this page...
2.
3.

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Presentational swap only; handlers and flows are unchanged, with minor
visual/DOM differences from the new design system button.
> 
> **Overview**
> Replaces deprecated **component-library** `ButtonSecondary` with
**`@metamask/design-system-react`** `Button` using
`variant={ButtonVariant.Secondary}` in Core UX flows: native-token scam
warning modals (`token-cell`, `token-list-item`), import-account cancel
(`bottom-buttons`), import-NFT cancel, and the network list **Add a
custom network** action (including `IconName` from the design system).
> 
> Prop mapping is consistent: `block` → `isFullWidth`,
`ButtonSecondarySize` → `ButtonSize`. **Primary** actions still use
`ButtonPrimary` where unchanged. Jest snapshots were updated for the new
MMDS button DOM (Tailwind-based classes and icon markup).
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
cf52226. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
…d transactions from activity page cp-13.41.0 (#44780)

<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

Fixes Monad swap activity details showing a network fee amount instead
of `Paid by MetaMask` for gas-sponsored swaps.
This PR reuses the existing gas sponsorship display logic and applies it
to the new Activity Details fee rows.
When a local transaction is marked as gas-sponsored, Activity Details
now renders the network fee as `Paid by MetaMask` instead of showing a
calculated fee.
Also adds unit tests for the sponsorship logic and fee row rendering.

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: Fixed sponsored network fee transfer to show the `Paid
by MetaMask` label in activity page

## **Related issues**

Fixes: https://consensyssoftware.atlassian.net/browse/WPN-1713

## **Manual testing steps**

1. Perform a MON to USDC swap on Monad.
2. Open the Activity tab.
3. Click the completed swap transaction.
4. Verify the transaction details show:
    - Network fee
    - Paid by MetaMask
5. Open the same swap from the token details activity list
6. Verify the token details transaction view also shows
    - Network fee
    - Paid by MetaMask
10. As a regression check, open a normal non-sponsored transaction
11. Verify normal transactions still show the calculated network fee
amount instead of `Paid by MetaMask`
12. As another regression check, verify rejected transactions do not
show `Paid by MetaMask`

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->
<img width="831" height="813"
alt="625474154-06befb51-1ed3-48be-8a88-a91cbd295c6a"
src="https://github.com/user-attachments/assets/da34bba1-ba3c-47c1-98f0-432494f4a094"
/>

### **After**

<!-- [screenshots/recordings] -->
<img width="1009" height="1283" alt="Screenshot From 2026-07-23
15-51-51"
src="https://github.com/user-attachments/assets/9b921be1-41c5-4906-94a7-1376c9f8b0a5"
/>

## **Pre-merge author checklist**

- [X] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [X] I've completed the PR template to the best of my ability
- [X] I’ve included tests if applicable
- [X] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [X] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [X] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [X] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Display-only activity fee labeling with shared sponsorship helper;
covered by unit tests and no payment or signing logic changes.
> 
> **Overview**
> Gas-sponsored swaps (e.g. Monad) were showing a calculated **network
fee** in Activity Details instead of **Paid by MetaMask**. This change
wires the same sponsorship rules used on the legacy transaction
breakdown into the activity fee pipeline.
> 
> Local activity items now attach a `gas-fee-sponsored` fee marker when
`isGasFeeSponsored` applies (with hardware wallets,
failed-without-receipt, revoke delegation, and rejected txs excluded).
When API-enriched activity replaces the local row,
`mergeActivityItemSponsoredFees` keeps that marker and drops the API’s
base network fee. **FeesRows** renders the sponsored type as **Paid by
MetaMask** via `SuccessPill`.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
1800b9b. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
…lected a nonevm network (#44706)

## **Description**

When a hardware-wallet account group is selected and the user switches
to a Non-EVM network, MetaMask silently changes `selectedAccount` to a
Snap account. Gas sponsorship / gasless eligibility still used
`isHardwareWallet`, which only checks that globally selected account, so
the HW account was mis-classified as eligible and “Gas sponsored” UI
could incorrectly appear.

This PR adds `useIsHardwareWalletAccount`, which prefers an explicit
address (e.g. confirmation `txParams.from`), then the selected group’s
EVM account, then the global selection. Gas sponsorship and gasless
hooks (`useIsNetworkGasSponsored`, `useIsGaslessSupported`,
`useGaslessSupportedSmartTransactions`) now use that helper so HW
accounts stay excluded even when a Non-EVM network is selected.

## **Changelog**

CHANGELOG entry: Fixed gas sponsorship incorrectly appearing for
hardware wallet accounts when a Non-EVM network is selected

## **Related issues**

Fixes:
[MUL-2011](https://consensyssoftware.atlassian.net/browse/MUL-2011?atlOrigin=eyJpIjoiZjE0NDgwZjVlYWM4NDE2NWJmZmFhMGFiYjNjY2QzNzMiLCJwIjoiaiJ9)

## **Manual testing steps**

1. Import/connect a Ledger, Trezor, or QR hardware wallet account and
select that account group.
2. Switch the selected network to a Non-EVM network (e.g. Solana).
3. Navigate to a gas-sponsored EVM network flow (e.g. send /
confirmation on Monad or another sponsored chain available in your
build).
4. Verify the “Gas sponsored” / gasless UI is **not** shown for the
hardware wallet account.
5. Switch back to an HD/imported EOA on the same sponsored network and
verify gas sponsorship still appears when expected.
6. With HW selected on an EVM network (no Non-EVM switch), confirm
sponsorship remains hidden as before.

## **Screenshots/Recordings**
### **Before**


https://github.com/user-attachments/assets/36df87eb-942f-41a3-8104-e094aa322795


### **After**


https://github.com/user-attachments/assets/e796243a-e042-411c-b3a6-f821ef92e5ac

<!--
## **Screenshots/Recordings**



-->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

[MUL-2011]:
https://consensyssoftware.atlassian.net/browse/MUL-2011?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ


<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes eligibility logic for gas sponsorship and gasless
confirmations across multiple hooks; behavior is narrower (more HW
exclusions) but affects user-visible transaction flows.
> 
> **Overview**
> Fixes **gas sponsored** and **gasless** UI incorrectly treating
Ledger/Trezor sends as eligible when the user picks a Non-EVM network
while a hardware account group is still selected—`selectedAccount` can
become a Snap account even though the EVM `from` address is still
hardware.
> 
> Introduces **`useIsHardwareWalletAccount`**, which resolves hardware
status in order: optional address (e.g. confirmation `txParams.from`),
the selected account group’s EVM EOA, then the legacy `isHardwareWallet`
global selection.
> 
> **`useIsNetworkGasSponsored`**, **`useIsGaslessSupported`**, and
**`useGaslessSupportedSmartTransactions`** now use this hook instead of
`isHardwareWallet` alone; confirmation paths pass
**`transactionMeta?.txParams?.from`** so eligibility follows the signing
account. Unit tests cover the new hook and the Non-EVM / HW `from`
scenario.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
60d0ff7. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
The Google sign-in button in the onboarding flow and security settings
(SRP reveal list) was using the legacy 4-segment flat Google `G` icon
(`google.svg`). Google has updated their brand icon to a new gradient
`G` logo.

<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

JIRA LINK : https://consensyssoftware.atlassian.net/browse/TO-936

## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

- The existing `google.svg` used the outdated flat multi-colour Google
`G` icon
- The `srp-reveal-list__social-icon` CSS class was referenced in
`reveal-srp-list.tsx` but was never defined in `index.scss`, causing the
Google icon to render at 0×0 px (invisible)

### Solution
- Replaced `app/images/google.svg` with Google's updated gradient `G`
logo (no background, no border — logo only, compliant with Google
branding guidelines for use alongside button text)
- Tightened the SVG `viewBox` to crop padding, set explicit `width="20"
height="20"` so the intrinsic size is always reliable regardless of CSS
context
- Added the missing `&__social-icon { width: 24px; height: 24px; }` rule
to `reveal-srp-list/index.scss` to fix the invisible icon in the
security settings page


## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: Updated Google sign-in button icon to the new Google
gradient `G` logo; fixed invisible Google icon on the Secret Recovery
Phrase security settings page.

## **Related issues**

## **Manual testing steps**

1. Run the extension (`yarn start`)
2. Go to the onboarding welcome screen
3. Verify the Google button shows the new gradient `G` icon (no circle
border, no white/dark background)
4. Verify the icon looks correct in both light and dark themes
5. Navigate to **Settings → Security & Privacy → Secret Recovery
Phrase**
6. Verify the Google icon is now visible next to the social login email
address (previously 0×0 and invisible)

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

<img width="519" height="174" alt="Screenshot 2026-07-23 at 1 42 46 PM"
src="https://github.com/user-attachments/assets/83ecb61a-ebdf-485d-9ed3-344a54012c50"
/>
<img width="446" height="272" alt="Screenshot 2026-07-23 at 1 42 50 PM"
src="https://github.com/user-attachments/assets/ee5d76b4-ef28-4211-9ecb-fef3d637045f"
/>


### **After**

<!-- [screenshots/recordings] -->

<img width="470" height="649" alt="Screenshot 2026-07-23 at 1 31 36 PM"
src="https://github.com/user-attachments/assets/9f6702f7-5cda-4226-bc5d-34832d626e1a"
/>
<img width="595" height="768" alt="Screenshot 2026-07-23 at 1 31 43 PM"
src="https://github.com/user-attachments/assets/6fd53b63-2728-4b86-a725-1049b6f19819"
/>
<img width="737" height="822" alt="Screenshot 2026-07-23 at 1 31 54 PM"
src="https://github.com/user-attachments/assets/ccec6f45-0864-4fff-9679-45be233ffca6"
/>
<img width="620" height="800" alt="Screenshot 2026-07-23 at 1 32 01 PM"
src="https://github.com/user-attachments/assets/ae2f864b-2b42-4ecd-b2b0-3ee68df330ba"
/>
<img width="857" height="305" alt="Screenshot 2026-07-23 at 1 32 32 PM"
src="https://github.com/user-attachments/assets/cec5aee6-fbb1-4221-b325-d4c523ccbd8f"
/>
<img width="886" height="313" alt="Screenshot 2026-07-23 at 1 32 42 PM"
src="https://github.com/user-attachments/assets/e490d72e-8f7d-436b-aa32-141d19fb965a"
/>



## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [x] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [x] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Visual-only asset and stylesheet changes with no auth or
business-logic impact.
> 
> **Overview**
> Updates the shared **`images/google.svg`** asset from the legacy flat
four-color **G** to Google’s newer gradient **G** (cropped viewBox,
20×20 intrinsic size) so onboarding Google sign-in and other consumers
pick up current branding.
> 
> Adds the missing **`srp-reveal-list__social-icon`** rule (24×24) in
`reveal-srp-list/index.scss` so the Google `<img>` on the Secret
Recovery Phrase social-login card is sized and visible instead of
collapsing to 0×0.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
03829ae. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
## **Description**

Refactors the tokens tab E2E page object with reusable helpers and
selectors needed by the Tron assets E2E cluster. This is the first slice
of the former #44777 split; fixture wiring lands in the follow-up PR
stacked on this branch.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Part of the local-blockchain E2E initiative (WPN-536).

## **Manual testing steps**

1. `yarn build:test`
2. Verify the branch builds and existing tokens-tab E2E tests still
pass.

## **Screenshots/Recordings**

N/A — test infrastructure only, no user-facing UI change.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
… branches (#44779)

## **Description**

Passes four `gate-override-*` inputs so the `AI PR Analyzer / Gate`
check concludes `success` for medium-risk Runway cherry-picks into
release branches. Fail-closed: trusted same-repo PRs only (forks
excluded), author `runway-github[bot]`, base `^release/`, title
`cherry.?pick`, risk within `medium`. Off for every other PR. Does not
change merge automation by itself.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

N/A

## **Manual testing steps**

1. A `runway-github[bot]` cherry-pick PR into `release/*` scored
`medium` concludes the gate `success` (`Risk gate passed via override:
medium ≤ medium`).
2. A `medium` PR into `main`, or from another author, stays `neutral`.

## **Screenshots/Recordings**

N/A. CI config change.

### **Before**

N/A

### **After**

N/A

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…4790)

<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**
Improves the create-password UX so the "passwords don't match" error no
longer nags the user on every keystroke while they are still typing the
confirmation. The mismatch error now appears only once the confirm field
reaches the minimum password length (`PASSWORD_MIN_LENGTH`), and still
clears immediately once the values match.

### computeMismatchError:
- confirm shorter than min length → false ('abc')
- confirm ≥ min length but shorter than password → false ('a]2$GHvw' vs
'a]2$GHvw&W')
- confirm ≥ min length, ≥ password length, and differs → true
('X]2$GHvw&W' vs 'a]2$GHvw&W')
- confirm === password → false

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: show password mismatch error only when confirm password
is equal or longer than PASSWORD_MIN_LENGTH

## **Related issues**

Fixes:

## **Manual testing steps**

1. Go to Menu > Settings > Security and password > Password
2. Continue until change password form is shown
3. Enter a password and confirm password
4. Before "Passwords don't match" error shows right away after typing
first letter of confirm password. It shows now when confirm password is
equal to password minimum length which is 8

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**
<img width="472" height="488" alt="image"
src="https://github.com/user-attachments/assets/b3858f2b-9005-4f95-aa56-7045c14376f1"
/>

<!-- [screenshots/recordings] -->

### **After**


https://github.com/user-attachments/assets/460a223b-e2e3-4981-96fe-33d6e788ec5c





<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.


<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Onboarding/settings password UI validation only; behavior is narrower
(fewer premature errors) with no vault or crypto changes.
> 
> **Overview**
> **Password confirmation UX** no longer shows “passwords don’t match”
on every keystroke while the user is still typing confirm. The shared
`PasswordForm` now uses exported **`computeMismatchError`**, which only
flags a mismatch when confirm is at least **`PASSWORD_MIN_LENGTH`**, at
least as long as the primary password, and not equal—so partial prefixes
and short confirm input stay silent until the user has typed enough to
judge a real mismatch.
> 
> When the primary password is lengthened after confirm already matched,
the mismatch message stays hidden but **`onChange`** still clears the
valid password (form stays invalid). Unit coverage was added for the
helper and edge cases; onboarding **create-password** and e2e onboarding
tests were updated to match the new rules.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
22e1862. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

Replaces the `selectERC20TokensByChain` Redux selector with the
`getAssetImageUrl` utility function in the `GasFeeTokenIcon` component.
The previous approach looked up the icon URL from the ERC20 tokens state
slice, which has been refactored. The new approach uses the shared
`getAssetImageUrl` helper from `asset-utils` to derive the static image
URL directly from the token address and chain ID.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes:

## **Manual testing steps**

1. Open MetaMask and navigate to a transaction confirmation that uses a
gas fee token (pay-with-token flow).
2. Verify the token icon is displayed correctly in the gas fee row.
3. Verify the native token icon is displayed when the native token is
selected.

## **Screenshots/Recordings**

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Localized confirmation UI change with equivalent fallback behavior; no
auth or transaction logic touched.
> 
> **Overview**
> **Gas fee token icons** on transaction confirmations no longer read
`iconUrl` from the `selectERC20TokensByChain` Redux slice.
**`GasFeeTokenIcon`** now resolves the image via shared
**`getAssetImageUrl(tokenAddress, chainId)`**, keeping the same
behavior: **`AvatarToken`** when a URL exists, **`PreferredAvatar`**
when it does not. Native-token rendering is unchanged.
> 
> Tests **mock `getAssetImageUrl`**, assert it is called with the token
address and confirmation chain ID, and cover both a returned URL and
**`undefined`** fallback paths.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
1fc2747. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry:

## **Related issues**

Fixes:

## **Manual testing steps**

1. Go to this page...
2.
3.

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Dependency version bump plus messenger delegation wiring; no direct
changes to auth, keys, or payment flows.
> 
> **Overview**
> Upgrades **`@metamask/assets-controller`** from **11.1.1** to
**11.2.0** (`package.json` / `yarn.lock`) so the extension picks up the
latest package behavior.
> 
> Because **11.2.0** expects remote feature flags on the controller
messenger, **`getAssetsControllerMessenger`** now delegates
**`RemoteFeatureFlagController:getState`** and
**`RemoteFeatureFlagController:stateChange`** to the AssetsController
child messenger. The assets-controller messenger unit tests were updated
so the delegated action/event lists include those entries.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
b1b2834. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
## **Description**

Extends Tron E2E fixtures with assets-focused mocks and environment
wiring, and removes staking-only fixture state from the shared helper.
Stacks on #44777.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Part of the local-blockchain E2E initiative (WPN-536).
Stacks on #44777.

## **Manual testing steps**

1. `yarn build:test`
2. Verify the branch builds and existing Tron E2E tests still pass.

## **Screenshots/Recordings**

N/A — test infrastructure only, no user-facing UI change.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

Adds unit and E2E coverage for the Wallet Imported Segment event,
asserting it fires with the expected onboarding properties when an SRP
wallet import completes.

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: null

## **Related issues**

Fixes:
https://consensyssoftware.atlassian.net/browse/MMQA-2055

## **Manual testing steps**

CI should pass
Execute locally using below commands:
yarn test:unit
ui/pages/onboarding-flow/create-password/create-password.test.tsx
yarn test:e2e:single test/e2e/tests/metrics/wallet-imported.spec.ts
--browser=chrome

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Test-only changes with no application or analytics implementation
modifications.
> 
> **Overview**
> Adds **unit and E2E tests** so the **Wallet Imported** analytics event
is verified when SRP import completes during onboarding—no production
behavior changes.
> 
> In `create-password.test.tsx`, a new case drives a successful import
submit and asserts `trackEvent` emits **Wallet Imported** (onboarding
category, `biometrics_enabled: false`) and **Wallet Import Attempted**.
Shared helpers `getTrackedEvent` / `getWalletImportedEvent` reduce
duplication with existing wallet-setup event checks.
> 
> In `wallet-imported.spec.ts`, a dedicated E2E case mocks Segment for
**Wallet Imported**, runs `completeImportSRPOnboardingFlow` with metrics
opted in, and asserts a single batch payload with expected properties
(`category`, `locale`, `chain_id`, `environment_type`, etc.), with
profile IDs stripped pending issue #31860.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
d474157. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

Removes the token approval text and its tooltip from the unified swaps
and bridge quote CTA. The MetaMask fee disclaimer remains visible when
applicable. Obsolete approval message translations are removed, and the
affected tests and snapshots are updated.

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: Removed the token approval message and tooltip from
swap and bridge quotes

## **Related issues**

Fixes: SWAPS-4823

## **Manual testing steps**

1. Build and load the extension, then unlock the wallet.
2. Open the unified swaps and bridge flow and request an ERC-20 quote
that requires token approval, testing both a same-chain swap and a
cross-chain bridge.
3. Verify the CTA area does not show an approval sentence or approval
tooltip. If a MetaMask fee applies, verify its fee disclaimer remains
visible.

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

<img width="477" height="985" alt="Screenshot 2026-07-23 at 10 50 55 AM"
src="https://github.com/user-attachments/assets/269a4066-fb19-4852-a9c5-c902d6c35bbb"
/>


### **After**

<!-- [screenshots/recordings] -->
<img width="476" height="917" alt="Screenshot 2026-07-23 at 11 13 17 AM"
src="https://github.com/user-attachments/assets/565f2166-426f-4dd6-8ce7-bf9ddaea7b94"
/>



## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.


<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Copy-only UI change with no transaction or approval logic modified;
the main product risk is less upfront disclosure before users confirm
approvals.
> 
> **Overview**
> Removes **token approval** messaging from the unified swap/bridge
quote CTA so users no longer see “approves token for bridge/swap” copy
or the **exact-access** info tooltip (including hardware-wallet-specific
bridge approval warnings).
> 
> `BridgeCTAInfoText` now only renders the **MetaMask fee disclaimer**
when a non-discounted MM fee applies; it renders nothing when the quote
needs approval but has no fee text to show. Related **locale strings**
(`bridgeApprovalWarning`, `grantExactAccess`,
`willApproveAmountForBridging`, etc.) are deleted across locales, with
**tests and snapshots** updated to match.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
e13c215. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
…4791)

This PR is to make sure that the balance is left aligned for smaller
viewports


## **Description**

<!--
Write a short description of the changes included in this pull request,
also include relevant motivation and context. Have in mind the following
questions:
1. What is the reason for the change?
2. What is the improvement/solution?
-->

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: null

## **Related issues**

Fixes:

## **Manual testing steps**

1. Go to this page...
2.
3.

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**



https://github.com/user-attachments/assets/91524f4d-55e2-44ca-8f00-71a89b3c2f98


## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.


<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Presentation-only layout changes in wallet overview with no auth,
data, or business-logic impact.
> 
> **Overview**
> **Wallet overview balance alignment** is updated so the sidepanel
keeps the balance **left-aligned** when the viewport is at or below
**490px**, while fullscreen/sidepanel layouts still **center** the
balance on wider widths.
> 
> Adds a **`wallet-overview-sidepanel`** class on the sidepanel
environment and a shared SCSS mixin that applies `start` alignment under
that breakpoint for the balance block, coin overview balance, and
loading skeleton. Inline Tailwind alignment on the balance wrapper and
skeleton is removed in favor of these styles, and the sidepanel
max-width is centralized as a SCSS variable.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
e2e6500. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

Align the activity transaction details max-width with the recently
updated app max width

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes: #44840

## **Manual testing steps**

1. Open Activity and click a transaction.
2. Resize the window through narrow, mid (~600–900px), and wide widths.
3. Confirm details always match the app content width with no Activity
showing around the edges.
4. Repeat in sidepanel while resizing the panel.

<!--
## **Screenshots/Recordings**

### **Before**

### **After**
-->

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
## **Description**

[PR #43639](#43639)
introduced a static route allowlist that let 14 deep-link paths bypass
the full-screen interstitial even when a link had a missing or invalid
signature. This conflicted with the security decision in [ADR
0011](https://github.com/MetaMask/decisions/blob/8112d93b758f27d09fc86fad09a45da52740ee35/decisions/core/0011-deep-linking-into-wallet.md?plain=1#L92-L93),
which requires every deep link to show the interstitial before its
destination opens.

[PR #44114](#44114)
subsequently added `/asset` to the skipped routes. [PR
#44639](#44639)
replaced that unconditional exception with an asynchronous Token API
lookup that allowed assets classified as known-safe to bypass the
interstitial. That lookup made `canSkipInterstitial` asynchronous in the
non-blocking Manifest V3 request listener, delaying the extension
redirect while `link.metamask.io` continued loading its fallback page.

This PR restores the protected flow across immediate and deferred
deep-link handling:

- Deletes the static 14-route bypass allowlist.
- Removes the unused `Route.skipInterstitial` property so route
definitions cannot opt out of the security boundary.
- Deletes the asynchronous `/asset` bypass and its Token API
security-data plumbing. Known-safe and unknown or malicious assets now
follow the same protected flow.
- Restores synchronous `canSkipInterstitial` behavior. Only trusted
MetaMask origins, or a valid signature combined with the user's skip
preference, can bypass the router-level interstitial.
- Keeps all actual deep-link route definitions, including `/asset` and
the 14 formerly allowlisted routes.
- Documents why `tryNavigateTo` must not perform external network or API
lookups before redirecting in MV3: otherwise the fallback page can
incorrectly tell users to install MetaMask when it is already installed.

Regression coverage exercises missing and invalid signatures for every
formerly allowlisted path, protected internal and external redirect
destinations, and both known-safe and unknown or malicious asset links.
The shared E2E flow once again requires the interstitial before
continuing to route destinations.

Validation completed:

- Focused Jest suites: 116 tests passed
- TypeScript type checking passed
- Oxfmt and ESLint passed for every changed code file
- Full LavaMoat policy regeneration passed for build tooling plus all
MV2 and MV3 profiles

## **Changelog**

CHANGELOG entry: Fixed deep links so protected routes no longer bypassed
the security interstitial based only on their path

## **Related issues**

Fixes #44816
Fixes #44817
Fixes #44818
Fixes #44819
Fixes #44820
Fixes #44821
Fixes #44822
Fixes #44823
Fixes #44824
Fixes #44825
Fixes #44826
Fixes #44827
Fixes #44828
Fixes #44829

## **Manual testing steps**

1. Build and load the Chrome MV3 extension.
2. Open Privacy settings and ensure the option to skip the deep-link
interstitial is disabled.
3. Paste `https://link.metamask.io/swap?amount=50` into the browser
address bar.
4. Verify the full-screen security interstitial appears before the swap
destination opens.
5. Continue through the interstitial and verify the swap destination
opens.
6. Paste `https://link.metamask.io/buy` into the browser address bar.
7. Verify the security interstitial appears before the external buy
destination opens.
8. Paste
`https://link.metamask.io/asset?assetId=eip155%3A1%2Ferc20%3A0x6b175474e89094c44da98b954eedeac495271d0f`
into the browser address bar.
9. Verify the known-safe DAI asset link also shows the security
interstitial.
10. Repeat with `&sig=aW52YWxpZC1zaWduYXR1cmU=` added to a deep link and
verify an invalid signature does not bypass the interstitial.

<!--
## **Screenshots/Recordings**

Not applicable; this restores existing interstitial behavior without
changing its visuals.

### **Before**

N/A

### **After**

N/A
-->

## **Pre-merge author checklist**

- [x] I have followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I have completed the PR template to the best of my ability
- [x] I have included tests if applicable
- [x] I have documented the code using JSDoc format if applicable
- [x] I have applied the right labels on the PR

## **Pre-merge reviewer checklist**

- [ ] I have manually tested the PR.
- [ ] I confirm that this PR addresses all acceptance criteria and
includes the necessary testing evidence.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **High Risk**
> Changes security-sensitive deep-link navigation for many product
routes and removes prior bypass behavior; incorrect logic could block
legitimate flows or still expose users to unsigned links.
>
> **Overview**
> Restores ADR-aligned deep-link security by **removing path-based and
async asset bypasses** so missing or invalid signatures no longer skip
the full-screen interstitial on protected routes (swap, buy, asset,
etc.).
>
> `DeepLinkRouter.canSkipInterstitial` is **synchronous** again: only
trusted MetaMask origins, or a **valid signature** plus the user’s skip
preference, can bypass. The static allowlist (`interstitial-bypass.ts`),
Token API–backed `/asset` checks (`interstitial-bypass-async.ts`), and
`Route.skipInterstitial` are deleted; deferred deep-link handling in
`utils.ts` matches the same rules. Docs warn that MV3 `onBeforeRequest`
must stay free of network work before `redirectTab`.
>
> Tests and E2E flows now expect the interstitial for unsigned/invalid
links on all formerly whitelisted paths and for external redirects from
untrusted origins.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
41a4ca9. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
## **Description**

- tar to 7.5.22
- Ignoring three react-router advisories because they don't apply to how
we're using them, and updating would require a very difficult major
version bump

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Closes: #44805
Progresses: #44859

<!--## **Manual testing steps**
## **Screenshots/Recordings**
## **Pre-merge author checklist**
## **Pre-merge reviewer checklist**-->

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Mostly lockfile and LavaMoat policy alignment plus documented audit
suppressions; tar/stream changes affect Snaps packaging but are routine
security bumps.
> 
> **Overview**
> **Dependency refresh** for the Snaps/tar extraction stack: `tar` moves
to **7.5.22**, with related bumps (`tar-stream` 3.2.0, `streamx` 2.28.0,
`tar-fs` 2.1.5, and new transitive packages such as `events-universal`,
`text-decoder`, and optional `bare-*` peers). `queue-tick` drops out of
the `streamx` graph in favor of that newer layout.
> 
> **LavaMoat** webpack policies (MV2/MV3 variants) are regenerated to
match: `streamx` now allows `process.nextTick` / `queueMicrotask`, wires
`events-universal` and `text-decoder` instead of `queue-tick`, and drops
the standalone `queue-tick` entry.
> 
> **Yarn audit** adds three ignored React Router GHSA IDs with
rationale—**HashRouter** (not server-controlled browser paths) for the
open-redirect issues and **no SSR/hydration** for the
`deserializeErrors` advisory—so CI stays green without a major React
Router upgrade.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
e846388. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: MetaMask Bot <metamaskbot@users.noreply.github.com>
## **Description**

Adds a single automatic retry for `PersistenceManager` write operations.
If the first `storage.local` or backup IndexedDB write fails,
`PersistenceManager` waits for half of the operation safener debounce
window and tries once more before surfacing the existing persistence
failure path.

Primary `storage.local` retry delays can be canceled when a newer `set`
or `persist` supersedes the in-flight write, preventing a stale retry
from running. Backup IndexedDB retries are not superseded, so an
in-progress vault backup retry still completes before the newer write
proceeds.

The reason for this split is that a newer primary write contains fresher
state, so retrying the older primary write would add storage churn and
briefly write stale data. Backup writes are different: by the time a
backup retry is waiting, primary storage for that operation has already
succeeded. Aborting that backup retry could intentionally leave the
recovery backup stale, and in split state the newer write might touch
unrelated keys and never refresh backed-up keys such as
`KeyringController`.

Successful retries emit `writeRetryRecovered`, which is forwarded to
Segment as `Data Persistence Write Retry Recovered` with the persistence
operation, original error metadata, and retry delay.

Also exports `PERSISTENCE_MANAGER_OPERATION_SAFENER_DEBOUNCE_MS` from
`PersistenceManager` and uses it to configure the operation safener, so
the retry delay is derived from the same shared timing value.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes: #44681

## **Manual testing steps**

1. Run the extension in a Chrome MV3 development build with MetaMetrics
enabled so Segment events can be inspected.
2. Trigger a wallet state change while forcing the first persistence
write to fail transiently, such as by temporarily making
`storage.local.set` reject once in the extension background context.
3. Verify the state write succeeds on the retry, the storage failure UI
is not shown, and a `Data Persistence Write Retry Recovered` event is
emitted with the original error metadata.
4. While a primary write retry is waiting, trigger and persist a newer
state change. Verify the stale retry is canceled and the newer state is
written.
5. Force the first backup IndexedDB write to fail, then trigger a newer
state change while the retry is waiting. Verify the backup retry still
completes before the newer write proceeds.
6. Force both the initial write and retry to fail, then verify the
existing storage failure handling still runs.

<!--
## **Screenshots/Recordings**

### **Before**

### **After**
-->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **High Risk**
> Changes core wallet persistence and vault backup behavior; incorrect
retry or supersede logic could lose state or leave backups stale, though
existing failure paths remain when both attempts fail.
> 
> **Overview**
> Adds a **single automatic retry** for `PersistenceManager`
`set`/`persist` paths and IndexedDB vault backup writes. After the first
failure it waits **500ms** (half the shared operation-safener debounce)
and tries once more before the existing failure UI and Sentry reporting.
> 
> **Primary** `storage.local` retries can be **canceled** when a newer
`set` or `persist` supersedes the in-flight write, so stale state is not
written. **Backup** IndexedDB retries are **not** superseded so an
in-progress vault backup can finish before newer writes proceed.
> 
> Successful retries emit `writeRetryRecovered`, wired in
`setup-initial-state-hooks` to Segment as **`Data Persistence Write
Retry Recovered`** with operation name, original error metadata, and
retry delay. **`PERSISTENCE_MANAGER_OPERATION_SAFENER_DEBOUNCE_MS`** is
exported and reused by `safe-reload` debouncing.
> 
> Test support: `simulateStorageSetFailure` accepts **`'once'`** (first
write per manager instance only). Unit and e2e coverage added for retry,
supersede, and analytics.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
708f9ff. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: Jongsun Suh <jongsun.suh@icloud.com>
… cp-13.42.0 (#44863)

## **Description**

Fixes the dark theme regression in transaction details introduced by
#44599 (native \`<dialog>\` refactor).

The browser UA stylesheet sets \`color: canvastext\` directly on
\`<dialog>\` elements, which overrides the inherited \`color:
var(--color-text-default)\` from \`html[data-theme]\`. Because
\`canvastext\` resolves based on the browser's native color-scheme
rather than MetaMask's \`data-theme\` attribute, text inside the dialog
renders with the wrong color in dark mode. Adding \`text-default\` here
sets the MMDS color token as an author style directly on the dialog
element, taking precedence over the UA rule and restoring correct text
color for all descendants.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes #44836

## **Manual testing steps**

> **Note:** The bug only reproduces when your OS/system theme differs
from the MetaMask theme. Set your OS to **light** mode and MetaMask to
**dark** mode to trigger it.

1. Set OS appearance to Light mode
2. In MetaMask, go to Settings → General → Theme → Dark
3. Go to Activity
4. Click any transaction
5. Verify all text in the transaction details dialog is visible
(white/light on dark background, not invisible black)

## **Screenshots/Recordings**

### **Before**

<img width="1506" height="869" alt="Screenshot 2026-07-24 at 1 34 22 PM"
src="https://github.com/user-attachments/assets/825237cc-e95b-4915-abf1-d94aa1cebdf6"
/>


<img width="451" height="624" alt="Image"
src="https://github.com/user-attachments/assets/fa5e2a3a-4153-40e9-a821-fc7e9e9417b3"
/>

### **After**

<img width="1507" height="871" alt="Screenshot 2026-07-24 at 1 31 51 PM"
src="https://github.com/user-attachments/assets/34383cb5-1e6f-46d8-a15a-a05411510fba"
/>

<img width="455" height="651" alt="Image"
src="https://github.com/user-attachments/assets/289b0c93-f702-4645-a2a0-680f4406b593"
/>

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

Fixes the locally enriched bridge transaction title text that
incorrectly changes when switching to a non-EVM network

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: fix: local bridge activity label when switching to
non-evm accounts

## **Related issues**

Fixes: #44591

## **Manual testing steps**

1. Do a token bridge
2. Switch network to Bitcoin

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.


<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes which transactions appear in local activity and how bridge
labels resolve when multichain network selection differs from EVM
account; limited to activity UI/selectors, not funds or auth.
> 
> **Overview**
> Fixes **local activity / bridge label enrichment** when the user
switches to a non-EVM network (e.g. Bitcoin) while staying on the same
account group.
> 
> `selectLocalTransactions` and `selectLocalActivityItems` now filter
and enrich using **`selectEvmAddress`** (the EVM account in the selected
group) instead of **`getSelectedInternalAccount`** (which tracks the
network-selected account). **`selectEvmAddress`** is defined earlier in
`activity.ts` so those selectors can depend on it.
> 
> Across locale files, **`activity_deposit_*_description`** strings are
cleared to empty messages (titles unchanged), so deposit rows no longer
show redundant subtitle copy.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
07b9d35. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

Co-authored-by: Cursor <cursoragent@cursor.com>
## **Description**

This PR adds the Tron network E2E cluster and the `home-network-filter`
page object it depends on. It is one reviewable step of a linear stack
and replaces #43659. Validated locally: `network.spec.ts` passes 5/6,
with the 1 failure being an element-visibility timeout that is likely
local flake — CI is the arbiter. Based on a fresh `main` and under 1000
changed lines.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Part of the local-blockchain E2E initiative (WPN-536).
Replaces #43659.

## **Manual testing steps**

1. `yarn build:test`
2. `yarn test:e2e:single test/e2e/tests/tron/network.spec.ts
--browser=chrome` (locally 5/6; the 1 element-visibility timeout is
likely local flake — CI is the arbiter).

## **Screenshots/Recordings**

N/A — test infrastructure only, no user-facing UI change.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I’ve included tests if applicable
- [x] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [x] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
<!--
Please submit this PR as a draft initially.
Do not mark it as "Ready for review" until the template has been
completely filled out, and PR status checks have passed at least once.
-->

## **Description**

Cleanup and replace deprecated selectors

## **Changelog**

<!--
If this PR is not End-User-Facing and should not show up in the
CHANGELOG, you can choose to either:
1. Write `CHANGELOG entry: null`
2. Label with `no-changelog`

If this PR is End-User-Facing, please write a short User-Facing
description in the past tense like:
`CHANGELOG entry: Added a new tab for users to see their NFTs`
`CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker`

(This helps the Release Engineer do their job more quickly and
accurately)
-->

CHANGELOG entry: null

## **Related issues**

Fixes:

## **Manual testing steps**

1. Go to this page...
2.
3.

## **Screenshots/Recordings**

<!-- If applicable, add screenshots and/or recordings to visualize the
before and after of your change. -->

### **Before**

<!-- [screenshots/recordings] -->

### **After**

<!-- [screenshots/recordings] -->

## **Pre-merge author checklist**

- [ ] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [ ] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I’ve applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Bridge history matching is narrower than the removed multi-field
`getBridgeHistoryItem` logic, so bridge/swap activity status and
intent-bridge pending cancel/speed-up rules could differ in edge cases.
> 
> **Overview**
> **Centralizes bridge history resolution** for activity and
pending-transaction UI by adding exported
`selectBridgeHistoryItemForTx`, which resolves by tx hash (via
bridge-status selectors), direct `txHistory` key on meta id, then
original tx meta id.
> 
> **Activity selectors** drop the deprecated raw `txHistory` selector
and the inline `getBridgeHistoryItem` group scan; local swap/bridge rows
now call the shared lookup with `initialTransaction` only, and non-EVM
bridge enrichment passes `{ hash: transaction.id }` instead of id-only.
> 
> **Pending transaction actions** read bridge history through
`useSelector` + `selectBridgeHistoryItemForTx` instead of
`useBridgeTxHistoryData`; tests mock Redux and the new selector
accordingly. A JSDoc note on `hasIntentBridgeActivity` was removed from
the hook params type only.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
db8cad3. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
## **Description**

After a Chrome Web Store upload is approved and published, rollout
percentage is today adjusted manually in the CWS Developer Dashboard.
This PR adds an audited, human-initiated path to raise deploy percentage
via CWS API v2.

**Problem:** Manual dashboard changes are hard to audit and easy to
mis-apply (rollback, large jumps, 100% without explicit confirmation).

**Solution:**
- New `.github/workflows/adjust-cws-rollout.yml` — `workflow_dispatch`
only; targets `dev`, `production`, `flask` (aligned with INFRA-3734
upload model).
- **Separate from upload:** upload = Runway + WIF on `cws-dev` /
`cws-production` / `cws-flask` (draft only). Rollout = human judgment
after monitoring (`docs/sensitive-release.md` 1% protocol).
- **Authorization:** dedicated rollout GitHub Environments with required
reviewers (platform must create):
  - `cws-rollout-dev` (UAT smoke)
  - `cws-rollout-production` (main listing)
  - `cws-rollout-flask` (Flask listing)
- Bot/Runway dispatch explicitly rejected; human initiates → environment
approver confirms → guardrails → CWS API.
- Guardrails script reports **all** violations before exit (range, no
rollback, 100% confirm, 50-point max step).
- CWS v2 `:fetchStatus` for current `deployPercentage`;
`:setPublishedDeployPercentage` to apply.
- `if: always()` audit summary (actor, environment, target, version,
previous/requested %, run URL).

**Open question (see INFRA-3651):** Runway-driven vs workflow-driven
rollout for production — pending Mark / Gauthier / Victor.

**Platform follow-up (not in this PR):**
1. Create `cws-rollout-*` GitHub Environments + required reviewers
(after RE confirmation).
2. Extend GCP WIF CEL + IAM bindings for rollout envs on dev and prod
(`adjust-cws-rollout.yml`; no Runway pin on rollout path).

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes:
[INFRA-3651](https://consensyssoftware.atlassian.net/browse/INFRA-3651)

## **Manual testing steps**

**Prerequisite:** Platform creates `cws-rollout-dev` /
`cws-rollout-production` / `cws-rollout-flask` and WIF CEL for
`adjust-cws-rollout.yml`.

1. **Dev — rollback:** Published version at e.g. 10%; dispatch
`desired_percentage=5` → guardrails fail with rollback message; attach
run link to INFRA-3651.
2. **Dev — 100% without confirm:** Dispatch `desired_percentage=100`
without `confirm_full_rollout=yes` → guardrails fail; attach run link.
3. **Dev — success:** Valid version, e.g. 5% → 10% → guardrails pass →
CWS updated; audit summary correct; attach run link.
4. **Production — bot block:** Any bot dispatch → rejected before GCP
auth; attach run link.
5. **Production — human success:** RE dispatches → environment approver
confirms → rollout updated on production listing; attach run link.
6. **Flask — human success:** Same as production on Flask listing
(`EXTENSION_ID_FLASK`); attach run link.

## **Screenshots/Recordings**

N/A — CI/workflow only; evidence is GitHub Actions run summaries and CWS
listing state.

### **Before**

N/A

### **After**

N/A

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding
Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [x] I've included tests if applicable
- [x] I've documented my code using [JSDoc](https://jsdoc.app/) format
if applicable
- [ ] I've applied the right labels on the PR (see [labeling
guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

[INFRA-3651]:
https://consensyssoftware.atlassian.net/browse/INFRA-3651?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Medium Risk**
> Changes who can move production extension rollout % and how (WIF + CWS
API), but bots are blocked, rollbacks are refused in-workflow, and
GitHub Environment reviewers are required before apply.
> 
> **Overview**
> Adds a **human-only** GitHub Actions path to raise Chrome Web Store
**published deploy percentage** after upload, separate from
`upload-extension-to-cws.yml` (Runway/draft upload).
> 
> New **`adjust-cws-rollout.yml`** is `workflow_dispatch` with inputs
for manifest **version**, **desired_percentage** (1–100), and **target**
(`dev` / `production` / `flask`). Each target maps to a dedicated
**`cws-rollout-*` GitHub Environment** (required reviewers), rejects
**Bot** senders, requires **`refs/heads/main`**, resolves WIF/listing
vars like the upload workflow, and authenticates to CWS with the
chromewebstore scope.
> 
> The job calls **`:fetchStatus`**, derives **current**
`deployPercentage` only from the **live published** `crxVersion` (Flask
uses `{version}-flask.0`), then runs
**`adjust-cws-rollout-guardrails.sh`** (valid ranges, **no rollback**
when desired &lt; current, no-op when equal) before
**`:setPublishedDeployPercentage`**. An **`if: always()`** step writes
an audit table to the run summary (actor, env, target, version,
before/after %, step outcomes).
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
88a5e3e. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Alejandro Som <560018+alucardzom@users.noreply.github.com>
@metamask-ci

ghost commented Aug 8, 2026

Copy link
Copy Markdown
Contributor
Builds ready [dfc2567]
⚡ Performance Benchmarks (Total: 🟢 10 pass · 🟡 7 warn · 🔴 4 fail)

Baseline (latest main): 171ed20 | Date: 7/28/2026 | Pipeline: 31232693325 | Baseline logs

Metricschrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🔴 srpButtonToSrpForm(p95) [CI log]🔴 [CI log]
onboardingNewWallet
[Sentry log · main/release]
🔴 longTaskCount(p95) [CI log]🔴 [CI log]

Regressions (🔴 4 failures)

Interaction Benchmarks · Samples: 5
Benchmarkchrome-webpackfirefox-webpack
loadNewAccount
[Sentry log · main/release]
🟡 [CI log]
🟡 load_new_account
🟡 [CI log]
🟡 load_new_account
confirmTx
[Sentry log · main/release]
🟢 [CI log]🟡 [CI log]
bridgeUserActions
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↑ loadNewAccount/load_new_account: +18%
  • ↑ loadNewAccount/total: +18%
  • ↑ confirmTx/longTaskMaxDuration: +11%
  • ↑ confirmTx/tbt: +10%
  • ↑ bridgeUserActions/bridge_load_asset_picker: +33%
  • ↑ bridgeUserActions/longTaskCount: +11%
  • ↑ bridgeUserActions/longTaskTotalDuration: +19%
  • ↑ bridgeUserActions/tbt: +36%
  • ↑ loadNewAccount/load_new_account: +21%
  • ↑ loadNewAccount/total: +21%
  • ↓ loadNewAccount/inp: -24%
  • ↓ loadNewAccount/fcp: -46%
  • ↑ loadNewAccount/lcp: +1140%
  • ↑ confirmTx/confirm_tx: +11%
  • ↓ confirmTx/longTaskCount: -100%
  • ↓ confirmTx/longTaskTotalDuration: -100%
  • ↓ confirmTx/longTaskMaxDuration: -100%
  • ↓ confirmTx/tbt: -100%
  • ↑ confirmTx/total: +11%
  • ↑ confirmTx/inp: +142%
  • ↓ confirmTx/fcp: -49%
  • ↑ confirmTx/lcp: +1213%
  • ↑ bridgeUserActions/bridge_load_page: +254%
  • ↑ bridgeUserActions/bridge_load_asset_picker: +73%
  • ↓ bridgeUserActions/longTaskCount: -100%
  • ↓ bridgeUserActions/longTaskTotalDuration: -100%
  • ↓ bridgeUserActions/longTaskMaxDuration: -100%
  • ↓ bridgeUserActions/tbt: -100%
  • ↑ bridgeUserActions/total: +17%
  • ↓ bridgeUserActions/inp: -15%
  • ↑ bridgeUserActions/lcp: +1126%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 confirmTx/INP: p75 256ms
Startup Benchmarks · Samples: 100
Benchmarkchrome-webpackfirefox-webpack
startupStandardHome
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
startupPowerUserHome
[Sentry log · main/release]
–🟡 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↓ startupStandardHome/numNetworkReqs: -14%
  • ↓ startupStandardHome/domInteractive: -16%
  • ↓ startupStandardHome/numNetworkReqs: -13%
  • ↑ startupPowerUserHome/uiStartup: +12%
  • ↑ startupPowerUserHome/domInteractive: +15%
  • ↑ startupPowerUserHome/backgroundConnect: +11%
  • ↑ startupPowerUserHome/initialActions: +11%
  • ↑ startupPowerUserHome/setupStore: +266%
  • ↑ startupPowerUserHome/inp: +10%
  • ↑ startupPowerUserHome/fcp: +13%
  • ↑ startupPowerUserHome/lcp: +12%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 startupPowerUserHome/INP: p75 208ms
  • 🟡 startupPowerUserHome/LCP: p75 3.2s
User Journey Benchmarks · Samples: 5 · real API 🔴 4

⚠️ Missing data: chrome/webpack/userJourneyTransactions

Benchmarkchrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🔴 [CI log]
🔴 doneButtonToHomeScreen
🔴 total
🔴 [CI log]
🔴 total
onboardingNewWallet
[Sentry log · main/release]
🔴 [CI log]
🔴 total
🔴 [CI log]
🔴 total
assetDetails
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
solanaAssetDetails
[Sentry log · main/release]
🟢 [CI log]🟡 [CI log]
🟡 assetClickToPriceChart
importSrpHome
[Sentry log · main/release]
🟡 [CI log]
🟡 total
🟢 [CI log]
sendTransactions
[Sentry log · main/release]
–🟡 [CI log]
swap
[Sentry log · main/release]
–🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↑ onboardingImportWallet/srpButtonToSrpForm: +18%
  • ↑ onboardingImportWallet/confirmSrpToPwForm: +16%
  • ↑ onboardingImportWallet/pwFormToMetricsScreen: +13%
  • ↓ onboardingImportWallet/doneButtonToHomeScreen: -37%
  • ↑ onboardingImportWallet/openAccountMenuToAccountListLoaded: +115%
  • ↑ onboardingImportWallet/longTaskCount: +29%
  • ↑ onboardingImportWallet/longTaskTotalDuration: +26%
  • ↑ onboardingImportWallet/longTaskMaxDuration: +10%
  • ↑ onboardingImportWallet/tbt: +30%
  • ↓ onboardingNewWallet/srpButtonToPwForm: -10%
  • ↓ onboardingNewWallet/createPwToRecoveryScreen: -12%
  • ↓ onboardingNewWallet/skipBackupToMetricsScreen: -22%
  • ↓ onboardingNewWallet/agreeButtonToOnboardingSuccess: -15%
  • ↓ onboardingNewWallet/doneButtonToAssetList: -19%
  • ↑ onboardingNewWallet/longTaskCount: +25%
  • ↓ onboardingNewWallet/longTaskTotalDuration: -17%
  • ↓ onboardingNewWallet/tbt: -30%
  • ↓ onboardingNewWallet/total: -18%
  • ↑ solanaAssetDetails/assetClickToPriceChart: +22%
  • ↓ solanaAssetDetails/longTaskCount: -100%
  • ↓ solanaAssetDetails/longTaskTotalDuration: -100%
  • ↓ solanaAssetDetails/longTaskMaxDuration: -100%
  • ↓ solanaAssetDetails/tbt: -100%
  • ↑ solanaAssetDetails/total: +22%
  • ↑ solanaAssetDetails/inp: +11%
  • ↑ solanaAssetDetails/fcp: +11%
  • ↑ importSrpHome/loginToHomeScreen: +15%
  • ↑ importSrpHome/openAccountMenuAfterLogin: +15%
  • ↑ importSrpHome/homeAfterImportWithNewWallet: +34%
  • ↑ importSrpHome/longTaskCount: +41%
  • ↑ importSrpHome/longTaskTotalDuration: +18%
  • ↑ importSrpHome/total: +32%
  • ↓ importSrpHome/cls: -14%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 importSrpHome/INP: p75 312ms
  • 🟡 solanaAssetDetails/FCP: p75 2.0s
  • 🟡 solanaAssetDetails/LCP: p75 2.5s
  • 🟡 sendTransactions/FCP: p75 2.1s
  • 🟡 sendTransactions/LCP: p75 2.6s
Dapp Page Load Benchmarks · Samples: 100

⚠️ Missing data: chrome/webpack/pageLoadBenchmark

✅ No regressions detected

Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 4.25 KiB (0.03%)
  • ui: 34.03 KiB (0.19%)
  • common: 0 Bytes (0%)
  • other: 0 Bytes (0%)
  • contentScripts: 476 Bytes (0.02%)
  • zip: 47.71 KiB (0.22%)

🍒 What's in this RC

Cherry-picks (12 commits)
Commit Description
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
75ea9568be Merge branch 'stable' into release/13.43.0

Changelog (162 commits since v13.42.0)
Commit Description
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
76657f7a3c release: release-changelog/13.43.0 (#45056)
9da0748ed3 Merge release/13.42.0 into release/13.43.0
d90d1e76b8 fix(hardware-wallets): bound stuck account-creation spinner with device-read timeout cp-13.42.0 (#45048)
0311ca5fc9 feat: add trust security signals tdp (#44761)
3114315a0e fix: consume stx enabled flag for batch sell from selected chain (#45032)
3ae0ce34cc chore: clean up TextFieldSearch styles after MMDS package update (#45030)
51cff5563f test: fix flaky test Smart Transactions should send transaction using USDC to pay fee (#45036)
0610a607c7 feat(perps): wire dedicated aggregated order-book socket per UI connection (#45035)
d67a05b8aa ci(slsa): publish attestation bundles and pin run-build actions (INFRA-3786) (#44955)
666b247f3a test: fix flaky custom-token import E2E by waiting for the Add Custom Token network picker to settle TimeoutError: Waiting for element to be located By(css selector, [data-testid="custom-token-import-submit-button"]:not([disabled])) (#45025)
9afac38fe7 feat: new segment schema support (#43132)
bfdb62afa3 test: fix flaky test BTC Account - Activity Receive transaction is rendered with Received label and confirmed status (#45022)
0fdbade0f4 test: MMQA - 1916 - Refactor multiple-provider-connections.spec.ts to good practices (#44941)
33bef9f690 test: fix flaky perps watchlist explore TimeoutError: Waiting for element to be located By(css selector, [data-testid="market-list-filter-sort-row"]) (#44936)
6d53060f6b test: replace driver.waitForSelector with page object methods (#44898)
ed7b8fbd53 fix: patch for missing slip44 entries in core client-utils cp-13.42.0 (#45006)
7e9653a51f feat: added metrics for custom network page (#45031)
5a94f11f60 feat(activity): contact names in activity rows (#45013)
5f842c6082 test: fix flaky Add wallet Import wallet using SRP during onboardingand MetaMask onboarding should not prevent network requests to advanced... (#45034)
c36df0ec1a fix: vertically center contact copy button (#45020)
e3abdc3e78 feat: added timer for balance loading cp-13.42.0 (#45033)
b424876ab6 chore: update assets controllers for defi fix (#45003)
adec2ed351 refactor(wpc-1066): migrate pending-approval HW methods to LegacyBackgroundApiService (#44937)
20bf478a91 feat(confirmations): add Money Account Deposit developer option (#44945)
48ad866df4 bump(perps): upgrade @metamask/perps-controller to v10 (#45024)
239006e967 fix(notifications): add bottom padding to marketing consent text (#45021)
9158172d8a refactor(wpc-1067): migrate network enablement methods to LegacyBackgroundApiService (#44938)
62aaaa4923 test: order selectors and methods in all page objects (#44987)
45505c9910 chore: wire stellar asset component with stellar asset selector (#44979)
ce134bc060 feat: defi positions v2 controller (#44392)
b50797d25a chore: pass Firefox system access via geckodriver and pin 0.36.0 (#45014)
0c7372db98 fix(pure-black): use bg-default on back up SRP page (#44983)
e47424b771 fix(perps): show wallet-confirmed deposits immediately in Perps Activity (#44736)
9b623cccf7 ci: turn on the Triage and Retry System by default (no retry-ci label needed) (#44956)
778bafe559 feat(ramps): wire Buy Continue with background checkout watch (#44689)
10b5de87df test: lavamoat e2e (#44925)
c1a5d29ffd fix: swaps stale dest exchange rates cp-13.42.0 (#44968)
0fa0c88cf3 chore: fix lint:changed script (#45010)
fa5c57e727 fix: navigate to homepage after users close popup from batch sell (#44991)
7dce891afb feat(ramps): send Portfolio-connected wallets to Portfolio on Buy (#44804)
3739101671 fix(pure-black): refine SRP input empty vs filled styling (#45004)
1ec648fa36 chore: update swap consumers to use and display partial QuoteMetadata (#44630)
0660a05750 refactor(wpc-1068): migrate requestSafeReload & openUpdateTabAndReload to LegacyBackgroundApiService (#44940)
d2fdd13169 perf(6570): bump react-hooks to v7 and remove react-compiler plugin (#44495)
cf719e0334 fix(pure-black): stop inverting bridge transaction settings tooltip theme (#44964)
10fabf3ed6 chore: New Crowdin Translations by GitHub Action cp-13.42.0 (#44746)
806f4bf8b6 fix(pure-black): use BackgroundDefault for markets row skeleton (#44984)
da76cb3edb fix(pure-black): use bg-default on Snap install screen (#45002)
c20d7eb736 fix(pure-black): set send network filter button background to transparent (#44882)
04b53836a4 chore(STX): add Robinhood Chain to smart transactions supported networks (#44926)
284f97705e chore: popover for failed transaction status (#44961)
2668c42734 fix(pure-black): remove border from page footer cancel buttons (#44981)
d0efdd7df1 chore(storybook): add Pure Black toolbar toggle and component stories (#44963)
fadc943601 feat: assets unify balance and traces (#44978)
bad91a67e9 chore: replaced deprecated Tag component with MMDS tag (#44785)
dd2075062d fix(confirmations): refetch MetaMask Pay required token price when it is missing (#44950)
66b8f875e3 fix(pure-black): fix Menu background specificity with bg-section (#44966)
00f32ff73c fix: qr camera permission throwing e.isUnlocked is not a function (#44701)
b5ed10c4c2 feat(hardware-wallets): enable shared signing flow (#43947)
1695992b6f feat: migrate Infura IPFS users to dweb.link and block Infura IPFS gateway entry (#44982)
0ad8940da9 feat: use new snap keyring v2/v1 split (#44289)
b7f13b1a4c test: refactor transaction details page and consolidate selectors (#44694)
61ff089628 test(e2e): add Tron assets E2E cluster (#44852)
540d2a65b1 feat: bump transaction-pay-controller to 26.0.0 (#44782)
df415e426e test: skip ERC20 max balance WS update test (ASSETS-3385) (#44952)
f87e3bc8db fix(pure-black): remove custom background color from InfoPopoverTooltip (#44933)
634b46cfed fix(pure-black): remove border-l and bg-alternative from drawer in popup/compact sidepanel (#44960)
57da315640 test: pom lint rule supporting groups (selectors, constructor, actions) (#44789)
7e641c6203 chore: bump @types/chrome and drop custom chrome typings (#44888)
cbd1c50aaf perf(7466): add memoization to network/asset modal components (Batch D) (#44296)
75e09ed50f fix(pure-black): settings sidebar uses bg-alternative in pure black mode (#44883)
c164a38416 fix: clear the postcss advisories cp-13.42.0 (#44865)
3f6a9050c3 test: cover Token Detection Enabled identify trait (#44915)
91ed59bb42 chore: replace local gator permission detail schemas with @metamask/7715-permission-types (#44415)
a73805093a fix: excempt batch sell routes from ConfirmationRouter (#44951)
87d0cf9c0a fix(pure-black): set main action button dropdown to bg-alternative (#44881)
17731f5111 fix(pure-black): fix account address popover background and refactor row hover to Tailwind (#44880)
b8ee5bb2eb fix(pure-black): correct tooltip background and arrow colors in dark and pure black themes (#44879)
7b6dde7630 fix(pure-black): add bg-alternative and border to asset explorer view (#44878)
cfdbb033e8 bump: brace-expansion to 5.0.8 (#44924)
00ebfcf32e feat: updated import NFT flow Modal (#44899)
a5f18a53c5 fix: Allow QR singing in side panel on brave (#44934)
bdbe8f29c1 chore(6922): bump @testing-library/react to v14 (#42635)
b35834378b chore: upgrade design system packages (v57.0.0) (#44931)
58b697a400 fix: remove deprecated METAMASK_ENVIRONMENT=test in favor of testing (#44944)
4e37811629 chore: remove copy-to-clipboard dependency (#44890)
4d2065f6a5 test: add coverage for Notification Clicked metrics event (#44920)
da23672992 feat(analytics): migrate pre-consent queue to AnalyticsController (#43869)
5201492b01 feat: refactor non-zero native custom networks (#44161)
9e0cbd2538 fix: allow Firefox WebDriver system access for about:debugging (#44946)
992ff087e7 test(e2e): refactor tokens tab page object for assets coverage (#44778)
b8ad63da79 ci(amo): allow release-team manual dispatch of AMO production (INFRA-3769) (#44519)
bd65eccfdb chore: remove defi v2 fetching from getApi (#44939)
3cb496ea9a chore: migrate markNotificationPopupAsAutomaticallyClosed to LegacyBackgroundApiService (#44249)
f835f69039 feat: initialize DeFiPositionsControllerV2 (#44772)
171ed202b7 feat: add UAT env on bridge (#44895)
ca508307ef feat: bump phishing controller 17.3.0 (#44841)
56ffb74681 refactor(ui): use Arrow2UpRight for Send action icons (#44929)
9c8c6bcb8b fix(pure-black): set perps balance dropdown to bg-alternative (#44875)
cd32d2d252 chore: remove component-library README.mdx docs (#44886)
bab3498f9c chore: remove deprecated textfieldsearch components (#44918)
2bbf04046f ci: fixed labels from forks (#44022)
199066c701 fix: add missing events to bottom nav bar experiment config cp-13.42.0 (#44919)
d53496f910 chore: swap position of network picker and search bar on swaps asset picker (#44911)
9d573278ab chore(6927): upgrade redux to v8 (#44445)
2f528e3470 build: no more PNGs inside SVGs allowed, delete unused images (#44832)
4011ce9d91 Merge origin/main into stable-main-13.41.0
72ba3533f4 chore: bump assets controller to v11.2.1 (#44903)
cba9e41d31 chore: fix ESLint ignore config (#44914)
5bb1c5e23d feat: update HeaderSearch and asset picker modal search bars to use TextFieldSearch (#44910)
2be47e1c8d fix: handle missing account for cross-chain asset deeplinks cp-13.42.0 (#44904)
7fac1b56cb test(e2e): stabilize network filter open before switch-network click (#44692)
ba9268b8c7 test: fix flaky test error page support consent TimeoutError: Waiting element to become stale (#44850)
60e4cd1b48 test: fix flaky unstable Continue button in Send page (#44837)
c4d2caae67 feat: migrate swap asset picker search to DSR TextFieldSearch (#44905)
fba4cb3aa7 refactor: simplify sponsored fee row; cleanup dead code (#44872)
ff4fd4dbb8 chore: rename SettingsHeader to PageHeaderWithSearch (#44902)
b072b88aef fix: updated checkbox and permissions page width cp-13.42.0 (#44896)
4045b69287 chore: remove dead app header props (#44900)
15db15fe5b feat: align search bar UIs (#44430)
67db57c82a fix(transactions): avoid inflated fees from failed container estimates (#44308)
75e46239ee feat(ci): add CWS rollout adjustment workflow (INFRA-3651) (#44060)
a03a82855f refactor: cleanup activity selectors (#44864)
7d8a31630f test(e2e): add Tron network E2E cluster (#44164)
e7a6a5e59f fix: local-enriched bridge label when switching networks (#44858)
42146f2fa5 fix(activity): apply text color token to native dialog for dark theme cp-13.42.0 (#44863)
55ad54b09e fix: retry persistence writes once (#44003)
c08a8bb748 bump: tar to 7.5.22, ignore react-router advisories cp-13.41.0 (#44862)
cdddd817a4 fix(deep-links): restore interstitial protection cp-13.42.0 (#44830)
b6619a9fb8 fix(activity): transaction details width (#44853)
5d2cff8067 feat: keep the balance left aligned for lower viewport cp-13.42.0 (#44791)
fddbd0cf34 chore: remove swaps approval text (#44794)
71272d9cd3 test: cover Wallet Imported event (#44747)
47bb810f81 test(e2e): extend Tron fixtures for assets E2E coverage (#44784)
01588c978d chore(assets-controller): bump to 11.2.0 (#44847)
c8df352c4c fix(confirmations): use getAssetImageUrl for gas fee token icon (#44769)
eca1e7ed3f feat: defer password confirm mismatch error until minimum length. (#44790)
e40d3d1af9 ci: pass AI analyzer gate for medium Runway cherry-picks into release branches (#44779)
5147646d2f test(e2e): refactor tokens tab page object for assets coverage (#44777)
81508e447a feat(onboarding): update Google sign-in icon to new brand logo (#44755)
545dd73434 fix: gas sponsorship being shown for hw accounts when the user has selected a nonevm network (#44706)
4ed04ec772 fix: restored old behavior to show Paid by MetaMask label in sponsored transactions from activity page cp-13.41.0 (#44780)
ca4d467800 refactor: migrate Core UX secondary buttons to MMDS (#44767)
197093a62a test: cover Wallet Setup Started Segment event (#44668)
5c6ffe848d fix(ci): post RC Slack when Builds ready, not only green main (#44831)
8011cc033a fix: eliminate dark-mode background flash for pure black mode (#44743)
d667c1f177 feat: enable pure black dark mode by default (#44806)
c42c6cbe77 ci: update cla.yml with more Cursor names (#44815)
88e20cf90c fix(assets): include tokens with large balances and few decimals in aggregated balance cp-13.41.0 (#44796)
1e2f17bea8 feat: upgrade bridge packages to latest versions (#44722)
5fb686386e release: Bump main version to 13.43.0 (#44799)

AI Test Plan

Risk Score High Risk Medium Risk Files Changed Commits
55/100 6 6 1354 165
Cherry-Pick Scenarios (2)

High Risk Scenarios (1)

1. Smart Transactions - Sentinel endpoint routing

Risk Level: HIGH

Why This Matters: Cherry-pick #45214 fixes STX controller routing; incorrect endpoints can break all STX sends or strand users mid-flow.

Test Steps:

  1. Enable Smart Transactions and prepare a small native transfer on a supported network.
  2. In devtools Network, monitor outgoing STX calls during quote and submit; verify requests target the new tx-sentinel Robinhood URL.
  3. Temporarily block the Robinhood URL (simulate outage) and confirm the flow fails gracefully or falls back to legacy send without trapping the user.
  4. Complete at least one STX successfully and verify Activity status updates through finalization.

Medium Risk Scenarios (1)

1. Perps - Order book on order entry page

Risk Level: MEDIUM

Why This Matters: Cherry-pick #45151 adds a new user-facing order book; incorrect wiring can misprice orders or break trading UX.

Test Steps:

  1. Open the Perps order entry page and verify the order book renders with bids/asks and updates live.
  2. Click a price level to auto-populate the order entry price; verify correct precision and side.
  3. Change markets and confirm the order book and selected price update accordingly.
  4. Validate empty/error states (unsupported network or no liquidity) are handled gracefully without console errors.

Release Scenarios (10)

High Risk Scenarios (5)

1. State Migrations 220/221 - Persistent state integrity

Risk Level: HIGH

Why This Matters: New migrations can corrupt or drop user data (accounts, networks, tokens, pending approvals) and block core wallet flows.

Test Steps:

  1. On 13.41/13.42, create a wallet with 3+ accounts, add at least one custom RPC network, import tokens, and add an address book entry.
  2. Start a dapp connection and initiate (but do not confirm) a transaction so there is a pending approval.
  3. Upgrade to 13.43.0, unlock, and verify accounts, selected account, custom networks, tokens, and address book entries are intact.
  4. Open Activity/Notifications and ensure the pending approval still exists and can be approved or rejected successfully.
  5. Switch across added networks and confirm balances and token lists render without errors.

2. State Migrations 220/221 - Metametrics consent and defaults

Risk Level: HIGH

Why This Matters: Metametrics-controller changes can mistakenly flip consent or leak PII, creating privacy regressions post-migration.

Test Steps:

  1. On 13.41/13.42, set Analytics to Opt-out in Settings > Security & Privacy (or during onboarding).
  2. Upgrade to 13.43.0 and unlock.
  3. Trigger common actions (open portfolio, switch network, open Send) and inspect devtools Network for analytics calls; verify none are sent while Opt-out.
  4. Toggle to Opt-in, repeat actions, and verify analytics events now send without exposing account addresses or secrets.
  5. Lock and unlock the wallet and verify the consent state persists.

3. Smart Transactions - submit and fallback

Risk Level: HIGH

Why This Matters: Controller and patch changes around Smart Transactions can break send flows or strand users in non-functional routes.

Test Steps:

  1. Enable Smart Transactions in Settings (where available) and switch to a supported network (e.g., Mainnet).
  2. Send a small native transfer; confirm the flow shows Smart Transaction routing/quoting and allows submission.
  3. Verify the transaction submits and status updates (queued/relayed) until finalized in Activity.
  4. Simulate unsupported/failed STX (e.g., switch to an unsupported network or disable network) and ensure the flow cleanly falls back to a legacy transaction.
  5. Confirm gas customization and fee display remain consistent across STX and fallback paths.

4. Dapp Permissions - Unconnected account alert

Risk Level: HIGH

Why This Matters: Incorrect unconnected-account gating can silently block dapp flows or allow unintended account access.

Test Steps:

  1. Connect a dapp to Account A, then switch the active account in the extension to Account B.
  2. From the dapp, attempt an action requiring permissions (request accounts or send).
  3. Verify the 'Unconnected account' alert appears in the extension and offers to connect the current account.
  4. Use the alert action to connect Account B and verify the original dapp action can proceed.
  5. Switch back to Account A and confirm the alert no longer appears for Account A.

5. Balances - Account group balance accuracy

Risk Level: HIGH

Why This Matters: Incorrect aggregation or stale state can misrepresent user funds, eroding trust in balances shown.

Test Steps:

  1. Use 3+ accounts with varied holdings (native and tokens) across 2+ networks.
  2. Open the Accounts/Assets view and note the total group balance.
  3. Hide one token and verify the group total updates correctly.
  4. Switch the primary network and confirm the group total and per-account balances recalculate without stale values.
  5. Toggle fiat currency display (if available) and verify the conversions and totals remain correct.

Medium Risk Scenarios (5)

1. Perps - Live market data stream resilience

Risk Level: MEDIUM

Why This Matters: Perps stream bridge changes can cause stalls or memory leaks, breaking real-time trading UX.

Test Steps:

  1. Open the Perps trading page and verify live market data populates (prices/tickers).
  2. Switch networks (supported to unsupported and back) and confirm the stream unsubscribes/re-subscribes without errors.
  3. Lock and then unlock the wallet; verify the stream resumes and UI updates continue.
  4. Simulate a brief offline period (toggle network offline) and confirm the client recovers and updates after reconnection.

2. Network Management - Invalid custom network alert

Risk Level: MEDIUM

Why This Matters: Incorrect or noisy network validation interrupts normal use and may mislead users about network safety.

Test Steps:

  1. Add a custom RPC with a mismatched chain ID or wrong RPC endpoint.
  2. Switch to that network and verify the 'Invalid custom network' alert appears.
  3. Use alert actions (e.g., Edit network) to correct RPC/chain ID and confirm the alert resolves.
  4. Switch away and back to confirm no false-positive alert on a valid configuration.

3. Assets - Network filter and control bar behaviors

Risk Level: MEDIUM

Why This Matters: Filter logic regressions can hide assets or confuse totals, leading to missed funds or actions.

Test Steps:

  1. In Assets, use the control bar to filter by a specific network and verify only tokens for that network are displayed.
  2. Switch to 'All networks' and confirm consolidated listing with correct per-network badges/labels.
  3. Use search and sorting, then close and reopen the extension; verify filter state persistence (or expected reset).
  4. Switch accounts and confirm filters apply consistently without resetting inadvertently.

4. App State - Route and UI state persistence

Risk Level: MEDIUM

Why This Matters: App-state-controller changes can create jarring resets or stuck UI flows after lock/unlock or reload.

Test Steps:

  1. Navigate to a non-default screen (e.g., Activity or Settings) and start a UI tour if available (e.g., Account icon tour).
  2. Lock the wallet, close the popup, and reopen; unlock.
  3. Verify the last route and relevant UI/tour state persist or reset as intended (e.g., tour step continuity).
  4. Reload the extension and confirm no unexpected resets or errors in the UI.

5. Analytics Events - Emission and redaction

Risk Level: MEDIUM

Why This Matters: Refactors in the metametrics controller may alter event names or redaction, risking broken dashboards or privacy leaks.

Test Steps:

  1. Set Analytics to Opt-in.
  2. Perform key actions: add network, connect dapp, send transaction, and reject a request.
  3. Inspect devtools Network for analytics payloads and verify expected event names/properties while ensuring account addresses and secrets are not sent in clear.
  4. Toggle to Opt-out and confirm subsequent actions no longer send analytics.

Teams Sign-off Status

Signed off: None yet

Awaiting sign-off (6):
Accounts, Assets, Networks, Permissions, Transactions, Wallet Integrations


Generated by AI Test Plan Analyzer (gpt-5) at 2026-08-08T02:10:15.163Z

AI generated test plan (JSON): test-plan-13.43.0.json

…GHSA-2v37-7h3g-55p8` (#45372)

- chore: bump nanoid to `^3.3.17` to clear `GHSA-2v37-7h3g-55p8`
cp-13.43.0 (#45362)

## **Description**

`nanoid` is a direct production dependency and `main` resolved it to
3.3.16.
[GHSA-2v37-7h3g-55p8](GHSA-2v37-7h3g-55p8)
covers `< 3.3.17` — a custom generator built with `customAlphabet` /
`customRandom` loops indefinitely when `size` is zero.

This moves the declared range to `^3.3.17` and consolidates every 3.x
descriptor in the tree onto a single 3.3.17 entry:

```
"nanoid@npm:^3.3.10, ^3.3.11, ^3.3.16, ^3.3.17, ^3.3.8":
  version: 3.3.17
```

Two notes for anyone repeating this, because the obvious commands both
fail in different directions:

- **`yarn dedupe` alone does not reach it.** Dedupe consolidates onto
the highest version *already in the lockfile*, so with 3.3.16 resolved
it is a no-op — the version has to be introduced with `yarn up` first.
- **A bare `yarn up nanoid` overshoots.** nanoid's `latest` dist-tag is
`6.0.1`, so it rewrites the range to `^6.0.1` and pulls a major; the 3.x
line ships under the `legacy` tag. Pinning to `@^3.3.17` keeps it in
range.

The remaining `nanoid@2.1.11` is untouched and unaffected — dev-only,
reached through `redux-devtools-core`.

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes: #45334

Reachability triage for this advisory, including why the upgrade path
here is clean unlike #45325's:

#45334 (comment)

## **Manual testing steps**

Dependency-only change with no runtime surface, so verification is by
resolution and audit rather than by using the app.

1. `yarn install`
2. `grep -A2 '^"nanoid@npm' yarn.lock` → every `^3.3.x` descriptor
resolves to a single `3.3.17` entry
3. `yarn npm audit --recursive --environment production` → nanoid no
longer reported

### Results on this branch

| check | result |
|---|---|
| declared range | `dependencies.nanoid` = `^3.3.17` |
| resolution | all five 3.x descriptors consolidated onto **3.3.17** |
| production audit | nanoid **not flagged** |
| diff scope | `package.json` 1 line, `yarn.lock` 10 lines |

## **Screenshots/Recordings**

N/A — no user-visible change.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding

Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable — N/A, dependency bump
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable — N/A
- [x] I’ve applied the right labels on the PR (see [labeling

guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Patch-level dependency bump with lockfile consolidation only; no
source changes and stays on nanoid 3.x.
> 
> **Overview**
> Bumps the direct production dependency **`nanoid`** from `^3.3.8` to
**`^3.3.17`** and refreshes **`yarn.lock`** so every `^3.3.x` descriptor
resolves to a single **3.3.17** entry (replacing **3.3.16**).
> 
> This addresses

[GHSA-2v37-7h3g-55p8](GHSA-2v37-7h3g-55p8),
where `customAlphabet` / `customRandom` can loop indefinitely when
`size` is zero on versions below 3.3.17. There are **no application or
runtime code changes**—only dependency resolution.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
3e63d80. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
[a58c242](a58c242)

---------

Co-authored-by: Jongsun Suh <jongsun.suh@icloud.com>
Co-authored-by: MetaMask Bot <metamaskbot@users.noreply.github.com>
@metamask-ci

ghost commented Aug 10, 2026

Copy link
Copy Markdown
Contributor
Builds ready [c81d0a9]
⚡ Performance Benchmarks (Total: 🟢 13 pass · 🟡 5 warn · 🔴 4 fail)

Baseline (latest main): 171ed20 | Date: 7/28/2026 | Pipeline: 31415403972 | Baseline logs

Metricschrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🔴 doneButtonToHomeScreen(p95) [CI log]🔴 [CI log]
onboardingNewWallet
[Sentry log · main/release]
🔴 doneButtonToAssetList(p95) [CI log]🔴 [CI log]

Regressions (🔴 4 failures)

Interaction Benchmarks · Samples: 5
Benchmarkchrome-webpackfirefox-webpack
loadNewAccount
[Sentry log · main/release]
🟢 [CI log]🟡 [CI log]
🟡 load_new_account
confirmTx
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
bridgeUserActions
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↓ loadNewAccount/inp: -17%
  • ↑ loadNewAccount/lcp: +44%
  • ↓ confirmTx/longTaskTotalDuration: -29%
  • ↓ confirmTx/longTaskMaxDuration: -28%
  • ↓ confirmTx/tbt: -51%
  • ↓ confirmTx/inp: -32%
  • ↓ confirmTx/fcp: -12%
  • ↓ bridgeUserActions/bridge_load_page: -16%
  • ↓ bridgeUserActions/bridge_load_asset_picker: -37%
  • ↓ bridgeUserActions/longTaskCount: -44%
  • ↓ bridgeUserActions/longTaskTotalDuration: -53%
  • ↓ bridgeUserActions/longTaskMaxDuration: -27%
  • ↓ bridgeUserActions/tbt: -68%
  • ↓ bridgeUserActions/total: -16%
  • ↓ bridgeUserActions/inp: -31%
  • ↓ bridgeUserActions/fcp: -20%
  • ↓ bridgeUserActions/lcp: -23%
  • ↑ loadNewAccount/load_new_account: +23%
  • ↑ loadNewAccount/total: +23%
  • ↑ loadNewAccount/inp: +29%
  • ↓ loadNewAccount/fcp: -41%
  • ↑ loadNewAccount/lcp: +1208%
  • ↑ confirmTx/confirm_tx: +12%
  • ↓ confirmTx/longTaskCount: -100%
  • ↓ confirmTx/longTaskTotalDuration: -100%
  • ↓ confirmTx/longTaskMaxDuration: -100%
  • ↓ confirmTx/tbt: -100%
  • ↑ confirmTx/total: +12%
  • ↓ confirmTx/inp: -24%
  • ↓ confirmTx/fcp: -46%
  • ↑ confirmTx/lcp: +1193%
  • ↑ bridgeUserActions/bridge_load_page: +311%
  • ↑ bridgeUserActions/bridge_load_asset_picker: +89%
  • ↑ bridgeUserActions/bridge_search_token: +20%
  • ↓ bridgeUserActions/longTaskCount: -100%
  • ↓ bridgeUserActions/longTaskTotalDuration: -100%
  • ↓ bridgeUserActions/longTaskMaxDuration: -100%
  • ↓ bridgeUserActions/tbt: -100%
  • ↑ bridgeUserActions/total: +42%
  • ↓ bridgeUserActions/fcp: -43%
  • ↑ bridgeUserActions/lcp: +1126%
Startup Benchmarks · Samples: 100
Benchmarkchrome-webpackfirefox-webpack
startupStandardHome
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
startupPowerUserHome
[Sentry log · main/release]
–🟡 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↓ startupStandardHome/numNetworkReqs: -14%
  • ↓ startupStandardHome/domInteractive: -29%
  • ↓ startupStandardHome/numNetworkReqs: -13%
  • ↓ startupStandardHome/fcp: -24%
  • ↑ startupPowerUserHome/uiStartup: +29%
  • ↑ startupPowerUserHome/load: +17%
  • ↑ startupPowerUserHome/domContentLoaded: +17%
  • ↑ startupPowerUserHome/domInteractive: +26%
  • ↑ startupPowerUserHome/backgroundConnect: +52%
  • ↑ startupPowerUserHome/firstReactRender: +18%
  • ↑ startupPowerUserHome/initialActions: +11%
  • ↑ startupPowerUserHome/loadScripts: +16%
  • ↑ startupPowerUserHome/setupStore: +280%
  • ↑ startupPowerUserHome/inp: +27%
  • ↑ startupPowerUserHome/fcp: +23%
  • ↑ startupPowerUserHome/lcp: +28%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 startupPowerUserHome/INP: p75 240ms
  • 🟡 startupPowerUserHome/LCP: p75 3.7s
User Journey Benchmarks · Samples: 5 · real API 🔴 4

⚠️ Missing data: chrome/webpack/userJourneyTransactions

Benchmarkchrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🔴 [CI log]
🔴 doneButtonToHomeScreen
🔴 total
🔴 [CI log]
🔴 total
onboardingNewWallet
[Sentry log · main/release]
🔴 [CI log]
🔴 total
🔴 [CI log]
🔴 total
assetDetails
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
solanaAssetDetails
[Sentry log · main/release]
🟢 [CI log]🟡 [CI log]
importSrpHome
[Sentry log · main/release]
🟡 [CI log]🟢 [CI log]
sendTransactions
[Sentry log · main/release]
–🟡 [CI log]
swap
[Sentry log · main/release]
–🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↓ onboardingImportWallet/srpButtonToSrpForm: -11%
  • ↓ onboardingImportWallet/confirmSrpToPwForm: -17%
  • ↓ onboardingImportWallet/pwFormToMetricsScreen: -16%
  • ↓ onboardingImportWallet/metricsToWalletReadyScreen: -17%
  • ↑ onboardingImportWallet/doneButtonToHomeScreen: +33%
  • ↑ onboardingImportWallet/openAccountMenuToAccountListLoaded: +167%
  • ↓ onboardingImportWallet/longTaskCount: -29%
  • ↓ onboardingImportWallet/longTaskTotalDuration: -35%
  • ↓ onboardingImportWallet/longTaskMaxDuration: -22%
  • ↓ onboardingImportWallet/tbt: -34%
  • ↑ onboardingImportWallet/total: +40%
  • ↓ onboardingNewWallet/agreeButtonToOnboardingSuccess: -11%
  • ↑ onboardingNewWallet/doneButtonToAssetList: +12%
  • ↑ onboardingNewWallet/tbt: +18%
  • ↑ onboardingNewWallet/total: +12%
  • ↑ solanaAssetDetails/assetClickToPriceChart: +30%
  • ↓ solanaAssetDetails/longTaskCount: -100%
  • ↓ solanaAssetDetails/longTaskTotalDuration: -100%
  • ↓ solanaAssetDetails/longTaskMaxDuration: -100%
  • ↓ solanaAssetDetails/tbt: -100%
  • ↑ solanaAssetDetails/total: +30%
  • ↑ solanaAssetDetails/fcp: +11%
  • ↑ solanaAssetDetails/lcp: +11%
  • ↑ importSrpHome/loginToHomeScreen: +25%
  • ↓ importSrpHome/homeAfterImportWithNewWallet: -24%
  • ↓ importSrpHome/longTaskCount: -15%
  • ↓ importSrpHome/longTaskTotalDuration: -22%
  • ↓ importSrpHome/longTaskMaxDuration: -22%
  • ↓ importSrpHome/tbt: -28%
  • ↓ importSrpHome/total: -24%
  • ↓ importSrpHome/cls: -15%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 importSrpHome/INP: p75 304ms
  • 🟡 importSrpHome/FCP: p75 1.8s
  • 🟡 solanaAssetDetails/FCP: p75 2.3s
  • 🟡 solanaAssetDetails/LCP: p75 3.1s
  • 🟡 sendTransactions/FCP: p75 2.0s
  • 🟡 sendTransactions/LCP: p75 2.5s
Dapp Page Load Benchmarks · Samples: 100
Benchmarkchrome-webpack
dappPageLoad
[Sentry log · main/release]
🟢 [CI log]
Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 4.25 KiB (0.03%)
  • ui: 34.03 KiB (0.19%)
  • common: 0 Bytes (0%)
  • other: 0 Bytes (0%)
  • contentScripts: 476 Bytes (0.02%)
  • zip: 47.71 KiB (0.22%)

🍒 What's in this RC

Cherry-picks (13 commits)
Commit Description
c81d0a92a3 release(runway): cherry-pick chore: bump nanoid to ^3.3.17 to clear GHSA-2v37-7h3g-55p8 (#45372)
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
75ea9568be Merge branch 'stable' into release/13.43.0

Changelog (163 commits since v13.42.0)
Commit Description
c81d0a92a3 release(runway): cherry-pick chore: bump nanoid to ^3.3.17 to clear GHSA-2v37-7h3g-55p8 (#45372)
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
76657f7a3c release: release-changelog/13.43.0 (#45056)
9da0748ed3 Merge release/13.42.0 into release/13.43.0
d90d1e76b8 fix(hardware-wallets): bound stuck account-creation spinner with device-read timeout cp-13.42.0 (#45048)
0311ca5fc9 feat: add trust security signals tdp (#44761)
3114315a0e fix: consume stx enabled flag for batch sell from selected chain (#45032)
3ae0ce34cc chore: clean up TextFieldSearch styles after MMDS package update (#45030)
51cff5563f test: fix flaky test Smart Transactions should send transaction using USDC to pay fee (#45036)
0610a607c7 feat(perps): wire dedicated aggregated order-book socket per UI connection (#45035)
d67a05b8aa ci(slsa): publish attestation bundles and pin run-build actions (INFRA-3786) (#44955)
666b247f3a test: fix flaky custom-token import E2E by waiting for the Add Custom Token network picker to settle TimeoutError: Waiting for element to be located By(css selector, [data-testid="custom-token-import-submit-button"]:not([disabled])) (#45025)
9afac38fe7 feat: new segment schema support (#43132)
bfdb62afa3 test: fix flaky test BTC Account - Activity Receive transaction is rendered with Received label and confirmed status (#45022)
0fdbade0f4 test: MMQA - 1916 - Refactor multiple-provider-connections.spec.ts to good practices (#44941)
33bef9f690 test: fix flaky perps watchlist explore TimeoutError: Waiting for element to be located By(css selector, [data-testid="market-list-filter-sort-row"]) (#44936)
6d53060f6b test: replace driver.waitForSelector with page object methods (#44898)
ed7b8fbd53 fix: patch for missing slip44 entries in core client-utils cp-13.42.0 (#45006)
7e9653a51f feat: added metrics for custom network page (#45031)
5a94f11f60 feat(activity): contact names in activity rows (#45013)
5f842c6082 test: fix flaky Add wallet Import wallet using SRP during onboardingand MetaMask onboarding should not prevent network requests to advanced... (#45034)
c36df0ec1a fix: vertically center contact copy button (#45020)
e3abdc3e78 feat: added timer for balance loading cp-13.42.0 (#45033)
b424876ab6 chore: update assets controllers for defi fix (#45003)
adec2ed351 refactor(wpc-1066): migrate pending-approval HW methods to LegacyBackgroundApiService (#44937)
20bf478a91 feat(confirmations): add Money Account Deposit developer option (#44945)
48ad866df4 bump(perps): upgrade @metamask/perps-controller to v10 (#45024)
239006e967 fix(notifications): add bottom padding to marketing consent text (#45021)
9158172d8a refactor(wpc-1067): migrate network enablement methods to LegacyBackgroundApiService (#44938)
62aaaa4923 test: order selectors and methods in all page objects (#44987)
45505c9910 chore: wire stellar asset component with stellar asset selector (#44979)
ce134bc060 feat: defi positions v2 controller (#44392)
b50797d25a chore: pass Firefox system access via geckodriver and pin 0.36.0 (#45014)
0c7372db98 fix(pure-black): use bg-default on back up SRP page (#44983)
e47424b771 fix(perps): show wallet-confirmed deposits immediately in Perps Activity (#44736)
9b623cccf7 ci: turn on the Triage and Retry System by default (no retry-ci label needed) (#44956)
778bafe559 feat(ramps): wire Buy Continue with background checkout watch (#44689)
10b5de87df test: lavamoat e2e (#44925)
c1a5d29ffd fix: swaps stale dest exchange rates cp-13.42.0 (#44968)
0fa0c88cf3 chore: fix lint:changed script (#45010)
fa5c57e727 fix: navigate to homepage after users close popup from batch sell (#44991)
7dce891afb feat(ramps): send Portfolio-connected wallets to Portfolio on Buy (#44804)
3739101671 fix(pure-black): refine SRP input empty vs filled styling (#45004)
1ec648fa36 chore: update swap consumers to use and display partial QuoteMetadata (#44630)
0660a05750 refactor(wpc-1068): migrate requestSafeReload & openUpdateTabAndReload to LegacyBackgroundApiService (#44940)
d2fdd13169 perf(6570): bump react-hooks to v7 and remove react-compiler plugin (#44495)
cf719e0334 fix(pure-black): stop inverting bridge transaction settings tooltip theme (#44964)
10fabf3ed6 chore: New Crowdin Translations by GitHub Action cp-13.42.0 (#44746)
806f4bf8b6 fix(pure-black): use BackgroundDefault for markets row skeleton (#44984)
da76cb3edb fix(pure-black): use bg-default on Snap install screen (#45002)
c20d7eb736 fix(pure-black): set send network filter button background to transparent (#44882)
04b53836a4 chore(STX): add Robinhood Chain to smart transactions supported networks (#44926)
284f97705e chore: popover for failed transaction status (#44961)
2668c42734 fix(pure-black): remove border from page footer cancel buttons (#44981)
d0efdd7df1 chore(storybook): add Pure Black toolbar toggle and component stories (#44963)
fadc943601 feat: assets unify balance and traces (#44978)
bad91a67e9 chore: replaced deprecated Tag component with MMDS tag (#44785)
dd2075062d fix(confirmations): refetch MetaMask Pay required token price when it is missing (#44950)
66b8f875e3 fix(pure-black): fix Menu background specificity with bg-section (#44966)
00f32ff73c fix: qr camera permission throwing e.isUnlocked is not a function (#44701)
b5ed10c4c2 feat(hardware-wallets): enable shared signing flow (#43947)
1695992b6f feat: migrate Infura IPFS users to dweb.link and block Infura IPFS gateway entry (#44982)
0ad8940da9 feat: use new snap keyring v2/v1 split (#44289)
b7f13b1a4c test: refactor transaction details page and consolidate selectors (#44694)
61ff089628 test(e2e): add Tron assets E2E cluster (#44852)
540d2a65b1 feat: bump transaction-pay-controller to 26.0.0 (#44782)
df415e426e test: skip ERC20 max balance WS update test (ASSETS-3385) (#44952)
f87e3bc8db fix(pure-black): remove custom background color from InfoPopoverTooltip (#44933)
634b46cfed fix(pure-black): remove border-l and bg-alternative from drawer in popup/compact sidepanel (#44960)
57da315640 test: pom lint rule supporting groups (selectors, constructor, actions) (#44789)
7e641c6203 chore: bump @types/chrome and drop custom chrome typings (#44888)
cbd1c50aaf perf(7466): add memoization to network/asset modal components (Batch D) (#44296)
75e09ed50f fix(pure-black): settings sidebar uses bg-alternative in pure black mode (#44883)
c164a38416 fix: clear the postcss advisories cp-13.42.0 (#44865)
3f6a9050c3 test: cover Token Detection Enabled identify trait (#44915)
91ed59bb42 chore: replace local gator permission detail schemas with @metamask/7715-permission-types (#44415)
a73805093a fix: excempt batch sell routes from ConfirmationRouter (#44951)
87d0cf9c0a fix(pure-black): set main action button dropdown to bg-alternative (#44881)
17731f5111 fix(pure-black): fix account address popover background and refactor row hover to Tailwind (#44880)
b8ee5bb2eb fix(pure-black): correct tooltip background and arrow colors in dark and pure black themes (#44879)
7b6dde7630 fix(pure-black): add bg-alternative and border to asset explorer view (#44878)
cfdbb033e8 bump: brace-expansion to 5.0.8 (#44924)
00ebfcf32e feat: updated import NFT flow Modal (#44899)
a5f18a53c5 fix: Allow QR singing in side panel on brave (#44934)
bdbe8f29c1 chore(6922): bump @testing-library/react to v14 (#42635)
b35834378b chore: upgrade design system packages (v57.0.0) (#44931)
58b697a400 fix: remove deprecated METAMASK_ENVIRONMENT=test in favor of testing (#44944)
4e37811629 chore: remove copy-to-clipboard dependency (#44890)
4d2065f6a5 test: add coverage for Notification Clicked metrics event (#44920)
da23672992 feat(analytics): migrate pre-consent queue to AnalyticsController (#43869)
5201492b01 feat: refactor non-zero native custom networks (#44161)
9e0cbd2538 fix: allow Firefox WebDriver system access for about:debugging (#44946)
992ff087e7 test(e2e): refactor tokens tab page object for assets coverage (#44778)
b8ad63da79 ci(amo): allow release-team manual dispatch of AMO production (INFRA-3769) (#44519)
bd65eccfdb chore: remove defi v2 fetching from getApi (#44939)
3cb496ea9a chore: migrate markNotificationPopupAsAutomaticallyClosed to LegacyBackgroundApiService (#44249)
f835f69039 feat: initialize DeFiPositionsControllerV2 (#44772)
171ed202b7 feat: add UAT env on bridge (#44895)
ca508307ef feat: bump phishing controller 17.3.0 (#44841)
56ffb74681 refactor(ui): use Arrow2UpRight for Send action icons (#44929)
9c8c6bcb8b fix(pure-black): set perps balance dropdown to bg-alternative (#44875)
cd32d2d252 chore: remove component-library README.mdx docs (#44886)
bab3498f9c chore: remove deprecated textfieldsearch components (#44918)
2bbf04046f ci: fixed labels from forks (#44022)
199066c701 fix: add missing events to bottom nav bar experiment config cp-13.42.0 (#44919)
d53496f910 chore: swap position of network picker and search bar on swaps asset picker (#44911)
9d573278ab chore(6927): upgrade redux to v8 (#44445)
2f528e3470 build: no more PNGs inside SVGs allowed, delete unused images (#44832)
4011ce9d91 Merge origin/main into stable-main-13.41.0
72ba3533f4 chore: bump assets controller to v11.2.1 (#44903)
cba9e41d31 chore: fix ESLint ignore config (#44914)
5bb1c5e23d feat: update HeaderSearch and asset picker modal search bars to use TextFieldSearch (#44910)
2be47e1c8d fix: handle missing account for cross-chain asset deeplinks cp-13.42.0 (#44904)
7fac1b56cb test(e2e): stabilize network filter open before switch-network click (#44692)
ba9268b8c7 test: fix flaky test error page support consent TimeoutError: Waiting element to become stale (#44850)
60e4cd1b48 test: fix flaky unstable Continue button in Send page (#44837)
c4d2caae67 feat: migrate swap asset picker search to DSR TextFieldSearch (#44905)
fba4cb3aa7 refactor: simplify sponsored fee row; cleanup dead code (#44872)
ff4fd4dbb8 chore: rename SettingsHeader to PageHeaderWithSearch (#44902)
b072b88aef fix: updated checkbox and permissions page width cp-13.42.0 (#44896)
4045b69287 chore: remove dead app header props (#44900)
15db15fe5b feat: align search bar UIs (#44430)
67db57c82a fix(transactions): avoid inflated fees from failed container estimates (#44308)
75e46239ee feat(ci): add CWS rollout adjustment workflow (INFRA-3651) (#44060)
a03a82855f refactor: cleanup activity selectors (#44864)
7d8a31630f test(e2e): add Tron network E2E cluster (#44164)
e7a6a5e59f fix: local-enriched bridge label when switching networks (#44858)
42146f2fa5 fix(activity): apply text color token to native dialog for dark theme cp-13.42.0 (#44863)
55ad54b09e fix: retry persistence writes once (#44003)
c08a8bb748 bump: tar to 7.5.22, ignore react-router advisories cp-13.41.0 (#44862)
cdddd817a4 fix(deep-links): restore interstitial protection cp-13.42.0 (#44830)
b6619a9fb8 fix(activity): transaction details width (#44853)
5d2cff8067 feat: keep the balance left aligned for lower viewport cp-13.42.0 (#44791)
fddbd0cf34 chore: remove swaps approval text (#44794)
71272d9cd3 test: cover Wallet Imported event (#44747)
47bb810f81 test(e2e): extend Tron fixtures for assets E2E coverage (#44784)
01588c978d chore(assets-controller): bump to 11.2.0 (#44847)
c8df352c4c fix(confirmations): use getAssetImageUrl for gas fee token icon (#44769)
eca1e7ed3f feat: defer password confirm mismatch error until minimum length. (#44790)
e40d3d1af9 ci: pass AI analyzer gate for medium Runway cherry-picks into release branches (#44779)
5147646d2f test(e2e): refactor tokens tab page object for assets coverage (#44777)
81508e447a feat(onboarding): update Google sign-in icon to new brand logo (#44755)
545dd73434 fix: gas sponsorship being shown for hw accounts when the user has selected a nonevm network (#44706)
4ed04ec772 fix: restored old behavior to show Paid by MetaMask label in sponsored transactions from activity page cp-13.41.0 (#44780)
ca4d467800 refactor: migrate Core UX secondary buttons to MMDS (#44767)
197093a62a test: cover Wallet Setup Started Segment event (#44668)
5c6ffe848d fix(ci): post RC Slack when Builds ready, not only green main (#44831)
8011cc033a fix: eliminate dark-mode background flash for pure black mode (#44743)
d667c1f177 feat: enable pure black dark mode by default (#44806)
c42c6cbe77 ci: update cla.yml with more Cursor names (#44815)
88e20cf90c fix(assets): include tokens with large balances and few decimals in aggregated balance cp-13.41.0 (#44796)
1e2f17bea8 feat: upgrade bridge packages to latest versions (#44722)
5fb686386e release: Bump main version to 13.43.0 (#44799)

AI Test Plan

Risk Score High Risk Medium Risk Files Changed Commits
55/100 6 6 1354 166
Cherry-Pick Scenarios (2)

High Risk Scenarios (1)

1. Smart Transactions – Tx Sentinel routing for Robinhood

Risk Level: HIGH

Why This Matters: Cherry-pick 45214 fixes Smart Transactions controller routing to the Robinhood tx-sentinel; incorrect routing would cause stuck or failed transactions for affected users.

Test Steps:

  1. Enable Smart Transactions and send a small ETH transfer on a Robinhood-integrated network (or the environment configured to use the Robinhood sentinel).
  2. In the transaction details, verify timely status updates (Submitted → Confirmed) and no stuck pending due to sentinel routing.
  3. Disable Smart Transactions and send again to verify legacy flow remains unaffected.
  4. Briefly disrupt connectivity after submit; confirm clear error/retry messaging without infinite pending.

Medium Risk Scenarios (1)

1. Perps – Order Book on Order Entry page

Risk Level: MEDIUM

Why This Matters: Cherry-pick 45151 adds a new order book in the order entry flow; rendering, real-time updates, and order placement integration must work to avoid broken trading experiences.

Test Steps:

  1. Open the Perps trading UI and select a liquid market (e.g., ETH-PERP); verify the order book renders with bids/asks.
  2. Confirm the book updates in real time; click a price level to prefill the order form.
  3. Place a small limit order and verify it appears under open orders with correct price/size.
  4. Switch markets and verify the book reloads; check an illiquid/empty market displays a graceful empty state.

Release Scenarios (10)

High Risk Scenarios (5)

1. State Migrations (220/221) – Full upgrade with rich user state

Risk Level: HIGH

Why This Matters: Migrations can corrupt/lose critical user state; a bad migration can break permissions, networks, or privacy settings across all users.

Test Steps:

  1. On 13.42.x, create 3+ accounts (incl. imported), add at least one custom network, connect to 2 dapps, add custom tokens/NFTs, install and enable a Snap, and opt OUT of MetaMetrics.
  2. Upgrade to 13.43.0 and unlock.
  3. Verify all accounts, balances, custom networks, connected sites/permissions, custom tokens/NFTs, and Snap enablement/permissions persist.
  4. Confirm MetaMetrics remains opted OUT and no telemetry is sent on navigation (inspect extension background DevTools -> Network).
  5. Perform basic actions (switch network, open activity, initiate a send and cancel before confirm) to ensure no migration-related crashes or warnings.

2. State Migrations (220/221) – Backfill/edge-case resilience

Risk Level: HIGH

Why This Matters: Real users often have older or partially corrupted state; migrations must be robust to avoid lockouts and data loss.

Test Steps:

  1. Prepare a pre-upgrade profile with intentionally missing or malformed optional fields (e.g., remove certain app-state/metametrics keys via state edit tool or QA fixture).
  2. Upgrade to 13.43.0 and unlock.
  3. Verify extension loads without white-screen or background errors; state keys are backfilled to safe defaults.
  4. Validate navigation through Home, Activity, and Settings works; no repeated migration prompts or loops.
  5. Export account state (if possible) and confirm schema alignment with new expected keys.

3. Transaction Flow – Smart Transactions on/off and fallback

Risk Level: HIGH

Why This Matters: Any regression in transaction submission, fee display, or status tracking can cause financial loss or user lockout.

Test Steps:

  1. Enable Smart Transactions in Settings -> Experimental (or equivalent), then send a small ETH transfer on Mainnet and confirm.
  2. In the activity/details view, verify Smart labeling, fee presentation, and timely status updates to confirmed.
  3. Disable Smart Transactions and repeat the send; verify legacy path works, with normal gas estimation and status.
  4. During a Smart Transaction submission, briefly disrupt network connectivity; verify user receives clear retry/failure messaging without stuck pending.
  5. Attempt Speed Up and Cancel on a pending Smart Transaction and verify correct behavior or informative limitations.

4. Network Management – Invalid Custom Network Alert

Risk Level: HIGH

Why This Matters: Incorrectly allowing actions on an invalid network can cause failed transactions and loss of user trust.

Test Steps:

  1. Add a custom network with a non-responsive or mismatched chainId RPC URL and switch to it.
  2. Verify the invalid custom network alert appears with actionable guidance.
  3. Attempt to initiate a swap or send; verify blocked or clearly warned flow, preventing accidental failures.
  4. Fix the RPC URL to a valid endpoint; confirm the alert disappears and transactions become available.
  5. Reload the extension to ensure alert state persists/clears correctly as the network validity changes.

5. Privacy & Telemetry – MetaMetrics Controller changes

Risk Level: HIGH

Why This Matters: Telemetry consent and event gating are critical for compliance and user trust; regressions can cause privacy violations.

Test Steps:

  1. In Settings, opt OUT of MetaMetrics, then switch networks, view activity, and open a token detail screen.
  2. Inspect extension background DevTools -> Network to verify no analytics endpoints are called.
  3. Opt IN to MetaMetrics and perform one send flow to confirmation; verify exactly expected analytics calls appear without PII leakage.
  4. Toggle opt-in/out again and reload; verify preference persists and behavior respects it.
  5. Confirm that consent prompts (if any) appear only once and do not regress across lock/unlock.

Medium Risk Scenarios (5)

1. Dapp Connections – Unconnected Account Alert behavior

Risk Level: MEDIUM

Why This Matters: Incorrect alerts can confuse users or lead to accidental actions with the wrong account.

Test Steps:

  1. Open a popular dapp (e.g., Uniswap) without connecting; verify the unconnected account alert appears in the extension when the site requests accounts.
  2. Connect one account to the site; verify the alert disappears.
  3. Switch to a different account that is not connected; verify the alert reappears and offers to connect.
  4. Disconnect the site from Settings -> Connected sites and reload the dapp; confirm the alert behavior is accurate.

2. Assets – Network filter and Control Bar behavior

Risk Level: MEDIUM

Why This Matters: Incorrect filtering can hide assets or mislead users about balances, causing support issues and loss of trust.

Test Steps:

  1. On the Tokens list, switch the control bar filter between All networks and Home network; verify token counts and balances update accordingly.
  2. Open the Home network filter modal and pick a different network; verify selection persists and the list updates.
  3. Combine filters (e.g., hide zero balances if available) and confirm the list remains accurate and performant.
  4. Navigate away and back; verify filters persist across sessions.

3. Balances – Account group balance aggregation

Risk Level: MEDIUM

Why This Matters: Incorrect totals or rounding lead to user confusion and perceived balance discrepancies.

Test Steps:

  1. With multiple accounts across at least two networks, verify the account group balance equals the sum of visible account balances in the selected currency.
  2. Toggle currency conversion (e.g., USD) and confirm totals recalculate accurately with current rates.
  3. Toggle visibility filters (e.g., hide small balances) and verify the group total reflects only visible assets.
  4. Refresh the extension and ensure the aggregated balance remains consistent and without flicker.

4. Perps – Streaming/bridge stability (market data updates)

Risk Level: MEDIUM

Why This Matters: Streaming regressions can degrade performance or show stale prices, risking user mistakes.

Test Steps:

  1. Open the Perps/trading page and select an active market; verify live data updates (prices/spreads) without UI freezes.
  2. Switch networks or lock/unlock while the page is open; ensure the stream resumes without errors.
  3. Simulate brief offline/online transitions; verify reconnection and no duplicate or stale data display.
  4. Confirm CPU/memory remain reasonable during sustained updates.

5. App State – Lock/Unlock and UI state persistence

Risk Level: MEDIUM

Why This Matters: App state controller changes can cause navigation glitches that block access to core features.

Test Steps:

  1. Open the extension to a non-default view (e.g., a token detail or activity tab).
  2. Lock the wallet, then unlock.
  3. Verify return to a sensible state (no blank screens, no incorrect navigation loops).
  4. Reload the extension; verify last-used tab/view persistence works as expected.

Teams Sign-off Status

Signed off: None yet

Awaiting sign-off (7):
Accounts, Assets, Networks, Security, Swaps and Bridge, Transactions, Wallet Integrations


Generated by AI Test Plan Analyzer (gpt-5) at 2026-08-10T18:27:52.032Z

AI generated test plan (JSON): test-plan-13.43.0.json

…lear `GHSA-55q2-fjhq-7xh7` (#45377)

- chore: bump `dompurify` to `3.4.13` to clear `GHSA-55q2-fjhq-7xh7`
cp-13.43.0 (#45364)

## **Description**

`dompurify` is a direct production dependency.
[GHSA-55q2-fjhq-7xh7](GHSA-55q2-fjhq-7xh7)
covers `<= 3.4.12` — during `IN_PLACE` sanitization a hook that removes
an element leaves that element's detached descendants executable,
because `_sanitizeElements()` returns early without calling
`_neutralizeSubtree()`.

**This is not a plain version bump.** `dompurify` was declared *as a
patch spec* in both `dependencies` and `resolutions`, each hard-pinning
the exact version 3.4.12, so `yarn up dompurify` cannot move it. Three
things change together:

- the dependency spec → `patch:dompurify@npm%3A3.4.13#...`
- the matching `resolutions` entry
- the patch itself, rebased 3.4.12 → 3.4.13 via `yarn patch` / `yarn
patch-commit`

**The carried-forward patch is unrelated to this advisory** — it
rewrites `'<!-->'` and `'<!---->'` as concatenations so the literals do
not trip LavaMoat's `SES_HTML_COMMENT_REJECTED`. Same two edits, only
line offsets moved:

```diff
-      dirty = '<!-->';
+      // Modifying to avoid lavamoat SES_HTML_COMMENT_REJECTED
+      dirty = '<!' + '--' + '>';
-      body = _initDocument('<!---->');
+      // Modifying to avoid lavamoat SES_HTML_COMMENT_REJECTED
+      body = _initDocument('<!' + '--' + '--' + '>');
```

### Patch scope: carried forward unchanged

The 3.4.12 patch covered three bundles; this covers the same three — 3
files, 6 hunks. `dist/purify.js` is the UMD build, so it takes the same
two edits one indent level deeper.

Verified rather than asserted — both the `+`/`-` content and the file
set diff clean against the 3.4.12 patch:

```
diff <(grep -E '^[+-]' old.patch | grep -vE '^(\+\+\+|---)' | sort) \
     <(grep -E '^[+-]' new.patch | grep -vE '^(\+\+\+|---)' | sort)   # no output
```

## **Changelog**

CHANGELOG entry: null

## **Related issues**

Fixes: #45325

Reachability triage for this advisory — why the vulnerable path is not
reachable as we use DOMPurify, and why an upgrade was still the cheaper
disposition than a suppression with a guarded invariant:

#45325 (comment)

## **Manual testing steps**

Verification is against the **installed artifact**, not the manifest — a
patch that silently failed to apply would still leave `package.json`
looking correct.

1. `yarn install`
2. `cat node_modules/dompurify/package.json | grep version` → `3.4.13`
3. `grep -c "'<!' + '--'"
node_modules/dompurify/dist/purify.{cjs.js,es.mjs}` → `2` each (patch
applied)
4. `grep -c "dirty = '<!-->'"
node_modules/dompurify/dist/purify.{cjs.js,es.mjs}` → `0` each (no
unpatched literals)
5. `grep -c "_neutralizeSubtree(currentNode)"
node_modules/dompurify/dist/purify.cjs.js` → `2` (upstream fix present
on both hook-detach paths)
6. `yarn npm audit --recursive --environment production`
7. `yarn jest
ui/pages/notifications/notification-components/feature-announcement`

### Results on this branch

| check | result |
|---|---|
| installed version | **3.4.13** |
| SES patch applied | 2 occurrences in each of all three bundles |
| patch scope | 3 files / 6 hunks — identical file set and `+`/`-`
content to the 3.4.12 patch |
| unpatched literals remaining | **0** in both files |
| upstream fix present | `_neutralizeSubtree(currentNode)` guards
**both** hook-detach returns |
| production audit | dompurify **not flagged** |
| consumer tests | **11/11 passing** |
| diff scope | `package.json` 4 lines, `yarn.lock` 18 lines, patch
renamed 3.4.12 → 3.4.13 |

## **Screenshots/Recordings**

N/A — no user-visible change.

## **Pre-merge author checklist**

- [x] I've followed [MetaMask Contributor
Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask
Extension Coding

Standards](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/CODING_GUIDELINES.md).
- [x] I've completed the PR template to the best of my ability
- [ ] I’ve included tests if applicable — N/A, dependency bump; existing
consumer suite exercised
- [ ] I’ve documented my code using [JSDoc](https://jsdoc.app/) format
if applicable — N/A
- [x] I’ve applied the right labels on the PR (see [labeling

guidelines](https://github.com/MetaMask/metamask-extension/blob/main/.github/guidelines/LABELING_GUIDELINES.md)).
Not required for external contributors.

## **Pre-merge reviewer checklist**

- [ ] I've manually tested the PR (e.g. pull and build branch, run the
app, test code being changed).
- [ ] I confirm that this PR addresses all acceptance criteria described
in the ticket it closes and includes the necessary testing evidence such
as recordings and or screenshots.

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Dependency-only security upgrade with the same behavioral patch as
before; no application code changes, though dompurify is on the HTML
sanitization path.
> 
> **Overview**
> **Upgrades `dompurify` from 3.4.12 to 3.4.13** to address
**GHSA-55q2-fjhq-7xh7** (hook-driven element removal could leave
detached descendants unsanitized in `IN_PLACE` mode). Because the
dependency is pinned as a Yarn **patch** spec in both `dependencies` and
`resolutions`, the change updates those entries and `yarn.lock` to
`patch:dompurify@npm%3A3.4.13#...` rather than a simple version bump.
> 
> The existing **LavaMoat** workaround is **rebased unchanged** onto
3.4.13: HTML comment placeholders (`'<!-->'`, `'<!---->'`) are built via
string concatenation in the three dist bundles so they do not trigger
`SES_HTML_COMMENT_REJECTED`.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
f49a90a. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
[0967a06](0967a06)

---------

Co-authored-by: Jongsun Suh <jongsun.suh@icloud.com>
Co-authored-by: MetaMask Bot <metamaskbot@users.noreply.github.com>
@metamask-ci

ghost commented Aug 10, 2026

Copy link
Copy Markdown
Contributor
Builds ready [a70b6f9]
⚡ Performance Benchmarks (Total: 🟢 13 pass · 🟡 5 warn · 🔴 4 fail)

Baseline (latest main): 171ed20 | Date: 7/28/2026 | Pipeline: 31420224789 | Baseline logs

Metricschrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🔴 openAccountMenuToAccountListLoaded(p95) [CI log]🔴 [CI log]
onboardingNewWallet
[Sentry log · main/release]
🔴 longTaskMaxDuration(p95) [CI log]🔴 [CI log]

Regressions (🔴 4 failures)

Interaction Benchmarks · Samples: 5
Benchmarkchrome-webpackfirefox-webpack
loadNewAccount
[Sentry log · main/release]
🟡 [CI log]
🟡 load_new_account
🟢 [CI log]
confirmTx
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
bridgeUserActions
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↑ loadNewAccount/load_new_account: +18%
  • ↑ loadNewAccount/total: +18%
  • ↑ bridgeUserActions/bridge_load_asset_picker: +13%
  • ↑ bridgeUserActions/longTaskCount: +11%
  • ↑ bridgeUserActions/longTaskTotalDuration: +21%
  • ↑ bridgeUserActions/tbt: +43%
  • ↓ loadNewAccount/fcp: -64%
  • ↑ loadNewAccount/lcp: +945%
  • ↓ confirmTx/longTaskCount: -100%
  • ↓ confirmTx/longTaskTotalDuration: -100%
  • ↓ confirmTx/longTaskMaxDuration: -100%
  • ↓ confirmTx/tbt: -100%
  • ↓ confirmTx/inp: -32%
  • ↓ confirmTx/fcp: -68%
  • ↑ confirmTx/lcp: +1203%
  • ↑ bridgeUserActions/bridge_load_page: +149%
  • ↑ bridgeUserActions/bridge_load_asset_picker: +95%
  • ↓ bridgeUserActions/longTaskCount: -100%
  • ↓ bridgeUserActions/longTaskTotalDuration: -100%
  • ↓ bridgeUserActions/longTaskMaxDuration: -100%
  • ↓ bridgeUserActions/tbt: -100%
  • ↑ bridgeUserActions/total: +22%
  • ↓ bridgeUserActions/inp: -31%
  • ↓ bridgeUserActions/fcp: -71%
  • ↑ bridgeUserActions/lcp: +1186%
Startup Benchmarks · Samples: 100
Benchmarkchrome-webpackfirefox-webpack
startupStandardHome
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
startupPowerUserHome
[Sentry log · main/release]
–🟡 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↓ startupStandardHome/numNetworkReqs: -14%
  • ↓ startupStandardHome/domInteractive: -29%
  • ↓ startupStandardHome/initialActions: -50%
  • ↓ startupStandardHome/numNetworkReqs: -13%
  • ↓ startupStandardHome/fcp: -26%
  • ↑ startupPowerUserHome/load: +15%
  • ↑ startupPowerUserHome/domContentLoaded: +15%
  • ↑ startupPowerUserHome/domInteractive: +20%
  • ↑ startupPowerUserHome/backgroundConnect: +15%
  • ↑ startupPowerUserHome/firstReactRender: +17%
  • ↑ startupPowerUserHome/initialActions: +11%
  • ↑ startupPowerUserHome/loadScripts: +13%
  • ↓ startupPowerUserHome/setupStore: -68%
  • ↑ startupPowerUserHome/inp: +10%
  • ↑ startupPowerUserHome/fcp: +17%
  • ↑ startupPowerUserHome/lcp: +10%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 startupPowerUserHome/INP: p75 208ms
  • 🟡 startupPowerUserHome/LCP: p75 3.2s
User Journey Benchmarks · Samples: 5 · real API 🔴 4

⚠️ Missing data: chrome/webpack/userJourneyTransactions

Benchmarkchrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🔴 [CI log]
🔴 doneButtonToHomeScreen
🔴 total
🔴 [CI log]
🔴 total
onboardingNewWallet
[Sentry log · main/release]
🔴 [CI log]
🔴 total
🔴 [CI log]
🔴 total
assetDetails
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
solanaAssetDetails
[Sentry log · main/release]
🟢 [CI log]🟡 [CI log]
importSrpHome
[Sentry log · main/release]
🟡 [CI log]🟢 [CI log]
sendTransactions
[Sentry log · main/release]
–🟡 [CI log]
swap
[Sentry log · main/release]
–🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↓ onboardingImportWallet/doneButtonToHomeScreen: -37%
  • ↑ onboardingImportWallet/openAccountMenuToAccountListLoaded: +132%
  • ↑ onboardingImportWallet/longTaskCount: +29%
  • ↑ onboardingImportWallet/longTaskTotalDuration: +27%
  • ↑ onboardingImportWallet/tbt: +23%
  • ↓ onboardingNewWallet/skipBackupToMetricsScreen: -17%
  • ↓ onboardingNewWallet/agreeButtonToOnboardingSuccess: -13%
  • ↑ onboardingNewWallet/tbt: +10%
  • ↓ solanaAssetDetails/longTaskCount: -100%
  • ↓ solanaAssetDetails/longTaskTotalDuration: -100%
  • ↓ solanaAssetDetails/longTaskMaxDuration: -100%
  • ↓ solanaAssetDetails/tbt: -100%
  • ↑ solanaAssetDetails/lcp: +713%
  • ↑ importSrpHome/openAccountMenuAfterLogin: +10%
  • ↑ importSrpHome/homeAfterImportWithNewWallet: +25%
  • ↑ importSrpHome/longTaskMaxDuration: +17%
  • ↑ importSrpHome/tbt: +11%
  • ↑ importSrpHome/total: +24%
  • ↓ importSrpHome/inp: -12%
  • ↑ importSrpHome/lcp: +16%
  • ↓ importSrpHome/cls: -11%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 importSrpHome/INP: p75 272ms
  • 🟡 importSrpHome/FCP: p75 1.8s
  • 🟡 solanaAssetDetails/FCP: p75 2.0s
  • 🟡 solanaAssetDetails/LCP: p75 2.5s
  • 🟡 sendTransactions/INP: p75 216ms
  • 🟡 sendTransactions/FCP: p75 2.0s
  • 🟡 sendTransactions/LCP: p75 2.7s
Dapp Page Load Benchmarks · Samples: 100
Benchmarkchrome-webpack
dappPageLoad
[Sentry log · main/release]
🟢 [CI log]
Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 4.25 KiB (0.03%)
  • ui: 34.29 KiB (0.19%)
  • common: 0 Bytes (0%)
  • other: 0 Bytes (0%)
  • contentScripts: 476 Bytes (0.02%)
  • zip: 47.78 KiB (0.22%)

🍒 What's in this RC

Cherry-picks (14 commits)
Commit Description
a70b6f95ab release(runway): cherry-pick chore: bump dompurify to 3.4.13 to clear GHSA-55q2-fjhq-7xh7 (#45377)
c81d0a92a3 release(runway): cherry-pick chore: bump nanoid to ^3.3.17 to clear GHSA-2v37-7h3g-55p8 (#45372)
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
75ea9568be Merge branch 'stable' into release/13.43.0

Changelog (164 commits since v13.42.0)
Commit Description
a70b6f95ab release(runway): cherry-pick chore: bump dompurify to 3.4.13 to clear GHSA-55q2-fjhq-7xh7 (#45377)
c81d0a92a3 release(runway): cherry-pick chore: bump nanoid to ^3.3.17 to clear GHSA-2v37-7h3g-55p8 (#45372)
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
76657f7a3c release: release-changelog/13.43.0 (#45056)
9da0748ed3 Merge release/13.42.0 into release/13.43.0
d90d1e76b8 fix(hardware-wallets): bound stuck account-creation spinner with device-read timeout cp-13.42.0 (#45048)
0311ca5fc9 feat: add trust security signals tdp (#44761)
3114315a0e fix: consume stx enabled flag for batch sell from selected chain (#45032)
3ae0ce34cc chore: clean up TextFieldSearch styles after MMDS package update (#45030)
51cff5563f test: fix flaky test Smart Transactions should send transaction using USDC to pay fee (#45036)
0610a607c7 feat(perps): wire dedicated aggregated order-book socket per UI connection (#45035)
d67a05b8aa ci(slsa): publish attestation bundles and pin run-build actions (INFRA-3786) (#44955)
666b247f3a test: fix flaky custom-token import E2E by waiting for the Add Custom Token network picker to settle TimeoutError: Waiting for element to be located By(css selector, [data-testid="custom-token-import-submit-button"]:not([disabled])) (#45025)
9afac38fe7 feat: new segment schema support (#43132)
bfdb62afa3 test: fix flaky test BTC Account - Activity Receive transaction is rendered with Received label and confirmed status (#45022)
0fdbade0f4 test: MMQA - 1916 - Refactor multiple-provider-connections.spec.ts to good practices (#44941)
33bef9f690 test: fix flaky perps watchlist explore TimeoutError: Waiting for element to be located By(css selector, [data-testid="market-list-filter-sort-row"]) (#44936)
6d53060f6b test: replace driver.waitForSelector with page object methods (#44898)
ed7b8fbd53 fix: patch for missing slip44 entries in core client-utils cp-13.42.0 (#45006)
7e9653a51f feat: added metrics for custom network page (#45031)
5a94f11f60 feat(activity): contact names in activity rows (#45013)
5f842c6082 test: fix flaky Add wallet Import wallet using SRP during onboardingand MetaMask onboarding should not prevent network requests to advanced... (#45034)
c36df0ec1a fix: vertically center contact copy button (#45020)
e3abdc3e78 feat: added timer for balance loading cp-13.42.0 (#45033)
b424876ab6 chore: update assets controllers for defi fix (#45003)
adec2ed351 refactor(wpc-1066): migrate pending-approval HW methods to LegacyBackgroundApiService (#44937)
20bf478a91 feat(confirmations): add Money Account Deposit developer option (#44945)
48ad866df4 bump(perps): upgrade @metamask/perps-controller to v10 (#45024)
239006e967 fix(notifications): add bottom padding to marketing consent text (#45021)
9158172d8a refactor(wpc-1067): migrate network enablement methods to LegacyBackgroundApiService (#44938)
62aaaa4923 test: order selectors and methods in all page objects (#44987)
45505c9910 chore: wire stellar asset component with stellar asset selector (#44979)
ce134bc060 feat: defi positions v2 controller (#44392)
b50797d25a chore: pass Firefox system access via geckodriver and pin 0.36.0 (#45014)
0c7372db98 fix(pure-black): use bg-default on back up SRP page (#44983)
e47424b771 fix(perps): show wallet-confirmed deposits immediately in Perps Activity (#44736)
9b623cccf7 ci: turn on the Triage and Retry System by default (no retry-ci label needed) (#44956)
778bafe559 feat(ramps): wire Buy Continue with background checkout watch (#44689)
10b5de87df test: lavamoat e2e (#44925)
c1a5d29ffd fix: swaps stale dest exchange rates cp-13.42.0 (#44968)
0fa0c88cf3 chore: fix lint:changed script (#45010)
fa5c57e727 fix: navigate to homepage after users close popup from batch sell (#44991)
7dce891afb feat(ramps): send Portfolio-connected wallets to Portfolio on Buy (#44804)
3739101671 fix(pure-black): refine SRP input empty vs filled styling (#45004)
1ec648fa36 chore: update swap consumers to use and display partial QuoteMetadata (#44630)
0660a05750 refactor(wpc-1068): migrate requestSafeReload & openUpdateTabAndReload to LegacyBackgroundApiService (#44940)
d2fdd13169 perf(6570): bump react-hooks to v7 and remove react-compiler plugin (#44495)
cf719e0334 fix(pure-black): stop inverting bridge transaction settings tooltip theme (#44964)
10fabf3ed6 chore: New Crowdin Translations by GitHub Action cp-13.42.0 (#44746)
806f4bf8b6 fix(pure-black): use BackgroundDefault for markets row skeleton (#44984)
da76cb3edb fix(pure-black): use bg-default on Snap install screen (#45002)
c20d7eb736 fix(pure-black): set send network filter button background to transparent (#44882)
04b53836a4 chore(STX): add Robinhood Chain to smart transactions supported networks (#44926)
284f97705e chore: popover for failed transaction status (#44961)
2668c42734 fix(pure-black): remove border from page footer cancel buttons (#44981)
d0efdd7df1 chore(storybook): add Pure Black toolbar toggle and component stories (#44963)
fadc943601 feat: assets unify balance and traces (#44978)
bad91a67e9 chore: replaced deprecated Tag component with MMDS tag (#44785)
dd2075062d fix(confirmations): refetch MetaMask Pay required token price when it is missing (#44950)
66b8f875e3 fix(pure-black): fix Menu background specificity with bg-section (#44966)
00f32ff73c fix: qr camera permission throwing e.isUnlocked is not a function (#44701)
b5ed10c4c2 feat(hardware-wallets): enable shared signing flow (#43947)
1695992b6f feat: migrate Infura IPFS users to dweb.link and block Infura IPFS gateway entry (#44982)
0ad8940da9 feat: use new snap keyring v2/v1 split (#44289)
b7f13b1a4c test: refactor transaction details page and consolidate selectors (#44694)
61ff089628 test(e2e): add Tron assets E2E cluster (#44852)
540d2a65b1 feat: bump transaction-pay-controller to 26.0.0 (#44782)
df415e426e test: skip ERC20 max balance WS update test (ASSETS-3385) (#44952)
f87e3bc8db fix(pure-black): remove custom background color from InfoPopoverTooltip (#44933)
634b46cfed fix(pure-black): remove border-l and bg-alternative from drawer in popup/compact sidepanel (#44960)
57da315640 test: pom lint rule supporting groups (selectors, constructor, actions) (#44789)
7e641c6203 chore: bump @types/chrome and drop custom chrome typings (#44888)
cbd1c50aaf perf(7466): add memoization to network/asset modal components (Batch D) (#44296)
75e09ed50f fix(pure-black): settings sidebar uses bg-alternative in pure black mode (#44883)
c164a38416 fix: clear the postcss advisories cp-13.42.0 (#44865)
3f6a9050c3 test: cover Token Detection Enabled identify trait (#44915)
91ed59bb42 chore: replace local gator permission detail schemas with @metamask/7715-permission-types (#44415)
a73805093a fix: excempt batch sell routes from ConfirmationRouter (#44951)
87d0cf9c0a fix(pure-black): set main action button dropdown to bg-alternative (#44881)
17731f5111 fix(pure-black): fix account address popover background and refactor row hover to Tailwind (#44880)
b8ee5bb2eb fix(pure-black): correct tooltip background and arrow colors in dark and pure black themes (#44879)
7b6dde7630 fix(pure-black): add bg-alternative and border to asset explorer view (#44878)
cfdbb033e8 bump: brace-expansion to 5.0.8 (#44924)
00ebfcf32e feat: updated import NFT flow Modal (#44899)
a5f18a53c5 fix: Allow QR singing in side panel on brave (#44934)
bdbe8f29c1 chore(6922): bump @testing-library/react to v14 (#42635)
b35834378b chore: upgrade design system packages (v57.0.0) (#44931)
58b697a400 fix: remove deprecated METAMASK_ENVIRONMENT=test in favor of testing (#44944)
4e37811629 chore: remove copy-to-clipboard dependency (#44890)
4d2065f6a5 test: add coverage for Notification Clicked metrics event (#44920)
da23672992 feat(analytics): migrate pre-consent queue to AnalyticsController (#43869)
5201492b01 feat: refactor non-zero native custom networks (#44161)
9e0cbd2538 fix: allow Firefox WebDriver system access for about:debugging (#44946)
992ff087e7 test(e2e): refactor tokens tab page object for assets coverage (#44778)
b8ad63da79 ci(amo): allow release-team manual dispatch of AMO production (INFRA-3769) (#44519)
bd65eccfdb chore: remove defi v2 fetching from getApi (#44939)
3cb496ea9a chore: migrate markNotificationPopupAsAutomaticallyClosed to LegacyBackgroundApiService (#44249)
f835f69039 feat: initialize DeFiPositionsControllerV2 (#44772)
171ed202b7 feat: add UAT env on bridge (#44895)
ca508307ef feat: bump phishing controller 17.3.0 (#44841)
56ffb74681 refactor(ui): use Arrow2UpRight for Send action icons (#44929)
9c8c6bcb8b fix(pure-black): set perps balance dropdown to bg-alternative (#44875)
cd32d2d252 chore: remove component-library README.mdx docs (#44886)
bab3498f9c chore: remove deprecated textfieldsearch components (#44918)
2bbf04046f ci: fixed labels from forks (#44022)
199066c701 fix: add missing events to bottom nav bar experiment config cp-13.42.0 (#44919)
d53496f910 chore: swap position of network picker and search bar on swaps asset picker (#44911)
9d573278ab chore(6927): upgrade redux to v8 (#44445)
2f528e3470 build: no more PNGs inside SVGs allowed, delete unused images (#44832)
4011ce9d91 Merge origin/main into stable-main-13.41.0
72ba3533f4 chore: bump assets controller to v11.2.1 (#44903)
cba9e41d31 chore: fix ESLint ignore config (#44914)
5bb1c5e23d feat: update HeaderSearch and asset picker modal search bars to use TextFieldSearch (#44910)
2be47e1c8d fix: handle missing account for cross-chain asset deeplinks cp-13.42.0 (#44904)
7fac1b56cb test(e2e): stabilize network filter open before switch-network click (#44692)
ba9268b8c7 test: fix flaky test error page support consent TimeoutError: Waiting element to become stale (#44850)
60e4cd1b48 test: fix flaky unstable Continue button in Send page (#44837)
c4d2caae67 feat: migrate swap asset picker search to DSR TextFieldSearch (#44905)
fba4cb3aa7 refactor: simplify sponsored fee row; cleanup dead code (#44872)
ff4fd4dbb8 chore: rename SettingsHeader to PageHeaderWithSearch (#44902)
b072b88aef fix: updated checkbox and permissions page width cp-13.42.0 (#44896)
4045b69287 chore: remove dead app header props (#44900)
15db15fe5b feat: align search bar UIs (#44430)
67db57c82a fix(transactions): avoid inflated fees from failed container estimates (#44308)
75e46239ee feat(ci): add CWS rollout adjustment workflow (INFRA-3651) (#44060)
a03a82855f refactor: cleanup activity selectors (#44864)
7d8a31630f test(e2e): add Tron network E2E cluster (#44164)
e7a6a5e59f fix: local-enriched bridge label when switching networks (#44858)
42146f2fa5 fix(activity): apply text color token to native dialog for dark theme cp-13.42.0 (#44863)
55ad54b09e fix: retry persistence writes once (#44003)
c08a8bb748 bump: tar to 7.5.22, ignore react-router advisories cp-13.41.0 (#44862)
cdddd817a4 fix(deep-links): restore interstitial protection cp-13.42.0 (#44830)
b6619a9fb8 fix(activity): transaction details width (#44853)
5d2cff8067 feat: keep the balance left aligned for lower viewport cp-13.42.0 (#44791)
fddbd0cf34 chore: remove swaps approval text (#44794)
71272d9cd3 test: cover Wallet Imported event (#44747)
47bb810f81 test(e2e): extend Tron fixtures for assets E2E coverage (#44784)
01588c978d chore(assets-controller): bump to 11.2.0 (#44847)
c8df352c4c fix(confirmations): use getAssetImageUrl for gas fee token icon (#44769)
eca1e7ed3f feat: defer password confirm mismatch error until minimum length. (#44790)
e40d3d1af9 ci: pass AI analyzer gate for medium Runway cherry-picks into release branches (#44779)
5147646d2f test(e2e): refactor tokens tab page object for assets coverage (#44777)
81508e447a feat(onboarding): update Google sign-in icon to new brand logo (#44755)
545dd73434 fix: gas sponsorship being shown for hw accounts when the user has selected a nonevm network (#44706)
4ed04ec772 fix: restored old behavior to show Paid by MetaMask label in sponsored transactions from activity page cp-13.41.0 (#44780)
ca4d467800 refactor: migrate Core UX secondary buttons to MMDS (#44767)
197093a62a test: cover Wallet Setup Started Segment event (#44668)
5c6ffe848d fix(ci): post RC Slack when Builds ready, not only green main (#44831)
8011cc033a fix: eliminate dark-mode background flash for pure black mode (#44743)
d667c1f177 feat: enable pure black dark mode by default (#44806)
c42c6cbe77 ci: update cla.yml with more Cursor names (#44815)
88e20cf90c fix(assets): include tokens with large balances and few decimals in aggregated balance cp-13.41.0 (#44796)
1e2f17bea8 feat: upgrade bridge packages to latest versions (#44722)
5fb686386e release: Bump main version to 13.43.0 (#44799)

AI Test Plan

Risk Score High Risk Medium Risk Files Changed Commits
55/100 6 6 1355 167
Cherry-Pick Scenarios (2)

High Risk Scenarios (1)

1. Smart Transactions - tx-sentinel (Robinhood URL) integration

Risk Level: HIGH

Why This Matters: Cherry-pick 45214 fixes Smart Transactions controller routing by adding a tx-sentinel Robinhood URL; a misconfiguration here can break submissions or protection checks globally.

Test Steps:

  1. Enable Smart Transactions if available (Settings > Experimental/Advanced).
  2. On a supported network (e.g., Ethereum mainnet), initiate a Smart Transaction (e.g., Send or Swap that routes via STX) and proceed to submission.
  3. Monitor DevTools Network for calls to the tx-sentinel Robinhood URL and ensure 2xx responses; confirm the transaction progresses through statuses (Submitted → Confirmed) without sentinel errors.
  4. Retry with a second transaction to ensure no flaky failures or blocked submissions.

Medium Risk Scenarios (1)

1. Perps - Order book on Order Entry page

Risk Level: MEDIUM

Why This Matters: Cherry-pick 45151 introduces a new order book UI within the entry flow; streaming data or render issues can block trading and degrade user trust.

Test Steps:

  1. Open the Perps Order Entry page (e.g., via Portfolio dapp connected to the extension) and ensure the extension is connected.
  2. Verify the order book renders with bids/asks and updates within a few seconds without manual refresh.
  3. Switch trading pairs or networks and confirm the book re-renders and streams correctly (no stale data or disconnect banners).
  4. Place a small test/limit order or simulate the action if available; confirm the UI uses current book data and no errors occur.

Release Scenarios (10)

High Risk Scenarios (5)

1. State Migrations (220/221) - Upgrade resilience

Risk Level: HIGH

Why This Matters: Migrations can corrupt or drop persisted data; ensuring seamless upgrade prevents account loss, broken connections, or privacy regressions.

Test Steps:

  1. On 13.42.x (or prior), create a wallet with 2+ accounts, add at least 1 custom RPC network, watch 3+ tokens, and connect two distinct sites (one per account).
  2. Opt-in to MetaMetrics, enable/disable a few privacy settings, and reorder accounts.
  3. Upgrade the same profile to 13.43.0 and unlock.
  4. Verify accounts (order and balances), connected sites per account, watched tokens, and custom networks all persist; confirm no blank screen or unexpected logout.
  5. Open Settings > Advanced/Privacy and verify all prior preferences (including MetaMetrics opt-in state) are preserved.

2. MetaMetrics Controller changes - consent and event gating

Risk Level: HIGH

Why This Matters: Changes to MetaMetrics controller can silently break consent gating or spam analytics; this directly impacts user privacy and compliance.

Test Steps:

  1. After upgrading to 13.43.0, go to Settings > Security & Privacy and verify the 'Participate in MetaMetrics' toggle reflects the pre-upgrade choice.
  2. With the toggle OFF, initiate a simple Send flow up to (but not including) final confirm and monitor DevTools Network for analytics endpoints (e.g., Segment/metrics); ensure no events are sent.
  3. Turn the toggle ON, repeat the Send flow, and confirm at least one analytics event is sent.
  4. Lock and unlock the extension; verify the consent toggle remains accurate and events remain gated accordingly.

3. Assets list control bar and network filtering

Risk Level: HIGH

Why This Matters: Multiple UI components changed around network filtering; any mismatch can hide assets or mislead users about balances.

Test Steps:

  1. On the Assets tab, use the control bar to switch between 'All networks' and 'Current network'; verify the token list updates accordingly.
  2. Open the 'Home network filter' modal, enable/disable specific networks, and confirm the Assets list reflects the selection immediately.
  3. Change the active network from the network pickers; confirm the control bar/network filter stay in sync and selections persist after closing/reopening the extension.
  4. Validate empty states (no tokens on a filtered network) and that removing filters restores expected tokens.

4. Invalid Custom Network Alert

Risk Level: HIGH

Why This Matters: Prevents users from transacting on misconfigured networks, reducing the risk of lost funds.

Test Steps:

  1. Add a custom RPC whose reported chainId does not match the configured chainId (or returns inconsistent network data).
  2. Switch to this custom network and open the extension home.
  3. Verify the 'Invalid custom network' alert appears and prevents risky actions (e.g., sending or connecting).
  4. Switch back to a valid network and ensure the alert dismisses automatically.

5. Unconnected Account Alert for dapps

Risk Level: HIGH

Why This Matters: Prevents accidental use of the wrong account with dapps, a common cause of user error.

Test Steps:

  1. Connect Site A to Account 1 only.
  2. In the extension, switch the selected account to Account 2 and return to Site A.
  3. Attempt a transaction or signature request on Site A; verify the 'Unconnected account' alert/banner appears.
  4. Use the provided action (switch/connect) and confirm the request proceeds only after the account is properly connected.

Medium Risk Scenarios (5)

1. App State Controller - lock/unlock and onboarding gating

Risk Level: MEDIUM

Why This Matters: App state flags drive many UI flows; regressions can trap users in onboarding loops or mis-route after unlock.

Test Steps:

  1. Fresh install 13.43.0, create a new wallet, and complete onboarding.
  2. Verify post-onboarding UI state (home route, no re-appearing onboarding prompts such as the account icon tour after it's dismissed once).
  3. Lock the wallet, relaunch the browser, and unlock; confirm return to the expected last route without stray prompts.
  4. Ensure notifications/alerts reflect correct state (e.g., no onboarding banners once completed).

2. Account Group Balance - aggregate accuracy

Risk Level: MEDIUM

Why This Matters: Incorrect aggregate balances can cause user confusion or bad financial decisions; changes to this component need validation.

Test Steps:

  1. With two accounts holding tokens on at least two networks, open the aggregated balance component (e.g., on home/portfolio views).
  2. Verify the displayed fiat total matches the sum of individual account balances using the current fiat currency.
  3. Switch the primary currency (e.g., USD to native), then back, and confirm the aggregate updates correctly.
  4. Toggle test networks visibility and confirm balances exclude test networks when hidden.

3. Bridge flow regression check (quotes to confirmation)

Risk Level: MEDIUM

Why This Matters: Underlying controller/package patch shifts can silently affect Bridge logic; a sanity check reduces risk of broken cross-network flows.

Test Steps:

  1. Open the Bridge feature, request a quote from Network A to Network B for a common token.
  2. Verify quotes populate and fee/route details render correctly.
  3. Proceed to confirmation, then either cancel or submit on a testnet and ensure status updates correctly.
  4. Ensure returning to the Bridge remembers the last selections and no errors persist.

4. Asset list performance and scrolling with large token sets

Risk Level: MEDIUM

Why This Matters: Large UI refactors can degrade list virtualization and responsiveness, harming everyday usability.

Test Steps:

  1. Use an account with 100+ tokens (or add many watch-only tokens) across multiple networks.
  2. Switch the Assets view to 'All networks' and scroll rapidly from top to bottom.
  3. Use the search/filter to find a specific token and clear the search.
  4. Verify smooth scrolling (no jank), correct rendering (no duplication/missing rows), and quick filter response.

5. Analytics events on confirmation screens

Risk Level: MEDIUM

Why This Matters: Confirm screens often emit critical events; ensuring correct gating avoids privacy violations and analytics regressions.

Test Steps:

  1. With MetaMetrics OFF, initiate a Send or Swap and navigate to the confirm screen; monitor DevTools Network for analytics calls.
  2. Confirm there are no analytics calls while consent is off.
  3. Turn MetaMetrics ON and repeat; confirm one or more analytics calls are made during the confirm flow.
  4. Complete the transaction and verify no unexpected errors are triggered by analytics.

Teams Sign-off Status

Signed off: None yet

Awaiting sign-off (8):
Accounts, Assets, Confirmations, Networks, Onboarding, Swaps and Bridge, Transactions, Wallet Integrations


Generated by AI Test Plan Analyzer (gpt-5) at 2026-08-10T19:27:51.486Z

AI generated test plan (JSON): test-plan-13.43.0.json

@metamask-ci

ghost commented Aug 10, 2026

Copy link
Copy Markdown
Contributor
Builds ready [a70b6f9]
⚡ Performance Benchmarks (Total: 🟢 13 pass · 🟡 5 warn · 🔴 4 fail)

Baseline (latest main): 171ed20 | Date: 7/28/2026 | Pipeline: 31420224789 | Baseline logs

Metricschrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🔴 openAccountMenuToAccountListLoaded(p95) [CI log]🔴 [CI log]
onboardingNewWallet
[Sentry log · main/release]
🔴 longTaskMaxDuration(p95) [CI log]🔴 [CI log]

Regressions (🔴 4 failures)

Interaction Benchmarks · Samples: 5
Benchmarkchrome-webpackfirefox-webpack
loadNewAccount
[Sentry log · main/release]
🟡 [CI log]
🟡 load_new_account
🟢 [CI log]
confirmTx
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
bridgeUserActions
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↑ loadNewAccount/load_new_account: +18%
  • ↑ loadNewAccount/total: +18%
  • ↑ bridgeUserActions/bridge_load_asset_picker: +13%
  • ↑ bridgeUserActions/longTaskCount: +11%
  • ↑ bridgeUserActions/longTaskTotalDuration: +21%
  • ↑ bridgeUserActions/tbt: +43%
  • ↓ loadNewAccount/fcp: -64%
  • ↑ loadNewAccount/lcp: +945%
  • ↓ confirmTx/longTaskCount: -100%
  • ↓ confirmTx/longTaskTotalDuration: -100%
  • ↓ confirmTx/longTaskMaxDuration: -100%
  • ↓ confirmTx/tbt: -100%
  • ↓ confirmTx/inp: -32%
  • ↓ confirmTx/fcp: -68%
  • ↑ confirmTx/lcp: +1203%
  • ↑ bridgeUserActions/bridge_load_page: +149%
  • ↑ bridgeUserActions/bridge_load_asset_picker: +95%
  • ↓ bridgeUserActions/longTaskCount: -100%
  • ↓ bridgeUserActions/longTaskTotalDuration: -100%
  • ↓ bridgeUserActions/longTaskMaxDuration: -100%
  • ↓ bridgeUserActions/tbt: -100%
  • ↑ bridgeUserActions/total: +22%
  • ↓ bridgeUserActions/inp: -31%
  • ↓ bridgeUserActions/fcp: -71%
  • ↑ bridgeUserActions/lcp: +1186%
Startup Benchmarks · Samples: 100
Benchmarkchrome-webpackfirefox-webpack
startupStandardHome
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
startupPowerUserHome
[Sentry log · main/release]
–🟡 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↓ startupStandardHome/numNetworkReqs: -14%
  • ↓ startupStandardHome/domInteractive: -29%
  • ↓ startupStandardHome/initialActions: -50%
  • ↓ startupStandardHome/numNetworkReqs: -13%
  • ↓ startupStandardHome/fcp: -26%
  • ↑ startupPowerUserHome/load: +15%
  • ↑ startupPowerUserHome/domContentLoaded: +15%
  • ↑ startupPowerUserHome/domInteractive: +20%
  • ↑ startupPowerUserHome/backgroundConnect: +15%
  • ↑ startupPowerUserHome/firstReactRender: +17%
  • ↑ startupPowerUserHome/initialActions: +11%
  • ↑ startupPowerUserHome/loadScripts: +13%
  • ↓ startupPowerUserHome/setupStore: -68%
  • ↑ startupPowerUserHome/inp: +10%
  • ↑ startupPowerUserHome/fcp: +17%
  • ↑ startupPowerUserHome/lcp: +10%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 startupPowerUserHome/INP: p75 208ms
  • 🟡 startupPowerUserHome/LCP: p75 3.2s
User Journey Benchmarks · Samples: 5 · real API 🔴 4

⚠️ Missing data: chrome/webpack/userJourneyTransactions

Benchmarkchrome-webpackfirefox-webpack
onboardingImportWallet
[Sentry log · main/release]
🔴 [CI log]
🔴 doneButtonToHomeScreen
🔴 total
🔴 [CI log]
🔴 total
onboardingNewWallet
[Sentry log · main/release]
🔴 [CI log]
🔴 total
🔴 [CI log]
🔴 total
assetDetails
[Sentry log · main/release]
🟢 [CI log]🟢 [CI log]
solanaAssetDetails
[Sentry log · main/release]
🟢 [CI log]🟡 [CI log]
importSrpHome
[Sentry log · main/release]
🟡 [CI log]🟢 [CI log]
sendTransactions
[Sentry log · main/release]
–🟡 [CI log]
swap
[Sentry log · main/release]
–🟢 [CI log]

📈 Results compared to the previous 5 runs on main

  • ↓ onboardingImportWallet/doneButtonToHomeScreen: -37%
  • ↑ onboardingImportWallet/openAccountMenuToAccountListLoaded: +132%
  • ↑ onboardingImportWallet/longTaskCount: +29%
  • ↑ onboardingImportWallet/longTaskTotalDuration: +27%
  • ↑ onboardingImportWallet/tbt: +23%
  • ↓ onboardingNewWallet/skipBackupToMetricsScreen: -17%
  • ↓ onboardingNewWallet/agreeButtonToOnboardingSuccess: -13%
  • ↑ onboardingNewWallet/tbt: +10%
  • ↓ solanaAssetDetails/longTaskCount: -100%
  • ↓ solanaAssetDetails/longTaskTotalDuration: -100%
  • ↓ solanaAssetDetails/longTaskMaxDuration: -100%
  • ↓ solanaAssetDetails/tbt: -100%
  • ↑ solanaAssetDetails/lcp: +713%
  • ↑ importSrpHome/openAccountMenuAfterLogin: +10%
  • ↑ importSrpHome/homeAfterImportWithNewWallet: +25%
  • ↑ importSrpHome/longTaskMaxDuration: +17%
  • ↑ importSrpHome/tbt: +11%
  • ↑ importSrpHome/total: +24%
  • ↓ importSrpHome/inp: -12%
  • ↑ importSrpHome/lcp: +16%
  • ↓ importSrpHome/cls: -11%

🌐 Core Web Vitals — 🟢 good · 🟡 needs improvement · 🔴 poor (web.dev thresholds)

  • 🟡 importSrpHome/INP: p75 272ms
  • 🟡 importSrpHome/FCP: p75 1.8s
  • 🟡 solanaAssetDetails/FCP: p75 2.0s
  • 🟡 solanaAssetDetails/LCP: p75 2.5s
  • 🟡 sendTransactions/INP: p75 216ms
  • 🟡 sendTransactions/FCP: p75 2.0s
  • 🟡 sendTransactions/LCP: p75 2.7s
Dapp Page Load Benchmarks · Samples: 100
Benchmarkchrome-webpack
dappPageLoad
[Sentry log · main/release]
🟢 [CI log]
Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 4.25 KiB (0.03%)
  • ui: 34.29 KiB (0.19%)
  • common: 0 Bytes (0%)
  • other: 0 Bytes (0%)
  • contentScripts: 476 Bytes (0.02%)
  • zip: 47.78 KiB (0.22%)

🍒 What's in this RC

Cherry-picks (14 commits)
Commit Description
a70b6f95ab release(runway): cherry-pick chore: bump dompurify to 3.4.13 to clear GHSA-55q2-fjhq-7xh7 (#45377)
c81d0a92a3 release(runway): cherry-pick chore: bump nanoid to ^3.3.17 to clear GHSA-2v37-7h3g-55p8 (#45372)
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
75ea9568be Merge branch 'stable' into release/13.43.0

Changelog (164 commits since v13.42.0)
Commit Description
a70b6f95ab release(runway): cherry-pick chore: bump dompurify to 3.4.13 to clear GHSA-55q2-fjhq-7xh7 (#45377)
c81d0a92a3 release(runway): cherry-pick chore: bump nanoid to ^3.3.17 to clear GHSA-2v37-7h3g-55p8 (#45372)
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
76657f7a3c release: release-changelog/13.43.0 (#45056)
9da0748ed3 Merge release/13.42.0 into release/13.43.0
d90d1e76b8 fix(hardware-wallets): bound stuck account-creation spinner with device-read timeout cp-13.42.0 (#45048)
0311ca5fc9 feat: add trust security signals tdp (#44761)
3114315a0e fix: consume stx enabled flag for batch sell from selected chain (#45032)
3ae0ce34cc chore: clean up TextFieldSearch styles after MMDS package update (#45030)
51cff5563f test: fix flaky test Smart Transactions should send transaction using USDC to pay fee (#45036)
0610a607c7 feat(perps): wire dedicated aggregated order-book socket per UI connection (#45035)
d67a05b8aa ci(slsa): publish attestation bundles and pin run-build actions (INFRA-3786) (#44955)
666b247f3a test: fix flaky custom-token import E2E by waiting for the Add Custom Token network picker to settle TimeoutError: Waiting for element to be located By(css selector, [data-testid="custom-token-import-submit-button"]:not([disabled])) (#45025)
9afac38fe7 feat: new segment schema support (#43132)
bfdb62afa3 test: fix flaky test BTC Account - Activity Receive transaction is rendered with Received label and confirmed status (#45022)
0fdbade0f4 test: MMQA - 1916 - Refactor multiple-provider-connections.spec.ts to good practices (#44941)
33bef9f690 test: fix flaky perps watchlist explore TimeoutError: Waiting for element to be located By(css selector, [data-testid="market-list-filter-sort-row"]) (#44936)
6d53060f6b test: replace driver.waitForSelector with page object methods (#44898)
ed7b8fbd53 fix: patch for missing slip44 entries in core client-utils cp-13.42.0 (#45006)
7e9653a51f feat: added metrics for custom network page (#45031)
5a94f11f60 feat(activity): contact names in activity rows (#45013)
5f842c6082 test: fix flaky Add wallet Import wallet using SRP during onboardingand MetaMask onboarding should not prevent network requests to advanced... (#45034)
c36df0ec1a fix: vertically center contact copy button (#45020)
e3abdc3e78 feat: added timer for balance loading cp-13.42.0 (#45033)
b424876ab6 chore: update assets controllers for defi fix (#45003)
adec2ed351 refactor(wpc-1066): migrate pending-approval HW methods to LegacyBackgroundApiService (#44937)
20bf478a91 feat(confirmations): add Money Account Deposit developer option (#44945)
48ad866df4 bump(perps): upgrade @metamask/perps-controller to v10 (#45024)
239006e967 fix(notifications): add bottom padding to marketing consent text (#45021)
9158172d8a refactor(wpc-1067): migrate network enablement methods to LegacyBackgroundApiService (#44938)
62aaaa4923 test: order selectors and methods in all page objects (#44987)
45505c9910 chore: wire stellar asset component with stellar asset selector (#44979)
ce134bc060 feat: defi positions v2 controller (#44392)
b50797d25a chore: pass Firefox system access via geckodriver and pin 0.36.0 (#45014)
0c7372db98 fix(pure-black): use bg-default on back up SRP page (#44983)
e47424b771 fix(perps): show wallet-confirmed deposits immediately in Perps Activity (#44736)
9b623cccf7 ci: turn on the Triage and Retry System by default (no retry-ci label needed) (#44956)
778bafe559 feat(ramps): wire Buy Continue with background checkout watch (#44689)
10b5de87df test: lavamoat e2e (#44925)
c1a5d29ffd fix: swaps stale dest exchange rates cp-13.42.0 (#44968)
0fa0c88cf3 chore: fix lint:changed script (#45010)
fa5c57e727 fix: navigate to homepage after users close popup from batch sell (#44991)
7dce891afb feat(ramps): send Portfolio-connected wallets to Portfolio on Buy (#44804)
3739101671 fix(pure-black): refine SRP input empty vs filled styling (#45004)
1ec648fa36 chore: update swap consumers to use and display partial QuoteMetadata (#44630)
0660a05750 refactor(wpc-1068): migrate requestSafeReload & openUpdateTabAndReload to LegacyBackgroundApiService (#44940)
d2fdd13169 perf(6570): bump react-hooks to v7 and remove react-compiler plugin (#44495)
cf719e0334 fix(pure-black): stop inverting bridge transaction settings tooltip theme (#44964)
10fabf3ed6 chore: New Crowdin Translations by GitHub Action cp-13.42.0 (#44746)
806f4bf8b6 fix(pure-black): use BackgroundDefault for markets row skeleton (#44984)
da76cb3edb fix(pure-black): use bg-default on Snap install screen (#45002)
c20d7eb736 fix(pure-black): set send network filter button background to transparent (#44882)
04b53836a4 chore(STX): add Robinhood Chain to smart transactions supported networks (#44926)
284f97705e chore: popover for failed transaction status (#44961)
2668c42734 fix(pure-black): remove border from page footer cancel buttons (#44981)
d0efdd7df1 chore(storybook): add Pure Black toolbar toggle and component stories (#44963)
fadc943601 feat: assets unify balance and traces (#44978)
bad91a67e9 chore: replaced deprecated Tag component with MMDS tag (#44785)
dd2075062d fix(confirmations): refetch MetaMask Pay required token price when it is missing (#44950)
66b8f875e3 fix(pure-black): fix Menu background specificity with bg-section (#44966)
00f32ff73c fix: qr camera permission throwing e.isUnlocked is not a function (#44701)
b5ed10c4c2 feat(hardware-wallets): enable shared signing flow (#43947)
1695992b6f feat: migrate Infura IPFS users to dweb.link and block Infura IPFS gateway entry (#44982)
0ad8940da9 feat: use new snap keyring v2/v1 split (#44289)
b7f13b1a4c test: refactor transaction details page and consolidate selectors (#44694)
61ff089628 test(e2e): add Tron assets E2E cluster (#44852)
540d2a65b1 feat: bump transaction-pay-controller to 26.0.0 (#44782)
df415e426e test: skip ERC20 max balance WS update test (ASSETS-3385) (#44952)
f87e3bc8db fix(pure-black): remove custom background color from InfoPopoverTooltip (#44933)
634b46cfed fix(pure-black): remove border-l and bg-alternative from drawer in popup/compact sidepanel (#44960)
57da315640 test: pom lint rule supporting groups (selectors, constructor, actions) (#44789)
7e641c6203 chore: bump @types/chrome and drop custom chrome typings (#44888)
cbd1c50aaf perf(7466): add memoization to network/asset modal components (Batch D) (#44296)
75e09ed50f fix(pure-black): settings sidebar uses bg-alternative in pure black mode (#44883)
c164a38416 fix: clear the postcss advisories cp-13.42.0 (#44865)
3f6a9050c3 test: cover Token Detection Enabled identify trait (#44915)
91ed59bb42 chore: replace local gator permission detail schemas with @metamask/7715-permission-types (#44415)
a73805093a fix: excempt batch sell routes from ConfirmationRouter (#44951)
87d0cf9c0a fix(pure-black): set main action button dropdown to bg-alternative (#44881)
17731f5111 fix(pure-black): fix account address popover background and refactor row hover to Tailwind (#44880)
b8ee5bb2eb fix(pure-black): correct tooltip background and arrow colors in dark and pure black themes (#44879)
7b6dde7630 fix(pure-black): add bg-alternative and border to asset explorer view (#44878)
cfdbb033e8 bump: brace-expansion to 5.0.8 (#44924)
00ebfcf32e feat: updated import NFT flow Modal (#44899)
a5f18a53c5 fix: Allow QR singing in side panel on brave (#44934)
bdbe8f29c1 chore(6922): bump @testing-library/react to v14 (#42635)
b35834378b chore: upgrade design system packages (v57.0.0) (#44931)
58b697a400 fix: remove deprecated METAMASK_ENVIRONMENT=test in favor of testing (#44944)
4e37811629 chore: remove copy-to-clipboard dependency (#44890)
4d2065f6a5 test: add coverage for Notification Clicked metrics event (#44920)
da23672992 feat(analytics): migrate pre-consent queue to AnalyticsController (#43869)
5201492b01 feat: refactor non-zero native custom networks (#44161)
9e0cbd2538 fix: allow Firefox WebDriver system access for about:debugging (#44946)
992ff087e7 test(e2e): refactor tokens tab page object for assets coverage (#44778)
b8ad63da79 ci(amo): allow release-team manual dispatch of AMO production (INFRA-3769) (#44519)
bd65eccfdb chore: remove defi v2 fetching from getApi (#44939)
3cb496ea9a chore: migrate markNotificationPopupAsAutomaticallyClosed to LegacyBackgroundApiService (#44249)
f835f69039 feat: initialize DeFiPositionsControllerV2 (#44772)
171ed202b7 feat: add UAT env on bridge (#44895)
ca508307ef feat: bump phishing controller 17.3.0 (#44841)
56ffb74681 refactor(ui): use Arrow2UpRight for Send action icons (#44929)
9c8c6bcb8b fix(pure-black): set perps balance dropdown to bg-alternative (#44875)
cd32d2d252 chore: remove component-library README.mdx docs (#44886)
bab3498f9c chore: remove deprecated textfieldsearch components (#44918)
2bbf04046f ci: fixed labels from forks (#44022)
199066c701 fix: add missing events to bottom nav bar experiment config cp-13.42.0 (#44919)
d53496f910 chore: swap position of network picker and search bar on swaps asset picker (#44911)
9d573278ab chore(6927): upgrade redux to v8 (#44445)
2f528e3470 build: no more PNGs inside SVGs allowed, delete unused images (#44832)
4011ce9d91 Merge origin/main into stable-main-13.41.0
72ba3533f4 chore: bump assets controller to v11.2.1 (#44903)
cba9e41d31 chore: fix ESLint ignore config (#44914)
5bb1c5e23d feat: update HeaderSearch and asset picker modal search bars to use TextFieldSearch (#44910)
2be47e1c8d fix: handle missing account for cross-chain asset deeplinks cp-13.42.0 (#44904)
7fac1b56cb test(e2e): stabilize network filter open before switch-network click (#44692)
ba9268b8c7 test: fix flaky test error page support consent TimeoutError: Waiting element to become stale (#44850)
60e4cd1b48 test: fix flaky unstable Continue button in Send page (#44837)
c4d2caae67 feat: migrate swap asset picker search to DSR TextFieldSearch (#44905)
fba4cb3aa7 refactor: simplify sponsored fee row; cleanup dead code (#44872)
ff4fd4dbb8 chore: rename SettingsHeader to PageHeaderWithSearch (#44902)
b072b88aef fix: updated checkbox and permissions page width cp-13.42.0 (#44896)
4045b69287 chore: remove dead app header props (#44900)
15db15fe5b feat: align search bar UIs (#44430)
67db57c82a fix(transactions): avoid inflated fees from failed container estimates (#44308)
75e46239ee feat(ci): add CWS rollout adjustment workflow (INFRA-3651) (#44060)
a03a82855f refactor: cleanup activity selectors (#44864)
7d8a31630f test(e2e): add Tron network E2E cluster (#44164)
e7a6a5e59f fix: local-enriched bridge label when switching networks (#44858)
42146f2fa5 fix(activity): apply text color token to native dialog for dark theme cp-13.42.0 (#44863)
55ad54b09e fix: retry persistence writes once (#44003)
c08a8bb748 bump: tar to 7.5.22, ignore react-router advisories cp-13.41.0 (#44862)
cdddd817a4 fix(deep-links): restore interstitial protection cp-13.42.0 (#44830)
b6619a9fb8 fix(activity): transaction details width (#44853)
5d2cff8067 feat: keep the balance left aligned for lower viewport cp-13.42.0 (#44791)
fddbd0cf34 chore: remove swaps approval text (#44794)
71272d9cd3 test: cover Wallet Imported event (#44747)
47bb810f81 test(e2e): extend Tron fixtures for assets E2E coverage (#44784)
01588c978d chore(assets-controller): bump to 11.2.0 (#44847)
c8df352c4c fix(confirmations): use getAssetImageUrl for gas fee token icon (#44769)
eca1e7ed3f feat: defer password confirm mismatch error until minimum length. (#44790)
e40d3d1af9 ci: pass AI analyzer gate for medium Runway cherry-picks into release branches (#44779)
5147646d2f test(e2e): refactor tokens tab page object for assets coverage (#44777)
81508e447a feat(onboarding): update Google sign-in icon to new brand logo (#44755)
545dd73434 fix: gas sponsorship being shown for hw accounts when the user has selected a nonevm network (#44706)
4ed04ec772 fix: restored old behavior to show Paid by MetaMask label in sponsored transactions from activity page cp-13.41.0 (#44780)
ca4d467800 refactor: migrate Core UX secondary buttons to MMDS (#44767)
197093a62a test: cover Wallet Setup Started Segment event (#44668)
5c6ffe848d fix(ci): post RC Slack when Builds ready, not only green main (#44831)
8011cc033a fix: eliminate dark-mode background flash for pure black mode (#44743)
d667c1f177 feat: enable pure black dark mode by default (#44806)
c42c6cbe77 ci: update cla.yml with more Cursor names (#44815)
88e20cf90c fix(assets): include tokens with large balances and few decimals in aggregated balance cp-13.41.0 (#44796)
1e2f17bea8 feat: upgrade bridge packages to latest versions (#44722)
5fb686386e release: Bump main version to 13.43.0 (#44799)

AI Test Plan

Risk Score High Risk Medium Risk Files Changed Commits
48/100 4 7 1355 167
Cherry-Pick Scenarios (2)

High Risk Scenarios (1)

1. Smart Transactions - Tx status tracking via updated tx-sentinel (Robinhood URL)

Risk Level: HIGH

Why This Matters: Cherry-pick 45214 fixes the Smart Transactions controller to use a new tx-sentinel endpoint; endpoint mismatches can break status tracking, leaving transactions stuck or misreported.

Test Steps:

  1. Enable Smart Transactions in Settings and ensure you are on a supported network (e.g., Mainnet).
  2. Submit a low-value token transfer or swap with Smart Transactions enabled; verify pre-flight details load, then confirm.
  3. Observe the transaction status: it should move from submitted/pending to confirmed without getting stuck; activity item should show accurate status and timing.
  4. Disable Smart Transactions and perform the same action to ensure the normal transaction path is unaffected.

Medium Risk Scenarios (1)

1. Perps - Order book on order entry page

Risk Level: MEDIUM

Why This Matters: Cherry-pick 45151 adds a new user-facing order book; integration issues can block order entry, prefill the wrong price, or display stale data during live trading.

Test Steps:

  1. Navigate to the Perps order entry page; verify an order book is visible with bids/asks and updates in real time.
  2. Click a price level in the order book; confirm the order entry price field populates correctly.
  3. Change the trading pair/market; ensure the order book updates to the new market without stale rows.
  4. Simulate temporary disconnection or switch networks; verify the order book shows a graceful empty/error state and recovers without a reload.

Release Scenarios (9)

High Risk Scenarios (3)

1. State Migrations 220/221 - Core wallet state

Risk Level: HIGH

Why This Matters: Migrations can corrupt or drop critical wallet state (accounts, permissions, networks). Two new migrations (220, 221) raise the risk of subtle data loss or incorrect defaults after upgrade.

Test Steps:

  1. Start with 13.42.x profile: create 2 accounts, connect a dapp to Account 1, add a custom RPC (use an invalid or offline endpoint), add a few ERC-20 tokens, and opt OUT of MetaMetrics.
  2. Upgrade to 13.43.0 and open the extension; let migrations run to completion.
  3. Verify both accounts, balances, tokens, and address book entries are intact; confirm connected site still lists Account 1 as connected and Account 2 as not connected.
  4. Switch to the custom RPC; observe expected invalid network handling (see related alert scenario), then switch back; ensure no crashes or data loss.
  5. Lock and unlock the wallet; verify state remains consistent (connected sites, selected account, last used network).

2. MetaMetrics consent and event gating (MetaMetrics Controller refactor)

Risk Level: HIGH

Why This Matters: Substantial MetaMetrics controller changes can cause consent regressions (unexpected prompts), lost preferences, or misfired analytics in critical flows.

Test Steps:

  1. Pre-upgrade: set MetaMetrics to Opt-In in 13.42.x; upgrade to 13.43.0 and open the extension.
  2. Confirm no unexpected consent prompt appears and Settings > Security & privacy shows the Opt-In state preserved.
  3. Connect a site and approve a basic permissions request; then initiate a simple send; ensure no duplicate or extraneous prompts appear and UI remains responsive.
  4. Toggle MetaMetrics OFF in Settings; repeat a connect and a send; confirm no analytics/consent UI regresses (no unexpected prompts, flows behave normally).

3. Connected Sites & Permissions persistence across account switching

Risk Level: HIGH

Why This Matters: Controller and app-state changes can break fine-grained permission mappings per account, leading to privacy and UX issues when switching accounts.

Test Steps:

  1. With a dapp open, connect Account 1 and confirm site permissions list shows the site connected to Account 1 only.
  2. Switch the active account in the extension to Account 2 while the site is open.
  3. Verify the site shows as not connected for Account 2; the extension should reflect that status in the connected sites panel.
  4. Reload the site and the extension; ensure the mapping (Account 1 connected, Account 2 not) persists; disconnect the site and verify both accounts show as disconnected.

Medium Risk Scenarios (6)

1. Alerts - Invalid Custom Network

Risk Level: MEDIUM

Why This Matters: This alert’s logic directly guides users away from misconfigured networks; logic changes can cause false positives/negatives that strand users.

Test Steps:

  1. Add a custom network with a bad RPC URL (wrong chainId response or an offline endpoint).
  2. Switch to this network; verify the 'Invalid custom network' alert appears with correct messaging and does not block navigation.
  3. Edit the network to a valid RPC; confirm the alert disappears without requiring an extension reload.
  4. Switch between valid/invalid networks repeatedly; verify no stale alerts persist and no crashes occur.

2. Alerts - Unconnected Account (Dapp connection)

Risk Level: MEDIUM

Why This Matters: Recent UI logic changes to this alert can confuse users about which account is connected, impacting security and transaction correctness.

Test Steps:

  1. Connect a site to Account 1; ensure the site shows connected.
  2. Switch the active account to Account 2 within the extension while staying on the same site.
  3. Verify the 'Unconnected account' alert appears with a clear CTA to connect Account 2.
  4. Use the CTA to connect Account 2; approve the permissions request; verify the alert disappears and both accounts’ connection statuses are accurate.

3. Assets List - Network Filter & Control Bar behavior

Risk Level: MEDIUM

Why This Matters: Multiple UI updates to the control bar and filter can cause state desyncs (wrong assets shown) and persistence bugs that confuse users managing tokens.

Test Steps:

  1. Open the Assets tab and use the control bar to enable 'Home networks only' (or similar) in the network filter.
  2. Switch between Mainnet and a custom network; verify only assets belonging to the selected/home networks are listed and that the toggle state persists when returning to the Assets tab.
  3. Use search within the filtered state; verify results respect the network filter; clear the filter and confirm all assets reappear.
  4. Close and reopen the extension; confirm the previously chosen filter state is remembered (if intended).

4. Account Group Balance - Aggregation and fiat conversion

Risk Level: MEDIUM

Why This Matters: Recent component changes can create mis-aggregation or stale totals, misleading users about their total holdings.

Test Steps:

  1. With multiple accounts holding different tokens, check the group balance summary; note the displayed fiat total.
  2. Change fiat currency in Settings; verify the group balance recalculates correctly and consistently across extension reload.
  3. Hide/unhide a token in one account; confirm the group total updates immediately and matches the sum of visible assets.

5. Perps streaming bridge - connection resilience

Risk Level: MEDIUM

Why This Matters: Stream bridge logic changes risk stale or missing market data, directly impacting trading UX and decision-making.

Test Steps:

  1. Open the Perps trading module and verify live market data appears (prices or positions as applicable).
  2. Briefly go offline (e.g., toggle network off for ~10s) and back online; confirm the stream auto-recovers without needing a page reload and data resumes updating.
  3. Switch accounts and networks; ensure subscriptions update and no old account’s data persists or leaks.

6. Account Icon Tour / First-run UI gating

Risk Level: MEDIUM

Why This Matters: Small logic tweaks to first-run cues can result in repetitive prompts or missed guidance that degrade onboarding UX.

Test Steps:

  1. Create a fresh profile and open the extension; verify the account icon tour (or relevant onboarding cue) appears at the appropriate time.
  2. Dismiss/complete the tour; lock and unlock the wallet; confirm the tour does not reappear unexpectedly.
  3. Reset onboarding state (if supported) and confirm the tour reappears only when intended.

Teams Sign-off Status

Signed off: None yet

Awaiting sign-off (8):
Accounts, Assets, Networks, Permissions, Swaps and Bridge, Transactions, Wallet, Wallet Integrations


Generated by AI Test Plan Analyzer (gpt-5) at 2026-08-10T20:38:54.640Z

AI generated test plan (JSON): test-plan-13.43.0.json

@metamask-ci

ghost commented Aug 11, 2026

Copy link
Copy Markdown
Contributor
Builds ready [e398446]
⚡ Performance Benchmarks (Total: 🟢 0 pass · 🟡 0 warn · 🔴 0 fail)

Baseline (latest main): 171ed20 | Date: 7/28/2026 | Pipeline: 31471899142 | Baseline logs

Interaction Benchmarks · Samples: 5

⚠️ Missing data: chrome/webpack/interactionUserActions, firefox/webpack/interactionUserActions

✅ No regressions detected

Startup Benchmarks · Samples: 100

⚠️ Missing data: chrome/webpack/startupStandardHome, chrome/webpack/startupPowerUserHome, firefox/webpack/startupStandardHome, firefox/webpack/startupPowerUserHome

✅ No regressions detected

User Journey Benchmarks · Samples: 5 · real API

⚠️ Missing data: chrome/webpack/userJourneyOnboardingImport, chrome/webpack/userJourneyOnboardingNew, chrome/webpack/userJourneyAssets, chrome/webpack/userJourneyAccountManagement, chrome/webpack/userJourneyTransactions, firefox/webpack/userJourneyOnboardingImport, firefox/webpack/userJourneyOnboardingNew, firefox/webpack/userJourneyAssets, firefox/webpack/userJourneyAccountManagement, firefox/webpack/userJourneyTransactions

✅ No regressions detected

Dapp Page Load Benchmarks · Samples: 100

⚠️ Missing data: chrome/webpack/pageLoadBenchmark

✅ No regressions detected

Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 4.25 KiB (0.03%)
  • ui: 34.29 KiB (0.19%)
  • common: 0 Bytes (0%)
  • other: 0 Bytes (0%)
  • contentScripts: 476 Bytes (0.02%)
  • zip: 47.78 KiB (0.22%)

🍒 What's in this RC

Cherry-picks (15 commits)
Commit Description
e3984460e8 release: temporarily disable benchmarks
a70b6f95ab release(runway): cherry-pick chore: bump dompurify to 3.4.13 to clear GHSA-55q2-fjhq-7xh7 (#45377)
c81d0a92a3 release(runway): cherry-pick chore: bump nanoid to ^3.3.17 to clear GHSA-2v37-7h3g-55p8 (#45372)
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
75ea9568be Merge branch 'stable' into release/13.43.0

Changelog (165 commits since v13.42.0)
Commit Description
e3984460e8 release: temporarily disable benchmarks
a70b6f95ab release(runway): cherry-pick chore: bump dompurify to 3.4.13 to clear GHSA-55q2-fjhq-7xh7 (#45377)
c81d0a92a3 release(runway): cherry-pick chore: bump nanoid to ^3.3.17 to clear GHSA-2v37-7h3g-55p8 (#45372)
dfc2567194 release(runway): cherry-pick fix(ci): grant orchestrator callees the attestations permissions they request (#45336)
eab409745b release(runway): cherry-pick fix(ci): restrict AMO flask/production to release/*; block flask dispatch (#45326)
cb83da7da8 release(runway): cherry-pick fix: resolve ip-address to >=10.3.1 for yarn audit (#45252)
a694e1ef9b Cherry-picking commits from cherry-pick-13-43-0-3cad329 to release/13.43.0 for PR #45158 (#45244)
18b0642e48 release(runway): cherry-pick chore: New Crowdin Translations by GitHub Action (#45216)
3b2076081e release(runway): cherry-pick feat(ci): derive orchestrator version from release branch (#45224)
024c9a632a release(runway): cherry-pick fix(ci): bind AMO package EXIT trap path before set -u can fail (#45225)
f576b8f4ac release(runway): cherry-pick fix: patch smart-transactions-controller to add the tx-sentinel robinhood URL (#45214)
400f264212 release(runway): cherry-pick chore: audit brace-expansion, postcss, fast-uri, undici, and socket.io-parser (#45188)
f1e31952b6 release(runway): cherry-pick feat(perps): add order book to order entry page (#45151)
1ea90deff7 release(runway): cherry-pick chore: bump snap-account-service (report migration error) (#45102)
76657f7a3c release: release-changelog/13.43.0 (#45056)
9da0748ed3 Merge release/13.42.0 into release/13.43.0
d90d1e76b8 fix(hardware-wallets): bound stuck account-creation spinner with device-read timeout cp-13.42.0 (#45048)
0311ca5fc9 feat: add trust security signals tdp (#44761)
3114315a0e fix: consume stx enabled flag for batch sell from selected chain (#45032)
3ae0ce34cc chore: clean up TextFieldSearch styles after MMDS package update (#45030)
51cff5563f test: fix flaky test Smart Transactions should send transaction using USDC to pay fee (#45036)
0610a607c7 feat(perps): wire dedicated aggregated order-book socket per UI connection (#45035)
d67a05b8aa ci(slsa): publish attestation bundles and pin run-build actions (INFRA-3786) (#44955)
666b247f3a test: fix flaky custom-token import E2E by waiting for the Add Custom Token network picker to settle TimeoutError: Waiting for element to be located By(css selector, [data-testid="custom-token-import-submit-button"]:not([disabled])) (#45025)
9afac38fe7 feat: new segment schema support (#43132)
bfdb62afa3 test: fix flaky test BTC Account - Activity Receive transaction is rendered with Received label and confirmed status (#45022)
0fdbade0f4 test: MMQA - 1916 - Refactor multiple-provider-connections.spec.ts to good practices (#44941)
33bef9f690 test: fix flaky perps watchlist explore TimeoutError: Waiting for element to be located By(css selector, [data-testid="market-list-filter-sort-row"]) (#44936)
6d53060f6b test: replace driver.waitForSelector with page object methods (#44898)
ed7b8fbd53 fix: patch for missing slip44 entries in core client-utils cp-13.42.0 (#45006)
7e9653a51f feat: added metrics for custom network page (#45031)
5a94f11f60 feat(activity): contact names in activity rows (#45013)
5f842c6082 test: fix flaky Add wallet Import wallet using SRP during onboardingand MetaMask onboarding should not prevent network requests to advanced... (#45034)
c36df0ec1a fix: vertically center contact copy button (#45020)
e3abdc3e78 feat: added timer for balance loading cp-13.42.0 (#45033)
b424876ab6 chore: update assets controllers for defi fix (#45003)
adec2ed351 refactor(wpc-1066): migrate pending-approval HW methods to LegacyBackgroundApiService (#44937)
20bf478a91 feat(confirmations): add Money Account Deposit developer option (#44945)
48ad866df4 bump(perps): upgrade @metamask/perps-controller to v10 (#45024)
239006e967 fix(notifications): add bottom padding to marketing consent text (#45021)
9158172d8a refactor(wpc-1067): migrate network enablement methods to LegacyBackgroundApiService (#44938)
62aaaa4923 test: order selectors and methods in all page objects (#44987)
45505c9910 chore: wire stellar asset component with stellar asset selector (#44979)
ce134bc060 feat: defi positions v2 controller (#44392)
b50797d25a chore: pass Firefox system access via geckodriver and pin 0.36.0 (#45014)
0c7372db98 fix(pure-black): use bg-default on back up SRP page (#44983)
e47424b771 fix(perps): show wallet-confirmed deposits immediately in Perps Activity (#44736)
9b623cccf7 ci: turn on the Triage and Retry System by default (no retry-ci label needed) (#44956)
778bafe559 feat(ramps): wire Buy Continue with background checkout watch (#44689)
10b5de87df test: lavamoat e2e (#44925)
c1a5d29ffd fix: swaps stale dest exchange rates cp-13.42.0 (#44968)
0fa0c88cf3 chore: fix lint:changed script (#45010)
fa5c57e727 fix: navigate to homepage after users close popup from batch sell (#44991)
7dce891afb feat(ramps): send Portfolio-connected wallets to Portfolio on Buy (#44804)
3739101671 fix(pure-black): refine SRP input empty vs filled styling (#45004)
1ec648fa36 chore: update swap consumers to use and display partial QuoteMetadata (#44630)
0660a05750 refactor(wpc-1068): migrate requestSafeReload & openUpdateTabAndReload to LegacyBackgroundApiService (#44940)
d2fdd13169 perf(6570): bump react-hooks to v7 and remove react-compiler plugin (#44495)
cf719e0334 fix(pure-black): stop inverting bridge transaction settings tooltip theme (#44964)
10fabf3ed6 chore: New Crowdin Translations by GitHub Action cp-13.42.0 (#44746)
806f4bf8b6 fix(pure-black): use BackgroundDefault for markets row skeleton (#44984)
da76cb3edb fix(pure-black): use bg-default on Snap install screen (#45002)
c20d7eb736 fix(pure-black): set send network filter button background to transparent (#44882)
04b53836a4 chore(STX): add Robinhood Chain to smart transactions supported networks (#44926)
284f97705e chore: popover for failed transaction status (#44961)
2668c42734 fix(pure-black): remove border from page footer cancel buttons (#44981)
d0efdd7df1 chore(storybook): add Pure Black toolbar toggle and component stories (#44963)
fadc943601 feat: assets unify balance and traces (#44978)
bad91a67e9 chore: replaced deprecated Tag component with MMDS tag (#44785)
dd2075062d fix(confirmations): refetch MetaMask Pay required token price when it is missing (#44950)
66b8f875e3 fix(pure-black): fix Menu background specificity with bg-section (#44966)
00f32ff73c fix: qr camera permission throwing e.isUnlocked is not a function (#44701)
b5ed10c4c2 feat(hardware-wallets): enable shared signing flow (#43947)
1695992b6f feat: migrate Infura IPFS users to dweb.link and block Infura IPFS gateway entry (#44982)
0ad8940da9 feat: use new snap keyring v2/v1 split (#44289)
b7f13b1a4c test: refactor transaction details page and consolidate selectors (#44694)
61ff089628 test(e2e): add Tron assets E2E cluster (#44852)
540d2a65b1 feat: bump transaction-pay-controller to 26.0.0 (#44782)
df415e426e test: skip ERC20 max balance WS update test (ASSETS-3385) (#44952)
f87e3bc8db fix(pure-black): remove custom background color from InfoPopoverTooltip (#44933)
634b46cfed fix(pure-black): remove border-l and bg-alternative from drawer in popup/compact sidepanel (#44960)
57da315640 test: pom lint rule supporting groups (selectors, constructor, actions) (#44789)
7e641c6203 chore: bump @types/chrome and drop custom chrome typings (#44888)
cbd1c50aaf perf(7466): add memoization to network/asset modal components (Batch D) (#44296)
75e09ed50f fix(pure-black): settings sidebar uses bg-alternative in pure black mode (#44883)
c164a38416 fix: clear the postcss advisories cp-13.42.0 (#44865)
3f6a9050c3 test: cover Token Detection Enabled identify trait (#44915)
91ed59bb42 chore: replace local gator permission detail schemas with @metamask/7715-permission-types (#44415)
a73805093a fix: excempt batch sell routes from ConfirmationRouter (#44951)
87d0cf9c0a fix(pure-black): set main action button dropdown to bg-alternative (#44881)
17731f5111 fix(pure-black): fix account address popover background and refactor row hover to Tailwind (#44880)
b8ee5bb2eb fix(pure-black): correct tooltip background and arrow colors in dark and pure black themes (#44879)
7b6dde7630 fix(pure-black): add bg-alternative and border to asset explorer view (#44878)
cfdbb033e8 bump: brace-expansion to 5.0.8 (#44924)
00ebfcf32e feat: updated import NFT flow Modal (#44899)
a5f18a53c5 fix: Allow QR singing in side panel on brave (#44934)
bdbe8f29c1 chore(6922): bump @testing-library/react to v14 (#42635)
b35834378b chore: upgrade design system packages (v57.0.0) (#44931)
58b697a400 fix: remove deprecated METAMASK_ENVIRONMENT=test in favor of testing (#44944)
4e37811629 chore: remove copy-to-clipboard dependency (#44890)
4d2065f6a5 test: add coverage for Notification Clicked metrics event (#44920)
da23672992 feat(analytics): migrate pre-consent queue to AnalyticsController (#43869)
5201492b01 feat: refactor non-zero native custom networks (#44161)
9e0cbd2538 fix: allow Firefox WebDriver system access for about:debugging (#44946)
992ff087e7 test(e2e): refactor tokens tab page object for assets coverage (#44778)
b8ad63da79 ci(amo): allow release-team manual dispatch of AMO production (INFRA-3769) (#44519)
bd65eccfdb chore: remove defi v2 fetching from getApi (#44939)
3cb496ea9a chore: migrate markNotificationPopupAsAutomaticallyClosed to LegacyBackgroundApiService (#44249)
f835f69039 feat: initialize DeFiPositionsControllerV2 (#44772)
171ed202b7 feat: add UAT env on bridge (#44895)
ca508307ef feat: bump phishing controller 17.3.0 (#44841)
56ffb74681 refactor(ui): use Arrow2UpRight for Send action icons (#44929)
9c8c6bcb8b fix(pure-black): set perps balance dropdown to bg-alternative (#44875)
cd32d2d252 chore: remove component-library README.mdx docs (#44886)
bab3498f9c chore: remove deprecated textfieldsearch components (#44918)
2bbf04046f ci: fixed labels from forks (#44022)
199066c701 fix: add missing events to bottom nav bar experiment config cp-13.42.0 (#44919)
d53496f910 chore: swap position of network picker and search bar on swaps asset picker (#44911)
9d573278ab chore(6927): upgrade redux to v8 (#44445)
2f528e3470 build: no more PNGs inside SVGs allowed, delete unused images (#44832)
4011ce9d91 Merge origin/main into stable-main-13.41.0
72ba3533f4 chore: bump assets controller to v11.2.1 (#44903)
cba9e41d31 chore: fix ESLint ignore config (#44914)
5bb1c5e23d feat: update HeaderSearch and asset picker modal search bars to use TextFieldSearch (#44910)
2be47e1c8d fix: handle missing account for cross-chain asset deeplinks cp-13.42.0 (#44904)
7fac1b56cb test(e2e): stabilize network filter open before switch-network click (#44692)
ba9268b8c7 test: fix flaky test error page support consent TimeoutError: Waiting element to become stale (#44850)
60e4cd1b48 test: fix flaky unstable Continue button in Send page (#44837)
c4d2caae67 feat: migrate swap asset picker search to DSR TextFieldSearch (#44905)
fba4cb3aa7 refactor: simplify sponsored fee row; cleanup dead code (#44872)
ff4fd4dbb8 chore: rename SettingsHeader to PageHeaderWithSearch (#44902)
b072b88aef fix: updated checkbox and permissions page width cp-13.42.0 (#44896)
4045b69287 chore: remove dead app header props (#44900)
15db15fe5b feat: align search bar UIs (#44430)
67db57c82a fix(transactions): avoid inflated fees from failed container estimates (#44308)
75e46239ee feat(ci): add CWS rollout adjustment workflow (INFRA-3651) (#44060)
a03a82855f refactor: cleanup activity selectors (#44864)
7d8a31630f test(e2e): add Tron network E2E cluster (#44164)
e7a6a5e59f fix: local-enriched bridge label when switching networks (#44858)
42146f2fa5 fix(activity): apply text color token to native dialog for dark theme cp-13.42.0 (#44863)
55ad54b09e fix: retry persistence writes once (#44003)
c08a8bb748 bump: tar to 7.5.22, ignore react-router advisories cp-13.41.0 (#44862)
cdddd817a4 fix(deep-links): restore interstitial protection cp-13.42.0 (#44830)
b6619a9fb8 fix(activity): transaction details width (#44853)
5d2cff8067 feat: keep the balance left aligned for lower viewport cp-13.42.0 (#44791)
fddbd0cf34 chore: remove swaps approval text (#44794)
71272d9cd3 test: cover Wallet Imported event (#44747)
47bb810f81 test(e2e): extend Tron fixtures for assets E2E coverage (#44784)
01588c978d chore(assets-controller): bump to 11.2.0 (#44847)
c8df352c4c fix(confirmations): use getAssetImageUrl for gas fee token icon (#44769)
eca1e7ed3f feat: defer password confirm mismatch error until minimum length. (#44790)
e40d3d1af9 ci: pass AI analyzer gate for medium Runway cherry-picks into release branches (#44779)
5147646d2f test(e2e): refactor tokens tab page object for assets coverage (#44777)
81508e447a feat(onboarding): update Google sign-in icon to new brand logo (#44755)
545dd73434 fix: gas sponsorship being shown for hw accounts when the user has selected a nonevm network (#44706)
4ed04ec772 fix: restored old behavior to show Paid by MetaMask label in sponsored transactions from activity page cp-13.41.0 (#44780)
ca4d467800 refactor: migrate Core UX secondary buttons to MMDS (#44767)
197093a62a test: cover Wallet Setup Started Segment event (#44668)
5c6ffe848d fix(ci): post RC Slack when Builds ready, not only green main (#44831)
8011cc033a fix: eliminate dark-mode background flash for pure black mode (#44743)
d667c1f177 feat: enable pure black dark mode by default (#44806)
c42c6cbe77 ci: update cla.yml with more Cursor names (#44815)
88e20cf90c fix(assets): include tokens with large balances and few decimals in aggregated balance cp-13.41.0 (#44796)
1e2f17bea8 feat: upgrade bridge packages to latest versions (#44722)
5fb686386e release: Bump main version to 13.43.0 (#44799)

AI Test Plan

Risk Score High Risk Medium Risk Files Changed Commits
55/100 6 6 1356 168
Cherry-Pick Scenarios (2)

High Risk Scenarios (1)

1. Smart Transactions – tx-sentinel routing (Robinhood)

Risk Level: HIGH

Why This Matters: Cherry-pick #45214 fixes Smart Transactions controller routing; incorrect sentinel URL would break preflight/monitoring, stalling or misreporting transactions.

Test Steps:

  1. Enable Smart Transactions (if gated) and prepare a simple ETH transfer on supported network.
  2. Proceed to the confirmation screen and send; in background DevTools, verify preflight/monitoring calls are routed to the new tx-sentinel Robinhood URL without errors.
  3. Confirm the transaction status updates (queued/mined) are received and displayed; ensure non-Smart-Transaction sends still function normally.

Medium Risk Scenarios (1)

1. Perps – Order Book on Order Entry page

Risk Level: MEDIUM

Why This Matters: Cherry-pick #45151 adds a new live Order Book to a trading surface; rendering or streaming regressions mislead users at the point of order placement.

Test Steps:

  1. Open the Perps order entry page and verify the Order Book renders with bids/asks and updates live.
  2. Switch accounts/networks and confirm the Order Book refreshes appropriately without stale data.
  3. Interact with the order size/price inputs and ensure the Order Book does not freeze or desync while you edit.

Release Scenarios (10)

High Risk Scenarios (5)

1. State Migrations 220/221 – data integrity on upgrade

Risk Level: HIGH

Why This Matters: Migrations can corrupt or drop persisted data; ensuring accounts, networks, and permissions survive the upgrade is critical to prevent user lockout or fund visibility issues.

Test Steps:

  1. Start from a profile on 13.42.x with: two imported accounts (one seed-derived, one private-key import), at least one custom network (custom RPC), and one connected site permission.
  2. Upgrade to 13.43.0 and unlock the wallet.
  3. Verify all accounts appear with correct names/addresses and balances; switch networks and confirm balances load without errors.
  4. Open Settings > Networks and confirm custom network(s) persist with correct chainId, RPC, and currency symbol.
  5. Open Connected sites for the active account and confirm existing site permissions remain intact and functional.

2. State Migrations 220/221 – stability and idempotency

Risk Level: HIGH

Why This Matters: Migrations must be no-op after the first run and must not break new installs; repeated initialization can surface race conditions that corrupt storage.

Test Steps:

  1. On 13.43.0, create a fresh wallet and confirm onboarding completes without migration errors.
  2. Lock the wallet, close the extension, reopen and unlock to re-trigger state initialization paths.
  3. Confirm no migration error banners appear and state (accounts, networks, settings) is unchanged after repeated loads.
  4. Toggle between multiple browser windows and ensure no duplicate or conflicting state is produced (e.g., duplicated accounts/networks).

3. MetaMetrics – consent gating and event suppression

Risk Level: HIGH

Why This Matters: Large changes in metametrics-controller can unintentionally send events when consent is off or include sensitive data, violating user privacy expectations.

Test Steps:

  1. In Settings > Advanced, toggle MetaMetrics OFF.
  2. Perform common actions: switch networks, view account details, and initiate (but cancel) a send to a known address.
  3. In the extension background DevTools Network tab, observe that no telemetry requests are sent to analytics endpoints during these actions.
  4. Toggle MetaMetrics ON and repeat the actions; verify events resume and include basic context (e.g., network) without leaking addresses.

4. MetaMetrics – event context accuracy

Risk Level: HIGH

Why This Matters: Incorrect or missing event context (e.g., wrong chainId/account state) undermines product analytics and can cause misrouted experiments or support issues.

Test Steps:

  1. With MetaMetrics ON, switch between two networks (e.g., Ethereum Mainnet and a testnet).
  2. Open a dapp and connect the active account; then switch to a different account in the extension while the site remains connected to the first.
  3. Trigger common events (open extension, open activity tab, view asset) and monitor analytics payloads via background DevTools.
  4. Verify event payloads include correct chainId and reflect the actual active account state but do not include full addresses or PII.

5. App State – lock/unlock and UI restoration

Risk Level: HIGH

Why This Matters: App-state-controller changes risk UI dead-ends or inconsistent state after lifecycle events, which directly impacts usability and support burden.

Test Steps:

  1. Navigate to Home > Assets > toggle views (e.g., open Network filter modal) and leave the extension on this screen.
  2. Lock the wallet, reload the extension (service worker restart), then unlock.
  3. Verify you return to a stable Home state without blank screens or stuck modals, and navigation works.
  4. Confirm recent UI state (e.g., last selected tab) is consistent or gracefully reset, without losing core settings.

Medium Risk Scenarios (5)

1. Custom Network validation – invalid custom network alert

Risk Level: MEDIUM

Why This Matters: Network misconfiguration can silently break transactions; the alert must be timely, accurate, and recoverable via clear actions.

Test Steps:

  1. Add a custom network where the RPC endpoint returns a different chainId than configured.
  2. Open Home and switch to this custom network; interact with a dapp to trigger network use.
  3. Verify an 'Invalid custom network' alert appears; inspect details and CTA (e.g., to edit network).
  4. Correct the chainId/RPC configuration and confirm the alert disappears and transactions/requests work normally.

2. Connected sites – unconnected account alert

Risk Level: MEDIUM

Why This Matters: Prevents users from signing with unintended accounts and clarifies site connection state, reducing signing mistakes.

Test Steps:

  1. Connect Account A to a test dapp (site permissions).
  2. In the extension, switch the active account to Account B and return to the dapp tab.
  3. Verify the 'Unconnected account' alert appears in the extension UI and provides a clear way to connect Account B.
  4. Connect Account B from the prompt and confirm the alert clears and the dapp reflects the new account.

3. Assets – network filter in Asset List and total balance accuracy

Risk Level: MEDIUM

Why This Matters: Filtering errors or stale balance aggregation mislead users about holdings, potentially causing incorrect decisions.

Test Steps:

  1. On Home > Assets, open the control bar and use the Network Filter to select a single network (e.g., Mainnet).
  2. Verify only assets from the selected network are shown and the account-group total updates accordingly.
  3. Switch the filter to 'All networks' and confirm hidden assets reappear and the total reflects the sum across networks.
  4. Quickly toggle between networks to check for UI flicker or stale totals.

4. Perps – live data stream stability (order entry/market data)

Risk Level: MEDIUM

Why This Matters: Perps stream bridge/controller changes can cause silent data stalls or cross-context leaks, directly affecting trading accuracy.

Test Steps:

  1. Open the Perps view (order entry) from within the extension’s portfolio/trading section.
  2. Observe live market data updates (prices, positions) for at least 60 seconds.
  3. Background the extension tab/window for ~15 seconds, then return and confirm data resumes without manual refresh.
  4. Switch networks or accounts while viewing and verify the stream reconnects appropriately without stale or cross-account data.

5. Onboarding/UI tours – Account Icon Tour gating

Risk Level: MEDIUM

Why This Matters: Tour gating interacts with persisted app state; regressions cause repetitive prompts or missing guidance for new users.

Test Steps:

  1. Update an existing profile to 13.43.0 and open the extension; verify the Account Icon Tour does not re-trigger if previously dismissed.
  2. Create a new wallet and open the extension for the first time; verify the tour appears once and can be dismissed.
  3. Lock/unlock and confirm the tour remains dismissed if it was previously completed.

Teams Sign-off Status

Signed off: None yet

Awaiting sign-off (5):
Accounts, Assets, Networks, Onboarding, Transactions


Generated by AI Test Plan Analyzer (gpt-5) at 2026-08-11T08:22:03.538Z

AI generated test plan (JSON): test-plan-13.43.0.json

This branch had an error being deployed

1 failed, 2 active, and 3 inactive deployments
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

release-13.43.0 Issue or pull request that will be included in release 13.43.0 skip-benchmark-gate Disables `run-benchmarks/quality-gate` job team-bots Bot team (for MetaMask Bot, Runway Bot, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.