Skip to content

Update dependency @nomicfoundation/hardhat-viem to v3.0.9 - #1303

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/nomicfoundation-hardhat-viem-3.x
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/nomicfoundation-hardhat-viem-3.x

Conversation

@renovate

@renovate renovate Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@nomicfoundation/hardhat-viem (source) 3.0.8 → 3.0.9 age adoption passing confidence

Release Notes

NomicFoundation/hardhat (@​nomicfoundation/hardhat-viem)

v3.0.9

Compare Source

Patch Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@socket-security

socket-security Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​@​nomicfoundation/​hardhat-viem@​3.0.99410010090100

View full report

@socket-security

socket-security Bot commented Sep 3, 2026 •

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Low
Potential code anomaly (AI signal): npm @nomicfoundation/hardhat-utils is 66.0% likely to have a medium risk anomaly

Notes: No direct malware, exfiltration, or obfuscated payload is evident in this fragment. The main risk is security/operational: it is a detached-process launcher that directly executes a caller-chosen entrypoint (including .ts via tsx/esm) with caller-provided arguments and environment, while suppressing output/errors (stdio:'ignore'). If any of absolutePathToSubProcessFile/args/env can be influenced by an attacker, this becomes a practical arbitrary code execution primitive in the spawned context.

Confidence: 0.66

Severity: 0.55

From: yarn.lock → npm/@nomicfoundation/hardhat-viem@3.0.9 → npm/@nomicfoundation/hardhat-utils@4.3.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@nomicfoundation/hardhat-utils@4.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm @nomicfoundation/hardhat-utils is 66.0% likely to have a medium risk anomaly

Notes: This module is primarily a subprocess launcher. It validates that the target file exists and is not a directory, then uses child_process.spawn to execute Node with the caller-provided entry path, arguments, and environment. While the snippet contains no overt malicious or obfuscated payload behavior, it effectively enables arbitrary code execution by design if an attacker can influence absolutePathToSubProcessFile/args/env at a higher layer. Detached execution and ignored stdio reduce observability.

Confidence: 0.66

Severity: 0.56

From: yarn.lock → npm/@nomicfoundation/hardhat-viem@3.0.9 → npm/@nomicfoundation/hardhat-utils@4.3.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@nomicfoundation/hardhat-utils@4.3.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block Low
Potential code anomaly (AI signal): npm undici is 68.0% likely to have a medium risk anomaly

Notes: Both alerts describe an in-place re-encoding of a local file from UTF-8 to Latin-1, overwriting the original without backups or validation. This can cause data loss and code corruption, creating a supply-chain tampering risk. The script itself shows no exfiltration or network activity, but its destructive behavior warrants deletion or strict safeguards and auditing.

Confidence: 0.68

Severity: 0.60

From: yarn.lock → npm/@nomicfoundation/hardhat-viem@3.0.9 → npm/undici@7.29.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/undici@7.29.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate
renovate Bot force-pushed the renovate/nomicfoundation-hardhat-viem-3.x branch from 64ad08d to d181ce3 Compare September 7, 2026 23:28
@renovate
renovate Bot force-pushed the renovate/nomicfoundation-hardhat-viem-3.x branch from d181ce3 to aa4e82d Compare September 24, 2026 19:31
@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8ab36904-5b02-4360-9009-a0e61669e3a8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants