Skip to content

Conversation

@bc-alexsaiannyi
Copy link
Contributor

@bc-alexsaiannyi bc-alexsaiannyi commented Aug 15, 2025

What?

This PR addresses a vulnerability in one of transitive dependences through bumping version to number of packages:

  • jest,
  • jest-environment-jsdom
  • jest-jasmine2
  • babel-jest

All of them are bumped to next major version - 30.0.5

Requirements

  • CHANGELOG.md entry added (required for code changes only)

Tickets / Documentation

Testing

  1. Run npm audit at the beginning
  2. Bump required packages (jest related) to fix vulnerability
  3. Run npm test for check any test failures
  4. Run npm test -- --verbose to check more details

Screenshots (if appropriate)

critical_vulnar after_update audit_after

@bc-alexsaiannyi bc-alexsaiannyi marked this pull request as ready for review August 15, 2025 12:40
@rtalvarez
Copy link
Member

Done in #2570

@rtalvarez rtalvarez closed this Sep 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants