Repository navigation
chore(deps-dev): bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot - #3971
Closed
dependabot[bot] wants to merge 1 commit into
Conversation
dependabot
Bot
requested review from
MohammadHaroonAbuomar,
liamcrumm and
Prayag (prayagupa)
as code owners
September 15, 2026 03:10
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found. |
📦 Dependency diff (SBOM)Comparing main → dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1. ✅ No dependency changes detected. |
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1
branch
2 times, most recently
from
September 15, 2026 03:37
9cf3226 to
653f128
Compare
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1
branch
from
September 15, 2026 04:35
653f128 to
f6d4eca
Compare
Bumps [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) from 30.4.2 to 30.5.1. - [Release notes](https://github.com/jestjs/jest/releases) - [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md) - [Commits](https://github.com/jestjs/jest/commits/v30.5.1/packages/jest) --- updated-dependencies: - dependency-name: jest dependency-version: 30.5.1 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1
branch
from
September 15, 2026 14:29
f6d4eca to
624d398
Compare
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 15, 2026
The lockfile hash verifier took the package name from the trailing node_modules/ path segment. For npm aliases that segment is the alias, not the package: jest 30.5 depends on "@jest/react-is-18": "npm:react-is@^18", so the lockfile carries node_modules/@jest/react-is-18 with "name": "react-is". Looking the alias up on the registry returns 404 and fails the check for every PR that bumps jest (#3971, #3994). Read the real package from the entry's "name" field, and from a "npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup. Diagnostics keep the alias path so reviewers can find the entry. While there, fetch dist.tarball along with dist.integrity and compare it with the lockfile "resolved" URL. A resolved URL that changed while the hash stayed the same now shows up in the diff and fails the check. Fetchers may still return a bare SRI string; only NpmDist results get the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist to match its return type. bytes.fromhex, which the shasum fallback uses, goes into the spell-check dictionary. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 15, 2026
The install-script audit built its candidate list from the trailing node_modules/ path segment of each lockfile entry. For npm aliases that segment is the alias, not a registry package, so the registry probe returned 404 and the audit reported a hard failure. jest 30.5 adds two such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of react-is), which fails the audit on every jest bump (#3971, #3994). Resolve the alias before probing: use the entry's "name" field (lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and drop the pair when the target is unsafe or a range. The audit then queries react-is@18.3.1, the package npm actually installs. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 15, 2026
@parcel/watcher is the native file-system watcher that jest-haste-map 30.5 depends on, so every jest bump now adds it (#3971). Its install hook, scripts/build-from-source.js, only runs node-gyp when npm_config_build_from_source=true and exits without doing anything otherwise; the compiled addon ships in optional per-platform packages. That is the same class of install hook as esbuild, sass-embedded and node-gyp, which the allow-list already covers. CI installs with --ignore-scripts, so the hook never runs there in any case. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
19 of 47 tasks
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 17, 2026
The lockfile hash verifier took the package name from the trailing node_modules/ path segment. For npm aliases that segment is the alias, not the package: jest 30.5 depends on "@jest/react-is-18": "npm:react-is@^18", so the lockfile carries node_modules/@jest/react-is-18 with "name": "react-is". Looking the alias up on the registry returns 404 and fails the check for every PR that bumps jest (#3971, #3994). Read the real package from the entry's "name" field, and from a "npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup. Diagnostics keep the alias path so reviewers can find the entry. While there, fetch dist.tarball along with dist.integrity and compare it with the lockfile "resolved" URL. A resolved URL that changed while the hash stayed the same now shows up in the diff and fails the check. Fetchers may still return a bare SRI string; only NpmDist results get the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist to match its return type. bytes.fromhex, which the shasum fallback uses, goes into the spell-check dictionary. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 17, 2026
The install-script audit built its candidate list from the trailing node_modules/ path segment of each lockfile entry. For npm aliases that segment is the alias, not a registry package, so the registry probe returned 404 and the audit reported a hard failure. jest 30.5 adds two such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of react-is), which fails the audit on every jest bump (#3971, #3994). Resolve the alias before probing: use the entry's "name" field (lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and drop the pair when the target is unsafe or a range. The audit then queries react-is@18.3.1, the package npm actually installs. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 17, 2026
@parcel/watcher is the native file-system watcher that jest-haste-map 30.5 depends on, so every jest bump now adds it (#3971). Its install hook, scripts/build-from-source.js, only runs node-gyp when npm_config_build_from_source=true and exits without doing anything otherwise; the compiled addon ships in optional per-platform packages. That is the same class of install hook as esbuild, sass-embedded and node-gyp, which the allow-list already covers. CI installs with --ignore-scripts, so the hook never runs there in any case. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 21, 2026
The lockfile hash verifier took the package name from the trailing node_modules/ path segment. For npm aliases that segment is the alias, not the package: jest 30.5 depends on "@jest/react-is-18": "npm:react-is@^18", so the lockfile carries node_modules/@jest/react-is-18 with "name": "react-is". Looking the alias up on the registry returns 404 and fails the check for every PR that bumps jest (#3971, #3994). Read the real package from the entry's "name" field, and from a "npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup. Diagnostics keep the alias path so reviewers can find the entry. While there, fetch dist.tarball along with dist.integrity and compare it with the lockfile "resolved" URL. A resolved URL that changed while the hash stayed the same now shows up in the diff and fails the check. Fetchers may still return a bare SRI string; only NpmDist results get the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist to match its return type. bytes.fromhex, which the shasum fallback uses, goes into the spell-check dictionary. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 21, 2026
The install-script audit built its candidate list from the trailing node_modules/ path segment of each lockfile entry. For npm aliases that segment is the alias, not a registry package, so the registry probe returned 404 and the audit reported a hard failure. jest 30.5 adds two such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of react-is), which fails the audit on every jest bump (#3971, #3994). Resolve the alias before probing: use the entry's "name" field (lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and drop the pair when the target is unsafe or a range. The audit then queries react-is@18.3.1, the package npm actually installs. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 21, 2026
@parcel/watcher is the native file-system watcher that jest-haste-map 30.5 depends on, so every jest bump now adds it (#3971). Its install hook, scripts/build-from-source.js, only runs node-gyp when npm_config_build_from_source=true and exits without doing anything otherwise; the compiled addon ships in optional per-platform packages. That is the same class of install hook as esbuild, sass-embedded and node-gyp, which the allow-list already covers. CI installs with --ignore-scripts, so the hook never runs there in any case. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Contributor
Author
|
Superseded by #4118. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1
branch
September 23, 2026 22:43
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 24, 2026
The lockfile hash verifier took the package name from the trailing node_modules/ path segment. For npm aliases that segment is the alias, not the package: jest 30.5 depends on "@jest/react-is-18": "npm:react-is@^18", so the lockfile carries node_modules/@jest/react-is-18 with "name": "react-is". Looking the alias up on the registry returns 404 and fails the check for every PR that bumps jest (#3971, #3994). Read the real package from the entry's "name" field, and from a "npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup. Diagnostics keep the alias path so reviewers can find the entry. While there, fetch dist.tarball along with dist.integrity and compare it with the lockfile "resolved" URL. A resolved URL that changed while the hash stayed the same now shows up in the diff and fails the check. Fetchers may still return a bare SRI string; only NpmDist results get the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist to match its return type. bytes.fromhex, which the shasum fallback uses, goes into the spell-check dictionary. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 24, 2026
The install-script audit built its candidate list from the trailing node_modules/ path segment of each lockfile entry. For npm aliases that segment is the alias, not a registry package, so the registry probe returned 404 and the audit reported a hard failure. jest 30.5 adds two such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of react-is), which fails the audit on every jest bump (#3971, #3994). Resolve the alias before probing: use the entry's "name" field (lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and drop the pair when the target is unsafe or a range. The audit then queries react-is@18.3.1, the package npm actually installs. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 24, 2026
@parcel/watcher is the native file-system watcher that jest-haste-map 30.5 depends on, so every jest bump now adds it (#3971). Its install hook, scripts/build-from-source.js, only runs node-gyp when npm_config_build_from_source=true and exits without doing anything otherwise; the compiled addon ships in optional per-platform packages. That is the same class of install hook as esbuild, sass-embedded and node-gyp, which the allow-list already covers. CI installs with --ignore-scripts, so the hook never runs there in any case. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar
added a commit
that referenced
this pull request
Sep 26, 2026
…r on Node 22 (#4006) * fix(ci): resolve npm aliases in lockfile integrity check The lockfile hash verifier took the package name from the trailing node_modules/ path segment. For npm aliases that segment is the alias, not the package: jest 30.5 depends on "@jest/react-is-18": "npm:react-is@^18", so the lockfile carries node_modules/@jest/react-is-18 with "name": "react-is". Looking the alias up on the registry returns 404 and fails the check for every PR that bumps jest (#3971, #3994). Read the real package from the entry's "name" field, and from a "npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup. Diagnostics keep the alias path so reviewers can find the entry. While there, fetch dist.tarball along with dist.integrity and compare it with the lockfile "resolved" URL. A resolved URL that changed while the hash stayed the same now shows up in the diff and fails the check. Fetchers may still return a bare SRI string; only NpmDist results get the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist to match its return type. bytes.fromhex, which the shasum fallback uses, goes into the spell-check dictionary. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> * fix(ci): resolve npm aliases in install-script audit The install-script audit built its candidate list from the trailing node_modules/ path segment of each lockfile entry. For npm aliases that segment is the alias, not a registry package, so the registry probe returned 404 and the audit reported a hard failure. jest 30.5 adds two such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of react-is), which fails the audit on every jest bump (#3971, #3994). Resolve the alias before probing: use the entry's "name" field (lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and drop the pair when the target is unsafe or a range. The audit then queries react-is@18.3.1, the package npm actually installs. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> * ci: run agentos-mcp-server npm job on Node 22 vitest 5 (#3960) declares engines "^22.12.0 || ^24.0.0 || >=26.0.0" and @vitest/istanbul-lib-coverage requires Node 22 or newer. The agentos-mcp-server entry of the build-npm matrix pinned Node 20, so npm ci logs EBADENGINE for those packages and the test runner runs on a Node it does not support. Move only that entry to Node 22. The other matrix entries keep their versions and the package's package.json engines field is unchanged; actions/setup-node resolves "22" to the current 22.x release. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> * chore(ci): allow @parcel/watcher in the install-script audit @parcel/watcher is the native file-system watcher that jest-haste-map 30.5 depends on, so every jest bump now adds it (#3971). Its install hook, scripts/build-from-source.js, only runs node-gyp when npm_config_build_from_source=true and exits without doing anything otherwise; the compiled addon ships in optional per-platform packages. That is the same class of install hook as esbuild, sass-embedded and node-gyp, which the allow-list already covers. CI installs with --ignore-scripts, so the hook never runs there in any case. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> * fix(ci): reject malformed npm alias metadata Signed-off-by: Imran Siddique <imran.siddique@opaque.co> --------- Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-authored-by: Imran Siddique <imran.siddique@opaque.co>
Yuvraj Singh (yuvrajsingh2428)
pushed a commit
to yuvrajsingh2428/agent-governance-toolkit
that referenced
this pull request
Oct 1, 2026
…r on Node 22 (microsoft#4006) * fix(ci): resolve npm aliases in lockfile integrity check The lockfile hash verifier took the package name from the trailing node_modules/ path segment. For npm aliases that segment is the alias, not the package: jest 30.5 depends on "@jest/react-is-18": "npm:react-is@^18", so the lockfile carries node_modules/@jest/react-is-18 with "name": "react-is". Looking the alias up on the registry returns 404 and fails the check for every PR that bumps jest (microsoft#3971, microsoft#3994). Read the real package from the entry's "name" field, and from a "npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup. Diagnostics keep the alias path so reviewers can find the entry. While there, fetch dist.tarball along with dist.integrity and compare it with the lockfile "resolved" URL. A resolved URL that changed while the hash stayed the same now shows up in the diff and fails the check. Fetchers may still return a bare SRI string; only NpmDist results get the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist to match its return type. bytes.fromhex, which the shasum fallback uses, goes into the spell-check dictionary. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> * fix(ci): resolve npm aliases in install-script audit The install-script audit built its candidate list from the trailing node_modules/ path segment of each lockfile entry. For npm aliases that segment is the alias, not a registry package, so the registry probe returned 404 and the audit reported a hard failure. jest 30.5 adds two such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of react-is), which fails the audit on every jest bump (microsoft#3971, microsoft#3994). Resolve the alias before probing: use the entry's "name" field (lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and drop the pair when the target is unsafe or a range. The audit then queries react-is@18.3.1, the package npm actually installs. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> * ci: run agentos-mcp-server npm job on Node 22 vitest 5 (microsoft#3960) declares engines "^22.12.0 || ^24.0.0 || >=26.0.0" and @vitest/istanbul-lib-coverage requires Node 22 or newer. The agentos-mcp-server entry of the build-npm matrix pinned Node 20, so npm ci logs EBADENGINE for those packages and the test runner runs on a Node it does not support. Move only that entry to Node 22. The other matrix entries keep their versions and the package's package.json engines field is unchanged; actions/setup-node resolves "22" to the current 22.x release. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> * chore(ci): allow @parcel/watcher in the install-script audit @parcel/watcher is the native file-system watcher that jest-haste-map 30.5 depends on, so every jest bump now adds it (microsoft#3971). Its install hook, scripts/build-from-source.js, only runs node-gyp when npm_config_build_from_source=true and exits without doing anything otherwise; the compiled addon ships in optional per-platform packages. That is the same class of install hook as esbuild, sass-embedded and node-gyp, which the allow-list already covers. CI installs with --ignore-scripts, so the hook never runs there in any case. Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> * fix(ci): reject malformed npm alias metadata Signed-off-by: Imran Siddique <imran.siddique@opaque.co> --------- Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com> Signed-off-by: Imran Siddique <imran.siddique@opaque.co> Co-authored-by: Imran Siddique <imran.siddique@opaque.co> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps jest from 30.4.2 to 30.5.1.
Release notes
Sourced from jest's releases.
... (truncated)
Changelog
Sourced from jest's changelog.
... (truncated)
Commits
9ab14fev30.5.1912baa3v30.5.0b91717achore: refresh coding agent instructions (#16182)