Skip to content

chore(deps-dev): bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot - #3971

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Bumps jest from 30.4.2 to 30.5.1.

Release notes

Sourced from jest's releases.

v30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

New Contributors

Full Changelog: jestjs/jest@v30.5.0...v30.5.1

v30.5.0

On a personal note: King Harald V of Norway passed away this morning. He ascended the throne 35 years ago, two months before I was born. This release is dedicated to his memory. Hvil i fred 🇳🇴


This is a big release. It touches jest-runtime, jest-resolve and jest-haste-map in many places, and with this many changes there might be regressions 😬. If your suite behaves differently after upgrading, please open an issue.

Highlights

whenCalledWith

Mock functions can now configure return values per argument list, contributed by @​timkindberg (#16053):

const fn = jest.fn();
fn.whenCalledWith('apple').mockReturnValue('red');
fn.whenCalledWith('banana').mockReturnValue('yellow');
fn.whenCalledWith(expect.any(Number)).mockReturnValue('numeric');
fn('apple'); // 'red'
fn('banana'); // 'yellow'
fn(42); // 'numeric'
fn('grape'); // undefined

The returned object is a real Mock, so mockReturnValueOnce, mockResolvedValue, mockImplementation etc. all chain here too. Argument slots accept literals or any asymmetric matcher, with the same equality semantics as toHaveBeenCalledWith(). Calls that match nothing fall through to the base mock. See the Mock Functions docs for matching and precedence details.

Describe-level retries

jest.retryTimes() can now retry a whole describe block instead of a single test, contributed by @​soltonigiri (#16322). Each attempt reruns the block's beforeAll/afterAll hooks, child tests and nested describes, which helps when tests in a block depend on shared state:

</tr></table> 

... (truncated)

Changelog

Sourced from jest's changelog.

30.5.1

Fixes

  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #16390) (#16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#16413)

Chore & Maintenance

  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#16404)

30.5.0

Features

  • [@jest/expect-utils, jest-mock] Add mockFn.whenCalledWith(...args) for configuring return values per argument list, with first-class asymmetric-matcher support (#16053)
  • [@jest/expect-utils] Export AsymmetricMatcher and FunctionParameters types (previously private to expect) (#16053)
  • [jest-circus, jest-core, jest-jasmine2, jest-test-result, jest-types] --collectTests now expands test.each/describe.each cases and reports per-status counts (skipped/todo via the new wouldRun flag for selected tests) plus a summary line that match a real run, including under --testNamePattern and .only/fdescribe focus on both the circus and jasmine2 runners (#16259)
  • [jest-circus, jest-environment, jest-runtime, jest-types] Add describe-level retries via jest.retryTimes(..., {entireDescribe: true}) (#16322)
  • [jest-circus, jest-message-util, jest-reporters, jest-types] Add retryMessages to AssertionResult and export formatErrorStack, so the retry log renders nested cause and AggregateError sections with code frames instead of serialized [cause]:/[errors]: markers (#16316)
  • [jest-circus, jest-types] Add unhandledErrorsDetailed to Circus.RunResult, so an unhandled rejection reports its cause chain and AggregateError entries with code frames instead of a pre-serialized stack (#16316)
  • [jest-haste-map] Replace NodeWatcher and FSEventsWatcher with @parcel/watcher for the non-watchman watch path (#16188)
  • [jest-resolve] Bump unrs-resolver to 1.12.1, remove jest-pnp-resolver and unnecessary checks (#15721)
  • [jest-resolve] Honor Node's --preserve-symlinks / NODE_PRESERVE_SYMLINKS in the default resolver by passing symlinks: false to unrs-resolver (#16260)
  • [jest-runtime] Apply automocking and manual __mocks__ files to synchronously evaluable ESM graphs on Node 24.9+ - static imports, dynamic import() and require() of an ESM file now generate an automock from the real module's namespace instead of failing with "Attempting to import a mock without a factory". Graphs that need async evaluation (top-level await) or an async-only resolver or transformer still throw (#16391)
  • [jest-runtime] Route process.getBuiltinModule through the sandbox, so it returns the sandbox process and the hooked node:module instead of the host's (#16391)
  • [jest-runtime] Throw an actionable error from module.register() and module.registerHooks() inside a test - the hooks attached to the loader running Jest itself, never saw the sandboxed requires they were meant for, and stayed registered for every later test file in the worker (#16391)
  • [jest-runtime] Surface resolution and import-attribute errors in an ESM graph before executing any of its CJS dependencies on Node 24.9+, matching Node's run-nothing-on-a-broken-graph behavior; the legacy loader on older versions keeps its linking-time execution order (#16391)
  • [jest-runtime] Throw ERR_SOURCE_PHASE_NOT_DEFINED with an actionable message for import source and import.source(), instead of failing at instantiation with V8's bare "Source phase import object is not defined" (#16391)
  • [jest-runtime] Emit the JSON-without-import-attribute deprecation warning once per test file instead of once per worker, so it is no longer silently swallowed for every file after the first (#16391)
  • [jest-runtime] Set import.meta.main to true in the test file and false in every module it loads, matching Node 24+ (#16367)
  • [jest-runtime] Resolve the module-sync export condition, so a package that exposes its ESM entry point for require() loads the same file Node would (#16336)
  • [jest-snapshot] Add external snapshot paths to custom reporter failure details (#16374)

Fixes

  • [jest-console, jest-reporters] CustomConsole now buffers console output so TestResult.console is populated for reporters when verbose is enabled, while GitHubActionsReporter avoids replaying buffered output in verbose mode (#16155)
  • [expect, jest-message-util, jest-pattern, jest-regex-util, jest-util] Revert node: protocol imports to restore webpack/browser-bundle compatibility (#16167)
  • [expect] Widen toMatchObject and objectContaining parameter type from Record<string, unknown> to object so class instances are accepted (#16196)
  • [jest-circus] Call a generator test body with the shared test context, so this matches what a regular test function receives (#16347)
  • [jest-circus] Capture the error listeners of the parent process instead of the in-sandbox process, so listeners registered before the test file survive teardown and sandbox listeners no longer leak onto the parent (#16347)
  • [jest-circus] Clear currentlyRunningTest after skipped and todo tests (#16342)
  • [jest-circus] Prevent late done() callbacks from affecting later test or hook invocations (#16343)
  • [jest-circus, jest-jasmine2] Honor --expand when formatting node:assert failures, instead of always collapsing the diff (#16347)
  • [jest-circus, jest-jasmine2, jest-message-util] Serialize the inner errors of an AggregateError into failureMessages, retryReasons and unhandledErrors, so --json output and reporter annotations include them (#16316)
  • [jest-circus, jest-snapshot] Keep snapshot state and counts correct when a test retries (#16344)
  • [@jest/create-cache-key-function] Include the caller support flags in the generated key, so a transformer that emits ESM or CJS based on them no longer shares one cache entry between the two (#16331)

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 15, 2026
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 15, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@github-actions

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions github-actions Bot removed the dependencies Pull requests that update a dependency file label Sep 15, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

@github-actions github-actions Bot added the size/XL Extra large PR (500+ lines) label Sep 15, 2026
@github-actions

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1.

✅ No dependency changes detected.

@MohammadHaroonAbuomar MohammadHaroonAbuomar changed the title chore(deps-dev): Bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot chore(deps-dev): bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot Sep 15, 2026
@dependabot dependabot Bot changed the title chore(deps-dev): bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot chore(deps-dev): Bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot Sep 15, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1 branch 2 times, most recently from 9cf3226 to 653f128 Compare September 15, 2026 03:37
@MohammadHaroonAbuomar MohammadHaroonAbuomar changed the title chore(deps-dev): Bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot chore(deps-dev): bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot Sep 15, 2026
@dependabot dependabot Bot changed the title chore(deps-dev): bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot chore(deps-dev): Bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot Sep 15, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1 branch from 653f128 to f6d4eca Compare September 15, 2026 04:35
Bumps [jest](https://github.com/jestjs/jest/tree/HEAD/packages/jest) from 30.4.2 to 30.5.1.
- [Release notes](https://github.com/jestjs/jest/releases)
- [Changelog](https://github.com/jestjs/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jestjs/jest/commits/v30.5.1/packages/jest)

---
updated-dependencies:
- dependency-name: jest
  dependency-version: 30.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1 branch from f6d4eca to 624d398 Compare September 15, 2026 14:29
@MohammadHaroonAbuomar MohammadHaroonAbuomar changed the title chore(deps-dev): Bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot chore(deps-dev): bump jest from 30.4.2 to 30.5.1 in /agent-governance-python/agent-os/extensions/copilot Sep 15, 2026
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 15, 2026
The lockfile hash verifier took the package name from the trailing
node_modules/ path segment. For npm aliases that segment is the alias,
not the package: jest 30.5 depends on "@jest/react-is-18":
"npm:react-is@^18", so the lockfile carries
node_modules/@jest/react-is-18 with "name": "react-is". Looking the
alias up on the registry returns 404 and fails the check for every PR
that bumps jest (#3971, #3994).

Read the real package from the entry's "name" field, and from a
"npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup.
Diagnostics keep the alias path so reviewers can find the entry.

While there, fetch dist.tarball along with dist.integrity and compare
it with the lockfile "resolved" URL. A resolved URL that changed while
the hash stayed the same now shows up in the diff and fails the check.
Fetchers may still return a bare SRI string; only NpmDist results get
the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist
to match its return type. bytes.fromhex, which the shasum fallback
uses, goes into the spell-check dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 15, 2026
The install-script audit built its candidate list from the trailing
node_modules/ path segment of each lockfile entry. For npm aliases that
segment is the alias, not a registry package, so the registry probe
returned 404 and the audit reported a hard failure. jest 30.5 adds two
such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of
react-is), which fails the audit on every jest bump (#3971, #3994).

Resolve the alias before probing: use the entry's "name" field
(lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and
drop the pair when the target is unsafe or a range. The audit then
queries react-is@18.3.1, the package npm actually installs.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 15, 2026
@parcel/watcher is the native file-system watcher that jest-haste-map
30.5 depends on, so every jest bump now adds it (#3971). Its install
hook, scripts/build-from-source.js, only runs node-gyp when
npm_config_build_from_source=true and exits without doing anything
otherwise; the compiled addon ships in optional per-platform packages.
That is the same class of install hook as esbuild, sass-embedded and
node-gyp, which the allow-list already covers. CI installs with
--ignore-scripts, so the hook never runs there in any case.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 17, 2026
The lockfile hash verifier took the package name from the trailing
node_modules/ path segment. For npm aliases that segment is the alias,
not the package: jest 30.5 depends on "@jest/react-is-18":
"npm:react-is@^18", so the lockfile carries
node_modules/@jest/react-is-18 with "name": "react-is". Looking the
alias up on the registry returns 404 and fails the check for every PR
that bumps jest (#3971, #3994).

Read the real package from the entry's "name" field, and from a
"npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup.
Diagnostics keep the alias path so reviewers can find the entry.

While there, fetch dist.tarball along with dist.integrity and compare
it with the lockfile "resolved" URL. A resolved URL that changed while
the hash stayed the same now shows up in the diff and fails the check.
Fetchers may still return a bare SRI string; only NpmDist results get
the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist
to match its return type. bytes.fromhex, which the shasum fallback
uses, goes into the spell-check dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 17, 2026
The install-script audit built its candidate list from the trailing
node_modules/ path segment of each lockfile entry. For npm aliases that
segment is the alias, not a registry package, so the registry probe
returned 404 and the audit reported a hard failure. jest 30.5 adds two
such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of
react-is), which fails the audit on every jest bump (#3971, #3994).

Resolve the alias before probing: use the entry's "name" field
(lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and
drop the pair when the target is unsafe or a range. The audit then
queries react-is@18.3.1, the package npm actually installs.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 17, 2026
@parcel/watcher is the native file-system watcher that jest-haste-map
30.5 depends on, so every jest bump now adds it (#3971). Its install
hook, scripts/build-from-source.js, only runs node-gyp when
npm_config_build_from_source=true and exits without doing anything
otherwise; the compiled addon ships in optional per-platform packages.
That is the same class of install hook as esbuild, sass-embedded and
node-gyp, which the allow-list already covers. CI installs with
--ignore-scripts, so the hook never runs there in any case.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 21, 2026
The lockfile hash verifier took the package name from the trailing
node_modules/ path segment. For npm aliases that segment is the alias,
not the package: jest 30.5 depends on "@jest/react-is-18":
"npm:react-is@^18", so the lockfile carries
node_modules/@jest/react-is-18 with "name": "react-is". Looking the
alias up on the registry returns 404 and fails the check for every PR
that bumps jest (#3971, #3994).

Read the real package from the entry's "name" field, and from a
"npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup.
Diagnostics keep the alias path so reviewers can find the entry.

While there, fetch dist.tarball along with dist.integrity and compare
it with the lockfile "resolved" URL. A resolved URL that changed while
the hash stayed the same now shows up in the diff and fails the check.
Fetchers may still return a bare SRI string; only NpmDist results get
the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist
to match its return type. bytes.fromhex, which the shasum fallback
uses, goes into the spell-check dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 21, 2026
The install-script audit built its candidate list from the trailing
node_modules/ path segment of each lockfile entry. For npm aliases that
segment is the alias, not a registry package, so the registry probe
returned 404 and the audit reported a hard failure. jest 30.5 adds two
such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of
react-is), which fails the audit on every jest bump (#3971, #3994).

Resolve the alias before probing: use the entry's "name" field
(lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and
drop the pair when the target is unsafe or a range. The audit then
queries react-is@18.3.1, the package npm actually installs.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 21, 2026
@parcel/watcher is the native file-system watcher that jest-haste-map
30.5 depends on, so every jest bump now adds it (#3971). Its install
hook, scripts/build-from-source.js, only runs node-gyp when
npm_config_build_from_source=true and exits without doing anything
otherwise; the compiled addon ships in optional per-platform packages.
That is the same class of install hook as esbuild, sass-embedded and
node-gyp, which the allow-list already covers. CI installs with
--ignore-scripts, so the hook never runs there in any case.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #4118.

@dependabot dependabot Bot closed this Sep 23, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/agent-governance-python/agent-os/extensions/copilot/jest-30.5.1 branch September 23, 2026 22:43
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 24, 2026
The lockfile hash verifier took the package name from the trailing
node_modules/ path segment. For npm aliases that segment is the alias,
not the package: jest 30.5 depends on "@jest/react-is-18":
"npm:react-is@^18", so the lockfile carries
node_modules/@jest/react-is-18 with "name": "react-is". Looking the
alias up on the registry returns 404 and fails the check for every PR
that bumps jest (#3971, #3994).

Read the real package from the entry's "name" field, and from a
"npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup.
Diagnostics keep the alias path so reviewers can find the entry.

While there, fetch dist.tarball along with dist.integrity and compare
it with the lockfile "resolved" URL. A resolved URL that changed while
the hash stayed the same now shows up in the diff and fails the check.
Fetchers may still return a bare SRI string; only NpmDist results get
the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist
to match its return type. bytes.fromhex, which the shasum fallback
uses, goes into the spell-check dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 24, 2026
The install-script audit built its candidate list from the trailing
node_modules/ path segment of each lockfile entry. For npm aliases that
segment is the alias, not a registry package, so the registry probe
returned 404 and the audit reported a hard failure. jest 30.5 adds two
such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of
react-is), which fails the audit on every jest bump (#3971, #3994).

Resolve the alias before probing: use the entry's "name" field
(lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and
drop the pair when the target is unsafe or a range. The audit then
queries react-is@18.3.1, the package npm actually installs.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 24, 2026
@parcel/watcher is the native file-system watcher that jest-haste-map
30.5 depends on, so every jest bump now adds it (#3971). Its install
hook, scripts/build-from-source.js, only runs node-gyp when
npm_config_build_from_source=true and exits without doing anything
otherwise; the compiled addon ships in optional per-platform packages.
That is the same class of install hook as esbuild, sass-embedded and
node-gyp, which the allow-list already covers. CI installs with
--ignore-scripts, so the hook never runs there in any case.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
MohammadHaroonAbuomar added a commit that referenced this pull request Sep 26, 2026
…r on Node 22 (#4006)

* fix(ci): resolve npm aliases in lockfile integrity check

The lockfile hash verifier took the package name from the trailing
node_modules/ path segment. For npm aliases that segment is the alias,
not the package: jest 30.5 depends on "@jest/react-is-18":
"npm:react-is@^18", so the lockfile carries
node_modules/@jest/react-is-18 with "name": "react-is". Looking the
alias up on the registry returns 404 and fails the check for every PR
that bumps jest (#3971, #3994).

Read the real package from the entry's "name" field, and from a
"npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup.
Diagnostics keep the alias path so reviewers can find the entry.

While there, fetch dist.tarball along with dist.integrity and compare
it with the lockfile "resolved" URL. A resolved URL that changed while
the hash stayed the same now shows up in the diff and fails the check.
Fetchers may still return a bare SRI string; only NpmDist results get
the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist
to match its return type. bytes.fromhex, which the shasum fallback
uses, goes into the spell-check dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

* fix(ci): resolve npm aliases in install-script audit

The install-script audit built its candidate list from the trailing
node_modules/ path segment of each lockfile entry. For npm aliases that
segment is the alias, not a registry package, so the registry probe
returned 404 and the audit reported a hard failure. jest 30.5 adds two
such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of
react-is), which fails the audit on every jest bump (#3971, #3994).

Resolve the alias before probing: use the entry's "name" field
(lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and
drop the pair when the target is unsafe or a range. The audit then
queries react-is@18.3.1, the package npm actually installs.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

* ci: run agentos-mcp-server npm job on Node 22

vitest 5 (#3960) declares engines "^22.12.0 || ^24.0.0 || >=26.0.0"
and @vitest/istanbul-lib-coverage requires Node 22 or newer. The
agentos-mcp-server entry of the build-npm matrix pinned Node 20, so
npm ci logs EBADENGINE for those packages and the test runner runs on
a Node it does not support. Move only that entry to Node 22. The other
matrix entries keep their versions and the package's package.json
engines field is unchanged; actions/setup-node resolves "22" to the
current 22.x release.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

* chore(ci): allow @parcel/watcher in the install-script audit

@parcel/watcher is the native file-system watcher that jest-haste-map
30.5 depends on, so every jest bump now adds it (#3971). Its install
hook, scripts/build-from-source.js, only runs node-gyp when
npm_config_build_from_source=true and exits without doing anything
otherwise; the compiled addon ships in optional per-platform packages.
That is the same class of install hook as esbuild, sass-embedded and
node-gyp, which the allow-list already covers. CI installs with
--ignore-scripts, so the hook never runs there in any case.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

* fix(ci): reject malformed npm alias metadata

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: Imran Siddique <imran.siddique@opaque.co>
Yuvraj Singh (yuvrajsingh2428) pushed a commit to yuvrajsingh2428/agent-governance-toolkit that referenced this pull request Oct 1, 2026
…r on Node 22 (microsoft#4006)

* fix(ci): resolve npm aliases in lockfile integrity check

The lockfile hash verifier took the package name from the trailing
node_modules/ path segment. For npm aliases that segment is the alias,
not the package: jest 30.5 depends on "@jest/react-is-18":
"npm:react-is@^18", so the lockfile carries
node_modules/@jest/react-is-18 with "name": "react-is". Looking the
alias up on the registry returns 404 and fails the check for every PR
that bumps jest (microsoft#3971, microsoft#3994).

Read the real package from the entry's "name" field, and from a
"npm:<pkg>@<ver>" version spec for v1-style entries, before the lookup.
Diagnostics keep the alias path so reviewers can find the entry.

While there, fetch dist.tarball along with dist.integrity and compare
it with the lockfile "resolved" URL. A resolved URL that changed while
the hash stayed the same now shows up in the diff and fails the check.
Fetchers may still return a bare SRI string; only NpmDist results get
the tarball comparison. fetch_npm_integrity is renamed fetch_npm_dist
to match its return type. bytes.fromhex, which the shasum fallback
uses, goes into the spell-check dictionary.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

* fix(ci): resolve npm aliases in install-script audit

The install-script audit built its candidate list from the trailing
node_modules/ path segment of each lockfile entry. For npm aliases that
segment is the alias, not a registry package, so the registry probe
returned 404 and the audit reported a hard failure. jest 30.5 adds two
such entries (@jest/react-is-18 and @jest/react-is-19, both aliases of
react-is), which fails the audit on every jest bump (microsoft#3971, microsoft#3994).

Resolve the alias before probing: use the entry's "name" field
(lockfile v2/v3) or the "npm:<pkg>@<ver>" version spec (v1 shape), and
drop the pair when the target is unsafe or a range. The audit then
queries react-is@18.3.1, the package npm actually installs.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

* ci: run agentos-mcp-server npm job on Node 22

vitest 5 (microsoft#3960) declares engines "^22.12.0 || ^24.0.0 || >=26.0.0"
and @vitest/istanbul-lib-coverage requires Node 22 or newer. The
agentos-mcp-server entry of the build-npm matrix pinned Node 20, so
npm ci logs EBADENGINE for those packages and the test runner runs on
a Node it does not support. Move only that entry to Node 22. The other
matrix entries keep their versions and the package's package.json
engines field is unchanged; actions/setup-node resolves "22" to the
current 22.x release.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

* chore(ci): allow @parcel/watcher in the install-script audit

@parcel/watcher is the native file-system watcher that jest-haste-map
30.5 depends on, so every jest bump now adds it (microsoft#3971). Its install
hook, scripts/build-from-source.js, only runs node-gyp when
npm_config_build_from_source=true and exits without doing anything
otherwise; the compiled addon ships in optional per-platform packages.
That is the same class of install hook as esbuild, sass-embedded and
node-gyp, which the allow-list already covers. CI installs with
--ignore-scripts, so the hook never runs there in any case.

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>

* fix(ci): reject malformed npm alias metadata

Signed-off-by: Imran Siddique <imran.siddique@opaque.co>

---------

Signed-off-by: MohammadHaroonAbuomar <40180927+MohammadHaroonAbuomar@users.noreply.github.com>
Signed-off-by: Imran Siddique <imran.siddique@opaque.co>
Co-authored-by: Imran Siddique <imran.siddique@opaque.co>
Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XL Extra large PR (500+ lines)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants