Skip to content

chore(deps): update jestjs-jest to ^30.5.2 - #10514

Merged
cryptodev-2s merged 3 commits into
mainfrom
renovate/jestjs-jest
Sep 29, 2026
Merged

cryptodev-2s merged 3 commits into
mainfrom
renovate/jestjs-jest

Conversation

@metamask-ci

@metamask-ci metamask-ci Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@jest/globals (source) ^30.4.1 → ^30.5.2 age confidence
jest (source) ^30.4.2 → ^30.5.2 age confidence
jest-environment-jsdom (source) ^30.4.1 → ^30.5.2 age confidence
jest-environment-node (source) ^30.4.1 → ^30.5.2 age confidence

Release Notes

jestjs/jest (@​jest/globals)

v30.5.2

Compare Source

Features
  • [@jest/transform] Strip TypeScript types with Node when no transformer claims a .ts, .mts or .cts file (#​16421)
Fixes
  • [jest-core, jest-haste-map, jest-transform] Keep require('../package.json') external when bundling, so jest --version and the transform and haste-map cache keys report the released version instead of the previous one (#​16422)
  • [jest-each] Escape a table row's keys before building the $variable interpolation RegExp, so a column name such as count(*) no longer fails the whole table with Invalid regular expression, and a . or | in a column name is matched literally (#​16345)
  • [@jest/source-map] Resolve absolute Windows paths in a source map's sources and sourceRoot again, instead of appending them to the transformed file's directory (#​16439)

v30.5.1

Compare Source

Fixes
  • [jest-config] Don't warn about global-only options in the config that supplies the global config - the root config a project resolves to, or the first entry of --projects when no root config is passed (#​16411)
  • [jest-config, jest-types] Stop accepting reporters, coverageReporters, workerIdleMemoryLimit, cwd and runnerOptions in a project config - they were silently ignored, and now warn like the other global-only options (#​16411)
  • [jest-config, jest-validate] Warn about maxWorkers and coverageThreshold in a project config instead of dropping them without a word (#​16411)
  • [jest-resolve] Match moduleNameMapper patterns against the specifier as written again (reverting #​16390) (#​16417)
  • [jest-runtime] Resolve package imports specifiers like #dep under ESM again (#​16413)
Chore & Maintenance
  • [jest-util] Name the testEnvironmentOptions.globalsCleanup option and link the docs from the JEST-01 deprecation warning, and document the option's modes (#​16404)

v30.5.0

Compare Source

Features
  • [@jest/expect-utils, jest-mock] Add mockFn.whenCalledWith(...args) for configuring return values per argument list, with first-class asymmetric-matcher support (#​16053)
  • [@jest/expect-utils] Export AsymmetricMatcher and FunctionParameters types (previously private to expect) (#​16053)
  • [jest-circus, jest-core, jest-jasmine2, jest-test-result, jest-types] --collectTests now expands test.each/describe.each cases and reports per-status counts (skipped/todo via the new wouldRun flag for selected tests) plus a summary line that match a real run, including under --testNamePattern and .only/fdescribe focus on both the circus and jasmine2 runners (#​16259)
  • [jest-circus, jest-environment, jest-runtime, jest-types] Add describe-level retries via jest.retryTimes(..., {entireDescribe: true}) (#​16322)
  • [jest-circus, jest-message-util, jest-reporters, jest-types] Add retryMessages to AssertionResult and export formatErrorStack, so the retry log renders nested cause and AggregateError sections with code frames instead of serialized [cause]:/[errors]: markers (#​16316)
  • [jest-circus, jest-types] Add unhandledErrorsDetailed to Circus.RunResult, so an unhandled rejection reports its cause chain and AggregateError entries with code frames instead of a pre-serialized stack (#​16316)
  • [jest-haste-map] Replace NodeWatcher and FSEventsWatcher with @parcel/watcher for the non-watchman watch path (#​16188)
  • [jest-resolve] Bump unrs-resolver to 1.12.1, remove jest-pnp-resolver and unnecessary checks (#​15721)
  • [jest-resolve] Honor Node's --preserve-symlinks / NODE_PRESERVE_SYMLINKS in the default resolver by passing symlinks: false to unrs-resolver (#​16260)
  • [jest-runtime] Apply automocking and manual __mocks__ files to synchronously evaluable ESM graphs on Node 24.9+ - static imports, dynamic import() and require() of an ESM file now generate an automock from the real module's namespace instead of failing with "Attempting to import a mock without a factory". Graphs that need async evaluation (top-level await) or an async-only resolver or transformer still throw (#​16391)
  • [jest-runtime] Route process.getBuiltinModule through the sandbox, so it returns the sandbox process and the hooked node:module instead of the host's (#​16391)
  • [jest-runtime] Throw an actionable error from module.register() and module.registerHooks() inside a test - the hooks attached to the loader running Jest itself, never saw the sandboxed requires they were meant for, and stayed registered for every later test file in the worker (#​16391)
  • [jest-runtime] Surface resolution and import-attribute errors in an ESM graph before executing any of its CJS dependencies on Node 24.9+, matching Node's run-nothing-on-a-broken-graph behavior; the legacy loader on older versions keeps its linking-time execution order (#​16391)
  • [jest-runtime] Throw ERR_SOURCE_PHASE_NOT_DEFINED with an actionable message for import source and import.source(), instead of failing at instantiation with V8's bare "Source phase import object is not defined" (#​16391)
  • [jest-runtime] Emit the JSON-without-import-attribute deprecation warning once per test file instead of once per worker, so it is no longer silently swallowed for every file after the first (#​16391)
  • [jest-runtime] Set import.meta.main to true in the test file and false in every module it loads, matching Node 24+ (#​16367)
  • [jest-runtime] Resolve the module-sync export condition, so a package that exposes its ESM entry point for require() loads the same file Node would (#​16336)
  • [jest-snapshot] Add external snapshot paths to custom reporter failure details (#​16374)
Fixes
  • [jest-console, jest-reporters] CustomConsole now buffers console output so TestResult.console is populated for reporters when verbose is enabled, while GitHubActionsReporter avoids replaying buffered output in verbose mode (#​16155)
  • [expect, jest-message-util, jest-pattern, jest-regex-util, jest-util] Revert node: protocol imports to restore webpack/browser-bundle compatibility (#​16167)
  • [expect] Widen toMatchObject and objectContaining parameter type from Record<string, unknown> to object so class instances are accepted (#​16196)
  • [jest-circus] Call a generator test body with the shared test context, so this matches what a regular test function receives (#​16347)
  • [jest-circus] Capture the error listeners of the parent process instead of the in-sandbox process, so listeners registered before the test file survive teardown and sandbox listeners no longer leak onto the parent (#​16347)
  • [jest-circus] Clear currentlyRunningTest after skipped and todo tests (#​16342)
  • [jest-circus] Prevent late done() callbacks from affecting later test or hook invocations (#​16343)
  • [jest-circus, jest-jasmine2] Honor --expand when formatting node:assert failures, instead of always collapsing the diff (#​16347)
  • [jest-circus, jest-jasmine2, jest-message-util] Serialize the inner errors of an AggregateError into failureMessages, retryReasons and unhandledErrors, so --json output and reporter annotations include them (#​16316)
  • [jest-circus, jest-snapshot] Keep snapshot state and counts correct when a test retries (#​16344)
  • [@jest/create-cache-key-function] Include the caller support flags in the generated key, so a transformer that emits ESM or CJS based on them no longer shares one cache entry between the two (#​16331)
  • [@jest/create-cache-key-function] Include the stringified project config in the generated key, so editing a transformer's own settings invalidates what it cached (#​16331)
  • [@jest/transform] Include the caller support flags in a transform's cache key, so a file transformed both as ESM and as CJS no longer serves one shape's output for the other (#​16331)
  • [jest-config] Add missing findRelatedTests, outputFile, and replname entries to ValidConfig so they no longer trigger spurious "Unknown option" warnings (#​16224)
  • [jest-config] Use --config for the global config when multiple --projects are specified (#​16273)
  • [jest-core] Serialize bigint values in --json and --outputFile output as their literal form (4n), instead of failing the run with TypeError: Do not know how to serialize a BigInt (#​16338)
  • [jest-core] Do not report a CustomGC async resource (used by N-API addons such as napi-rs for per-isolate GC bookkeeping) as an open handle, since it is napi_unref'd by the addon and can never keep the event loop alive (#​16379)
  • [jest-each] Keep a $&, $`, $' or $$ inside a %p param value out of the replacement, so the title shows the value instead of the text around it (#​16338)
  • [jest-each] Interpolate a bigint into a %j title as its literal form ("4n") at any depth, instead of throwing TypeError: Do not know how to serialize a BigInt while collecting the tests (#​16338)
  • [jest-environment, jest-runtime] Bind sandboxInjectedGlobals to the right values when injectGlobals is false, instead of shifting every one of them by a position (#​16377)
  • [jest-environment-node, jest-util] Only warn about a conflicting globalsCleanup mode when one was explicitly configured, and follow the mode that is actually in effect (#​16323)
  • [jest-environment-node, jest-util] Stop resolving lazy globals when setting up an environment, so Node 26's builtin module globals are no longer loaded (and no longer emit their deprecation warnings) for every test file (#​16324)
  • [jest-haste-map] Keep watch mode alive when an outside process briefly makes a file unreadable on Windows, instead of tearing the watcher down on EPERM (#​16295)
  • [jest-haste-map] Keep indexing when an outside process holds a file open on Windows, instead of failing the whole crawl on EPERM (#​16358)
  • [jest-haste-map] Keep a duplicated manual mock resolving when the file it pointed at is deleted in watch mode (#​16360)
  • [jest-haste-map] Shut the worker farm down when a duplicate manual mock aborts the build under throwOnModuleCollision (#​16354)
  • [jest-haste-map] Attach the watchman client's error listener before the first command, so a watchman failure falls back to the node crawler instead of crashing on an unhandled error event, and always end the client (#​16355)
  • [jest-haste-map] Stop delivering watch events after WatchmanWatcher is closed, and route its warnings through the configured console (#​16355)
  • [jest-haste-map] Restore the nested duplicates index correctly in ModuleMap.fromJSON, so a haste collision reported inside a test worker raises DuplicateHasteCandidatesError instead of a TypeError (#​16353)
  • [jest-haste-map] Match watched files on a full extension, so moduleFileExtensions: ['js'] no longer accepts foo.mjs (#​16352)
  • [jest-haste-map] Delimit the fields that make up the haste map cache key, so two different option sets cannot hash to the same cache file (#​16352)
  • [jest-message-util] Print the inner errors of an AggregateError thrown inside a test (#​16316)
  • [jest-message-util] Indent nested cause and AggregateError sections of a test failure by one level per depth, so the nesting is legible instead of rendering flat (#​16316)
  • [jest-message-util] Color stack traces line by line so blank lines stay blank (#​16316)
  • [jest-message-util] Detect Jest's own frames without assuming the checkout directory's name, and cover @jest/* packages, so stack traces and code frames point at user code (#​16326)
  • [jest-mock] mockResolvedValue / mockRejectedValue now see all overload return types, so a Promise-returning overload survives even when a later overload returns a non-Promise (e.g. pg.Client['end']) (#​16237)
  • [@jest-environment/jsdom-abstract] Make @types/jsdom a peer dependency (#​16166)
  • [jest-mock] Remove the leftover own accessor descriptor when restoring a spyOn of an inherited getter or setter, so the instance keeps reflecting the prototype (#​16226)
  • [jest-resolve] Include extensionsToTreatAsEsm in the shouldLoadAsEsm cache key, so projects with different extension lists don't read each other's answers (#​16369)
  • [jest-resolve] Make getModuleIDAsync build and cache data: URI module IDs the same way as getModuleID (#​16370)
  • [jest-resolve] Keep the node: prefix when resolving a core module asynchronously, so a builtin that only exists prefixed (node:sea, node:sqlite, node:test, node:test/reporters) resolves instead of failing as a missing bare package (#​16388)
  • [jest-resolve] Look up manual mocks for node: protocol specifiers under the unprefixed name they are stored as (#​16388)
  • [jest-resolve] Apply moduleNameMapper consistently to both spellings of core module specifiers (fs vs node:fs) (#​16390)
  • [jest-resolve] Keep virtual and ordinary mock module IDs isolated across test files (#​16296)
  • [jest-resolve] Guard missing require.resolve.paths (#​16052)
  • [jest-resolve, jest-config, jest-runner] Support a user resolver written as an ES module (#​16332)
  • [jest-resolve, jest-runtime] Throw the CJS parse error for ESM syntax in a "type": "commonjs" package or a .cjs file instead of loading it as ESM, matching Node (#​16368)
  • [@jest/source-map] Keep source map sources that name a scheme, such as webpack:///, instead of resolving them into a path that does not exist (#​16327)
  • [@jest/source-map] Look up --testLocationInResults positions at the right column, and keep a mapping to the first column instead of discarding it (#​16327)
  • [@jest/source-map] Warn when a source map cannot be parsed, instead of silently leaving its frames untranslated (#​16327)
  • [jest-runner, @jest/source-map] Keep a source-mapped stack for an error thrown after the test environment was torn down (#​16327)
  • [jest-runtime, @jest/source-map] Keep source maps past teardown and past the next test file's install, so a stack from a file no earlier stack mentioned still points at the original source (#​16330)
  • [jest-runtime] Report that no coverage was collected when getAllV8CoverageInfoCopy is called after teardown, instead of returning an empty result (#​16385)
  • [jest-runtime] Cache a CJS module's parsed exports before walking its re-exports, so two modules that re-export each other no longer overflow the stack when imported from ESM (#​16363)
  • [jest-runtime] Keep a re-exported ES module's parse failure from marking the re-exporting CommonJS file as ESM, so module.exports = require('./dep.mjs') loads instead of failing with module is not defined (#​16363)
  • [jest-runtime] Scope module mocks instantiated inside jest.isolateModules/isolateModulesAsync to that block, so a mock first imported there no longer outlives it - matching how CommonJS mocks already behave (#​16365)
  • [jest-runtime] Suspend module isolation while generating an automock, so loading the real module to read its shape no longer populates the isolated registry (#​16365)
  • [jest-runtime] Check a cached ES module's status before require() returns it, so a module whose evaluation threw rethrows that error and one left linked by a failed sibling is evaluated instead of returning uninitialized bindings (#​16364)
  • [jest-runtime] Report the original ERR_REQUIRE_ASYNC_MODULE when a require() of a top-level-await graph is retried, instead of a spurious "concurrent import()" error (#​16364)
  • [jest-runtime] Throw the evaluation error when another caller's import() of the same module failed while we awaited it, instead of resolving with the errored module (#​16364)
  • [jest-runtime] Mark the result of require()ing an ES module that has a default export with __esModule: true through a live-binding facade, and serve the same object from require.cache, matching Node (#​16367)
  • [jest-runtime] Provide a CommonJS module's exports under the 'module.exports' named export when imported from ESM, matching Node 23+ (#​16367)
  • [jest-runtime] Give the test file itself a non-null require.main (#​16367)
  • [jest-runtime] Populate module.children with the modules a file loads, matching Node (#​16368)
  • [jest-runtime] Provide import.meta.resolve and import.meta.jest in data: URI modules, accept any-case mediatype parameters, and use Node's error codes for invalid data: URIs (#​16368)
  • [jest-runtime] Key ES modules by full URL, so query and fragment suffixes create the same module instances as Node and show up in import.meta.url (#​16375)
  • [jest-runtime] Share modules between overlapping graphs when a CommonJS module require()s an ES module mid-load, instead of evaluating shared dependencies twice (#​16375)
  • [jest-runtime] Throw ERR_REQUIRE_CYCLE_MODULE like Node when a CommonJS module require()s an ES module that is still being loaded, instead of evaluating the module a second time (#​16366)
  • [jest-runtime] Key builtin modules in the ESM registry by one canonical specifier (#​16341)
  • [jest-runtime] import.meta.resolve() for a builtin uses its node: specifier (#​16341)
  • [jest-runtime] Fall back to native ESM when a .js file contains ESM syntax but has no "type":"module" marker (#​16152)
  • [jest-runtime] Allow require() of ESM-marked files on Node < 24.9 via transform fallback (#​16244)
  • [jest-runtime, @jest/transform] Surface actionable ERR_REQUIRE_ESM error for files with untransformed ESM syntax instead of the generic "unexpected token" message (#​16244)
  • [jest-runtime] Support older test environments whose moduleMocker does not implement clearMocksOnScope (#​16169)
  • [jest-runtime] Apply jest.unstable_mockModule when the mocked file itself is require()d, not only when it is imported as a dependency (#​16389)
  • [jest-runtime] Apply jest.unstable_mockModule to statically imported data: URIs on Node 24.9+, matching dynamic import() (#​16389)
  • [jest-runtime] Run an async jest.unstable_mockModule factory once per module instead of twice, and fail the import instead of crashing the worker when the factory rejects (#​16389)
  • [jest-runtime] Hide a require(esm) module that failed to evaluate from require.cache, as Node does, instead of exposing a namespace with uninitialized bindings (#​16389)
  • [jest-runtime] Strip the byte-order mark when importing a JSON module, matching require() and Node (#​16389)
  • [jest-runtime] Throw ERR_REQUIRE_ASYNC_MODULE when require(esm) runs under an async-only custom resolver, instead of silently resolving with the default resolver (#​16389)
  • [jest-runtime] Parse imported JSON modules with the test realm's JSON, so their objects pass instanceof Object inside the test like require()d JSON does (#​16389)
  • [jest-runtime] Accept every file: URL string in the sandboxed module.createRequire, including one with a localhost authority, as Node does (#​16389)
  • [jest-runtime] Point at {virtual: true} when jest.mock or jest.unstable_mockModule is given a module that cannot be resolved (#​16389)
  • [jest-reporters] Fix coverage report table formatting in CI/GitHub Actions environments where process.stdout.columns is undefined by falling back to the COLUMNS env var or 80 columns in CI, preserving existing behaviour in other non-TTY environments (#​16227)
  • [jest-runtime] Support CJS-in-ESM exports via "module.exports" named exports (#​16277)
  • [jest-snapshot] Keep a skipped or failed test's hinted snapshots, instead of reporting them obsolete (#​16348)
  • [jest-util] Stop globsToMatcher reusing a cached matcher compiled with different picomatch options, and keep its dot: true default when dot is passed as undefined (#​16381)
  • [pretty-format] Move the react-is aliases into the @jest scope, so they cannot be shadowed by unrelated packages published under the alias names (#​16333)
Chore & Maintenance
  • [docs] Document the intentional divergences from Node's module system in the ECMAScript Modules page (#​16368)
  • [docs] Note deprecation of react-test-renderer in React Native tutorial and pretty-format README (#​16294)
  • [docs] Use @testing-library/react-native in the React Native tutorial instead of the deprecated react-test-renderer (#​16318)
  • [babel-jest, @jest/transform] Update babel-plugin-istanbul to v8 (#​16049)
  • [jest-config, @jest/reporters, jest-runtime] Update glob to v13 (#​16397)
  • [jest-haste-map] Refactor massive class into multiple files (#​16180)
  • [jest-haste-map] Drop walker dependency; replace hand-rolled directory recursion in the JS crawler and watcher startup with fdir (#​16187)
  • [jest-haste-map] Reuse cached metadata for files whose haste name is a known duplicate, instead of re-reading and re-parsing them on every startup (#​16351)
  • [jest-haste-map] Cache the watchman socket path and replace the watchman --version probe with get-sockname, so warm runs spawn no watchman processes (#​16386)
  • [jest-resolve] Store the per-directory package-type lookup in the cache it reads, so it actually memoizes (#​16369)
  • [jest-resolve, jest-runtime] Cut repeated work on the resolution hot path: hoist the platform-extension list to construction, memoize isCoreModule and the options cache-key serialization, skip mapper preparation when no moduleNameMapper is configured, run each mapper regex once, and stop re-parsing NODE_OPTIONS on every default-resolver call (#​16371)
  • [jest-resolve] Cut warm resolution cost to about a third: reuse one unrs-resolver factory per options shape instead of cloning per resolution, compose the factory cache key from per-array cached strings instead of serializing options, and stop constructing an Error for misses that findNodeModule swallows; add a __benchmarks__ suite for the default resolver (#​16373)
  • [jest-runner, @jest/source-map] Replace source-map-support with an implementation in @jest/source-map (#​16327)
  • [jest-snapshot] Load babel, semver and synckit lazily, so requiring the package (which every test process does through @jest/expect) no longer loads ~200 modules that only writing inline snapshots needs (#​16387)
  • [jest-runtime] Reduce per-require overhead: skip module ID resolution when no mock can apply, answer core modules before probing for a manual mock, share one require.cache proxy across modules, and cache empty files (#​16376)
  • [@jest/source-map] Deprecate getCallsite in favour of SourceMapSupport#getCallsite (#​16327)
  • [jest-runtime] Avoid magical null value in ESM loader (#​16160)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.


Note

Low Risk
Dev-only dependency alignment; validate CI with yarn test after install, since Jest 30.5 changes haste-map watching and module runtime behavior.

Overview
Bumps the monorepo test stack from Jest 30.4.x to ^30.5.2 everywhere it is declared: root jest and @jest/globals, per-package jest devDependencies, and matching jest-environment-jsdom / jest-environment-node where those packages use them.

Root LavaMoat allowScripts is adjusted for the upgrade: the obsolete babel-runtime>core-js entry is removed, and jest>@jest/core>jest-haste-map>@parcel/watcher#2.6.0 is added with install scripts disabled (same pattern as other native transitive deps). No application or library source changes—only manifest/version pins (plus lockfile if present outside this diff).

Reviewed by Cursor Bugbot for commit 2d7f946. Bugbot is set up for automated code reviews on this repo. Configure here.

@metamask-ci

metamask-ci Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: yarn.lock
! Corepack is about to download https://repo.yarnpkg.com/4.17.1/packages/yarnpkg-cli/bin/yarn.js

@socket-security

socket-security Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedjest-environment-jsdom@​30.4.1 ⏵ 30.5.21001006293 +2100
Updated@​jest/​globals@​30.4.1 ⏵ 30.5.21001006395 +2100
Updatedjest-environment-node@​30.4.1 ⏵ 30.5.2100 +110067 +195 +2100
Updatedjest@​30.4.2 ⏵ 30.5.21001006995 +7100

View full report

@socket-security

socket-security Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Caution

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Potential security risk (AI signal): npm @jest/snapshot-utils is 74.0% likely risky

Notes: No clear indicators of overt malware (no network exfiltration, credential theft, or persistence) are present in this module. However, it contains a high-impact execution sink: it loads snapshot files from disk and evaluates their contents as JavaScript via new Function before header validation. If snapshot files can be tampered with, this enables arbitrary code execution in the test/Jest process, making it a significant supply-chain security risk.

Confidence: 0.74

Severity: 0.78

From: package.json → npm/@jest/globals@30.5.2 → npm/jest@30.5.2 → npm/@jest/snapshot-utils@30.5.1

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@jest/snapshot-utils@30.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Native binaries present: npm @parcel/watcher

Location: Package overview

From: package.json → npm/@jest/globals@30.5.2 → npm/jest@30.5.2 → npm/ts-jest@29.4.14 → npm/@parcel/watcher@2.6.0

ℹ Read more on: This package | This alert | Why is native code a concern?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Verify that the inclusion of native code is expected and necessary for this package's functionality. If it is unnecessary or unexpected, consider using alternative packages without native code to mitigate potential risks.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@parcel/watcher@2.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
System shell access: npm @parcel/watcher in module child_process

Module: child_process

Location: Package overview

From: package.json → npm/@jest/globals@30.5.2 → npm/jest@30.5.2 → npm/ts-jest@29.4.14 → npm/@parcel/watcher@2.6.0

ℹ Read more on: This package | This alert | What is shell access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should avoid accessing the shell which can reduce portability, and make it easier for malicious shell access to be introduced.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@parcel/watcher@2.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Install-time scripts: npm @parcel/watcher during install

Install script: install

Source: node scripts/build-from-source.js

From: package.json → npm/@jest/globals@30.5.2 → npm/jest@30.5.2 → npm/ts-jest@29.4.14 → npm/@parcel/watcher@2.6.0

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@parcel/watcher@2.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Network access: npm jest-haste-map in module node:net

Module: node:net

Location: Package overview

From: package.json → npm/@jest/globals@30.5.2 → npm/jest@30.5.2 → npm/ts-jest@29.4.14 → npm/jest-haste-map@30.5.1

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jest-haste-map@30.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Install-time scripts: npm unrs-resolver during postinstall

Install script: postinstall

Source: node postinstall.js

From: package.json → npm/jest@30.5.2 → npm/unrs-resolver@1.12.2

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/unrs-resolver@1.12.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @emnapi/core is 62.0% likely to have a medium risk anomaly

Notes: No overt data theft, network exfiltration, cryptomining, or backdoor installation is visible. However, the module includes strong dynamic execution sinks: napi_run_script uses g.eval(...) and emnapiCreateFunction uses new Function(...) to create named wrappers. These are high-risk patterns in supply-chain reviews; if the parent project exposes these APIs to untrusted input (directly or indirectly from Wasm), it could enable arbitrary code execution. The rest of the code is largely Wasm memory/handle marshaling typical of N-API glue runtimes.

Confidence: 0.62

Severity: 0.55

From: package.json → npm/jest@30.5.2 → npm/@emnapi/core@1.10.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/core@1.10.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @emnapi/core is 62.0% likely to have a medium risk anomaly

Notes: Primary concern is direct dynamic code execution. napi_run_script uses eval() on a string originating from wasm-provided input, and ee uses new Function(...) to construct wrapper functions. If the wasm module or its inputs are attacker-controlled, this provides JavaScript code execution in the host context. Aside from these dynamic execution sinks, the remaining code mainly performs wasm memory/table management and worker async orchestration typical of such runtimes, with no clear hardcoded exfiltration or backdoor behavior in this fragment.

Confidence: 0.62

Severity: 0.68

From: package.json → npm/jest@30.5.2 → npm/@emnapi/core@1.10.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/core@1.10.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @emnapi/core is 66.0% likely to have a medium risk anomaly

Notes: No explicit evidence of overt malware (network exfiltration, credential theft, backdoors, or filesystem/process activity) appears in this fragment. However, the module contains high-sensitivity dynamic execution capabilities: napi_run_script performs eval-like execution of a JavaScript string obtained from WebAssembly, and emnapiCreateFunction can use the Function constructor for wrapper generation. Combined with wasm-driven indirect callback dispatch and reflective object mutation, this runtime is security-sensitive and should only be used with fully trusted WebAssembly and tightly controlled inputs.

Confidence: 0.66

Severity: 0.66

From: package.json → npm/jest@30.5.2 → npm/@emnapi/core@1.10.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/core@1.10.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @emnapi/core is 66.0% likely to have a medium risk anomaly

Notes: This module appears to be a legitimate wasm-to-JS/Node-API bridge/runtime, but it contains high-impact dynamic execution capabilities: napi_run_script uses eval() on a string originating from the WASM/handle side, and the binding layer can generate functions via new Function(). It also performs indirect host callback invocation based on runtime handles selected by worker/work-queue control. No explicit exfiltration/backdoor behavior is visible in the provided fragment, so malware likelihood is low, but security risk is moderate-to-high due to host-context code execution if the WASM module or its inputs are not fully trusted.

Confidence: 0.66

Severity: 0.68

From: package.json → npm/jest@30.5.2 → npm/@emnapi/core@1.10.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@emnapi/core@1.10.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Environment variable access: npm @parcel/watcher

Env Vars: npm_config_build_from_source

Location: Package overview

From: package.json → npm/@jest/globals@30.5.2 → npm/jest@30.5.2 → npm/ts-jest@29.4.14 → npm/@parcel/watcher@2.6.0

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@parcel/watcher@2.6.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm @unrs/resolver-binding-wasm32-wasi is 90.0% likely to have a medium risk anomaly

Notes: This loader establishes a Node.js WASI/worker environment that: 1) passes the entire host process.env into the WASI instance (exposing all environment variables, including secrets, to loaded modules); 2) preopens the filesystem root (granting broad file read/write access under the host’s root directory); and 3) implements importScripts via synchronous fs.readFileSync + eval (allowing any local JS file to be executed in the loader context). If an untrusted or compromised WASM module or script is provided, it can read sensitive environment variables, access or modify arbitrary files, and execute arbitrary JavaScript—posing a moderate security risk. Recommended mitigations: restrict WASI preopens to a minimal directory, limit or sanitize environment variables passed into WASI, and replace or sandbox the eval-based importScripts mechanism.

Confidence: 0.90

Severity: 0.60

From: package.json → npm/jest@30.5.2 → npm/@unrs/resolver-binding-wasm32-wasi@1.12.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@unrs/resolver-binding-wasm32-wasi@1.12.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Environment variable access: npm jest-haste-map reads WATCHMAN_SOCK

Env Vars: WATCHMAN_SOCK

Location: Package overview

From: package.json → npm/@jest/globals@30.5.2 → npm/jest@30.5.2 → npm/ts-jest@29.4.14 → npm/jest-haste-map@30.5.1

ℹ Read more on: This package | This alert | What is environment variable access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should be clear about which environment variables they access, and care should be taken to ensure they only access environment variables they claim to.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jest-haste-map@30.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn
Low priority
Potential code anomaly (AI signal): npm node-addon-api is 77.0% likely to have a medium risk anomaly

Notes: The script is a legitimate formatting helper within a Node.js project. It orchestrates clang-format via git-clang-format, supports fix and diff modes, and provides actionable feedback to the developer. While operational dependencies exist, no malicious activity or data leakage is evident based on the provided code and typical usage.

Confidence: 0.77

Severity: 0.50

From: package.json → npm/@jest/globals@30.5.2 → npm/jest@30.5.2 → npm/ts-jest@29.4.14 → npm/node-addon-api@7.1.1

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/node-addon-api@7.1.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn

View full report

GuillaumeRx
GuillaumeRx previously approved these changes Sep 29, 2026
@cryptodev-2s
cryptodev-2s added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 4fce22e Sep 29, 2026
348 of 357 checks passed
@cryptodev-2s
cryptodev-2s deleted the renovate/jestjs-jest branch September 29, 2026 09:06

This branch was successfully deployed

2 active (1 outdated) deployments
dependabot — 2d7f946f Deployed Sep 29, 2026 by metamask-ci[bot] via Repair constraints, lockfile and changelogs #713
default-branch — b2fa54cb Deployed Sep 28, 2026 by metamask-ci[bot] via Determine whether this PR is a release PR #4753
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants