Skip to content

Use ts-jest@25.5.1 - #264

Merged
whymarrh merged 1 commit into
developfrom
update-ts-jest
Sep 8, 2020
Merged

whymarrh merged 1 commit into
developfrom
update-ts-jest

Conversation

@whymarrh

@whymarrh whymarrh commented Sep 7, 2020

Copy link
Copy Markdown
Contributor

This PR updates ts-jest to address a security advisory with yargs-parser.

See https://www.npmjs.com/advisories/1500 for more information.

The yarn audit output:

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ low           │ Prototype Pollution                                          │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ yargs-parser                                                 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2             │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ ts-jest                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ ts-jest > yargs-parser                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://www.npmjs.com/advisories/1500                        │
└───────────────┴──────────────────────────────────────────────────────────────┘

@whymarrh
whymarrh requested a review from a team as a code owner September 7, 2020 14:46

@Gudahtt Gudahtt left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@whymarrh
whymarrh merged commit b97abbf into develop Sep 8, 2020
@whymarrh
whymarrh deleted the update-ts-jest branch September 8, 2020 17:16
Naz-Ovh pushed a commit to 0x-fork/metamask-core that referenced this pull request Sep 13, 2026
The addition of `web3` as a development dependency in
8aaca96 broke `yarn build:docs`, which
generates API docs via TypeDoc and is run when a new version of the
package is published. Curiously, `yarn build` continues to work.

It seems that TypeDoc is using the development variant of the TypeScript
configuration file instead of the build variant, which `yarn build` uses
internally. The build variant limits the scope of TypeScript to just
files within `src`, hiding dependencies. Correcting the TypeDoc config
to use this file fixes the issue.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants