Skip to content

chore(deps): bump @faker-js/faker to 10.5.0 - #21171

Open
mozilla-blender[bot] wants to merge 2 commits into
mainfrom
blender/security-bump-@faker-js/faker
Open

chore(deps): bump @faker-js/faker to 10.5.0#21171
mozilla-blender[bot] wants to merge 2 commits into
mainfrom
blender/security-bump-@faker-js/faker

Conversation

@mozilla-blender

Copy link
Copy Markdown
Contributor

Summary

Resolves a flagged transitive dependency advisory.

This is a transitive dependency update. Only yarn.lock (and possibly package.json) changed.


Created by BLEnder investigation via BLEnder

@mozilla-blender

Copy link
Copy Markdown
Contributor Author

BLEnder could not fix this PR automatically. Workflow run

@vbudhram
vbudhram requested a review from a team as a code owner September 11, 2026 19:52
mozilla-blender Bot and others added 2 commits September 11, 2026 16:05
Because:
 - @faker-js/faker 10 is ESM-only, so jest's CJS runtime throws
   "Cannot use import statement outside a module" in 30 projects.
 - GHSA-qxc2-j82w-r537 is patched only in 10.5.0, so 9.x is not an option.

This commit:
 - Adds the faker exception to transformIgnorePatterns in jest.preset.js.
 - Adds it to the three configs that override the preset value.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@vbudhram
vbudhram force-pushed the blender/security-bump-@faker-js/faker branch from f201534 to 338bcc8 Compare September 11, 2026 20:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant