Skip to content

[DT-4196] Upgrade to jsdom 30.1.1 and Vitest 5.0.3, drop the Dependabot jsdom ignore - #3986

Merged
kevinmarete merged 2 commits into
developfrom
km-dt-4196-jsdom-30-1
Oct 2, 2026
Merged

kevinmarete merged 2 commits into
developfrom
km-dt-4196-jsdom-30-1

Conversation

@kevinmarete

Copy link
Copy Markdown
Contributor

Addresses

https://broadworkbench.atlassian.net/browse/DT-4196

Security risk: no — test-only dependency upgrade; jsdom and Vitest are dev dependencies and nothing in the shipped bundle changes.

Summary

Unpins jsdom so Dependabot can keep it current. jsdom goes to 30.1.1 and the jsdom ignore in .github/dependabot.yml is removed.

The ticket was waiting on vitest-dev/vitest#11295, but that alone wasn't enough: develop already has it (Vitest 5.0.2), and the EditDac DAA upload tests still failed. jsdom 30.1 no longer exposes a Blob's impl through an own Symbol, so the shim found no impl at all. vitest-dev/vitest#11379 fixes that and ships in 5.0.3, so vitest and @vitest/* move to 5.0.3 in both the root and server workspaces.

jsdom now reports computed font-weight numerically per spec, so four assertions change from normal/bold to 400/700. The negative not.toHaveStyle({ fontWeight: 'bold' }) in CloseoutReview becomes a positive 400 check, since the negative form would pass vacuously.

No Blob-shim workaround and no focus/FocusTrap mocks. Root (4937), browser (15) and server (705) suites pass locally; flipping each changed expectation makes its test fail.


Have you read Terra's Contributing Guide lately? If not, do that first.

  • Label PR with a Jira ticket number and include a link to the ticket
  • Label PR with a security risk modifier [no, low, medium, high]
  • PR describes scope of changes
  • Get a minimum of one thumbs worth of review, preferably two if enough team members are available
  • Get PO sign-off for all non-trivial UI or workflow changes
  • Verify all tests go green
  • Test this change deployed correctly and works on dev environment after deployment

🤖 Generated with Claude Code

kevinmarete and others added 2 commits October 2, 2026 12:49
…ot jsdom ignore

Vitest 5.0.3 includes vitest-dev/vitest#11379, which restores the
URL.createObjectURL Blob shim on jsdom 30.1. jsdom now reports computed
font-weight numerically, so four assertions move from keywords to 400/700.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@kevinmarete kevinmarete self-assigned this Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Coverage Report for DUOS Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 90.75% 12666 / 13957
🔵 Statements 90.27% 13558 / 15020
🔵 Functions 87.98% 3793 / 4311
🔵 Branches 83.06% 8020 / 9656
File CoverageNo changed files found.
Generated in workflow #7495 for commit 9eeb6d4 by the Vitest Coverage Report Action

@kevinmarete
kevinmarete marked this pull request as ready for review October 2, 2026 17:00
@kevinmarete
kevinmarete requested a review from a team as a code owner October 2, 2026 17:00
@kevinmarete
kevinmarete requested review from fboulnois, otchet-broad and rushtong and removed request for a team October 2, 2026 17:00

@rushtong rushtong left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍🏽

@otchet-broad otchet-broad left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@kevinmarete
kevinmarete removed the request for review from fboulnois October 2, 2026 22:45
@kevinmarete
kevinmarete merged commit 0a5d16f into develop Oct 2, 2026
16 checks passed
@kevinmarete
kevinmarete deleted the km-dt-4196-jsdom-30-1 branch October 2, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants