Skip to content

[CSR-0] chore: Bump typescript from 5.9.3 to 7.0.2 in /packages/jest - #417

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/jest/typescript-7.0.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/jest/typescript-7.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Bumps typescript from 5.9.3 to 7.0.2.

Release notes

Sourced from typescript's releases.

TypeScript 7.0.2

https://devblogs.microsoft.com/typescript/announcing-typescript-7-0/

This tag was originally released at: https://github.com/microsoft/typescript-go/releases/tag/typescript%2Fv7.0.2

TypeScript 6.0.3

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0.1 RC

For release notes, check out the release announcement blog post.

Downloads are available on:

TypeScript 6.0 Beta

For release notes, check out the release announcement.

Downloads are available on:

Commits
  • 1e4744d Merge branch 'main' into ts7-release
  • a5a219cmicrosoft/typescript-go#4558
  • ecfe30d Update status localization
  • 5de25b5 Hide executable name in TypeScript status
  • d7ce74a Show bundled TypeScript version for packaged servers
  • 29be66a Correct TS 7 release version to 7.0.2
  • ed2bd1b Merge branch 'main' into ts7-release
  • 8873075 Bump the github-actions group across 1 directory with 3 updates (microsoft/ty...
  • 9427131 Set up stable / nightly extension split, other prep (microsoft/typescript-go#...
  • d4eaca5microsoft/typescript-go#4549
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by microsoft1es, a new releaser for typescript since your current version.


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [typescript](https://github.com/microsoft/TypeScript) from 5.9.3 to 7.0.2.
- [Release notes](https://github.com/microsoft/TypeScript/releases)
- [Commits](microsoft/TypeScript@v5.9.3...v7.0.2)

---
updated-dependencies:
- dependency-name: typescript
  dependency-version: 7.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Assignees

The following users could not be added as assignees: ynahmany. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Please fix the above issues or remove invalid values from dependabot.yml.

Copy link
Copy Markdown
Contributor

Security dependency triage — Tier B, needs a decision. Not auto-mergeable.

What and why. typescript ^5.9.3 → ^7.0.2 in packages/jest (devDependencies). Closes no Vanta finding and no advisory — npm audit --package-lock-only on main (99d37d4) reports only @humanfs/node, @vitest/mocker, vitest and esbuild. Routine major bump, not a security fix.

Exposure. development. Declared only by packages/jest; the compiler shapes the published @currents/jest output but ships no runtime code itself.

The fix. One file changed: packages/jest/package.json. package-lock.json is not touched.

Breaking-change check. Major bump, so Tier B by rule. The concrete blocker is a peer-dependency conflict, not a subtle behaviour change.

Verification. Reproduced locally against head e65f6f5:

$ npm ci --dry-run
npm error code ERESOLVE
npm error While resolving: ts-jest@29.4.12
npm error Found: typescript@7.0.2
npm error   dev typescript@"^7.0.2" from @currents/jest@1.3.2
npm error Could not resolve dependency:
npm error peer typescript@">=4.3 <7" from ts-jest@29.4.12

Control — the same command on main (99d37d4) completes successfully.

ts-jest@29.4.12 caps its peer at typescript <7, so typescript 7 and the pinned ts-jest cannot both be installed. This is the Tier B "new peer-dependency warnings versus a baseline install" criterion in its hard form: not a warning, a resolution failure.

CI coverage. All workflows run npm ci and none is paths-filtered, so all trigger here. On e65f6f5 the checks are red — lint, Unit Tests, jest Types, typecheck-status (run 33400003636). Root-caused above, not a flake.

What a human should still check.

  1. ts-jest has to move to a release whose peer range admits typescript 7 before this can land; that is the ordering decision, and it is not in this PR.
  2. Decide [CSR-0] chore: Bump typescript from 5.9.3 to 7.0.2 #414 (root), [CSR-0] chore: Bump typescript from 5.9.3 to 7.0.2 in /packages/cmd #416 (packages/cmd) and this one together — three separate PRs move the same compiler piecemeal, and the lockfile is regenerated by only one of them ([CSR-0] chore: Bump typescript from 5.9.3 to 7.0.2 #414).
  3. Once ts-jest is sorted, the lockfile here still needs regenerating; this diff is manifest-only.

Needs release. No.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants