Skip to content

chore(deps-dev): update jest to 30.5.2 in both packages - #4269

Draft
Ricky Gummadi (Ricky-G) wants to merge 4 commits into
mainfrom
ricky-g-jest-updates
Draft

Ricky Gummadi (Ricky-G) wants to merge 4 commits into
mainfrom
ricky-g-jest-updates

Conversation

@Ricky-G

@Ricky-G Ricky Gummadi (Ricky-G) commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Replacement for #4118: update Jest exactly 30.4.2 -> 30.5.2 in both the Copilot extension and TypeScript SDK, preserving Dependabot's public-registry lock graph. Include the required dependency audit and a deterministic deadline fixture correction. Draft, not merge-ready: the newly required SDK resolver postinstall needs a maintainer security-policy decision.

Related Issue

Replacement for #4118; original stays open. Original head 8868504e4c39edf4d43cb8c77fc02083121aab7f. Shared candidate-cap fix #4151 is already merged.

If no related issue is linked above, you must complete "Problem & Solution", "Impact on Your Work", and "Alternatives Considered" below.

Problem & Solution

The original's latest failure is an install-script policy finding, not tooling capacity: run 37796334509, job 113376782101 uses --strict --max-deps 2000, scans 123 candidates, and flags SDK unrs-resolver@1.12.2 declaring postinstall: node postinstall.js. Replacement hosted audits reproduce that finding.

Jest 30.5.2 requires jest-resolve@30.5.1, which changes the resolver constraint from ^1.7.11 to ^1.12.1. Main's SDK resolver 1.11.1 is incompatible, so the generated graph selects 1.12.2. Both eligible 1.12.1 and 1.12.2 declare a postinstall. Copilot already contains 1.12.2, but that does not establish approval.

Tagged and installed source inspection confirms that the postinstall delegates to napi-postinstall@0.3.4 through checkAndPreparePackage(packageJson, true), which checks platform bindings and can install or download a missing binding. This script was not executed. Maintainers must review the lifecycle behavior and decide whether a separate policy change is appropriate or defer the update. No scanner, allowlist, incompatible override, feed/TLS setting, supported Node version, or production code is changed here.

Human-owned lockfile changes require the dated audit added here. Initial hosted Node 20.20.2 SDK testing also exposed an existing five-millisecond fixture deadline race. A controlled ten-millisecond scheduling delay reproduces the same assertion failure on baseline Jest 30.4.2 and updated Jest 30.5.2. The fixture now uses a scoped fake clock, restores real timers, retains the original failure/open/reset/success assertions, and adds blocked execution at four milliseconds and allowed execution exactly at five milliseconds. The corrected hosted Node 20 install/build/test jobs pass in both packages.

Impact on Your Work

Preserves the original two-package update with real compatibility evidence and an explicit unresolved security prerequisite instead of disguising the audit failure.

Timeline

None. Keep draft until the lifecycle-policy decision, latest-head CI and human review are complete.

Alternatives Considered

Resolver 1.11.1 violates Jest's new requirement; 1.12.1 also publishes the script. #4151 already fixes the candidate cap. Incompatible resolutions, unreviewed exceptions, longer test sleeps and weakened assertions were rejected.

Online lock-only generation through the configured mirror introduced feed-wide URLs and weaker integrity metadata; that output was discarded. git diff --exit-code 7b7407d79b6988b54e4535bf4dee4ce6388d9a41 origin/main -- <both manifests and both lockfiles> returned 0: these four files are identical between the original merge-base and main 17595e64. Reviewed original public-registry locks were then regenerated offline with npm without losing any landed lock/security changes. Final manifest/lock semantics remain identical to #4118. Offline regeneration establishes graph consistency, not provenance; hosted CI independently verified upstream hashes.

Type of Change

  • Bug fix (non-breaking change that fixes an issue)
  • New feature (non-breaking change that adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Documentation update
  • Maintenance (dependency updates, CI/CD, refactoring)
  • Security fix

Package(s) Affected

Core & runtime:

  • agent-governance-toolkit-core
  • agent-primitives
  • agent-os
  • agent-mesh
  • agent-runtime
  • agent-sre
  • agent-compliance

Governance & security:

  • agent-mcp-governance
  • agent-rag-governance
  • agent-sandbox
  • agent-discovery
  • agt-policies
  • policy-engine

Platform & tooling:

  • agent-hypervisor
  • agent-lightning
  • agent-marketplace
  • agent-governance-toolkit-cli
  • agent-governance-toolkit-integrations
  • agent-governance-toolkit-protocols
  • agentmesh-integrations (framework integrations)

CLI plugins:

  • agent-governance CLI plugins (copilot-cli / claude-code / opencode / antigravity-cli)

Shared / other:

  • schemas
  • action (GitHub Action)
  • examples
  • docs / root

Also affected: standalone TypeScript SDK, which has no dedicated checkbox above.

Changes

File Change
agent-governance-python/agent-os/extensions/copilot/package.json Exact Jest 30.5.2 pin; no other direct changes.
agent-governance-python/agent-os/extensions/copilot/package-lock.json Regenerated public-registry graph; existing resolver 1.12.2 retained.
agent-governance-typescript/package.json Exact Jest 30.5.2 pin; no other direct changes.
agent-governance-typescript/package-lock.json Regenerated graph including mandatory resolver 1.11.1 -> 1.12.2.
agent-governance-typescript/tests/metrics.test.ts Controlled deadline clock and exact-boundary assertions.
docs/dependency-audits/2026-10-08-jest-30.5.2.md Required audit, policy blocker, baseline comparison and hosted evidence; document-local spelling of the upstream proper name.

The four original manifest/lock surfaces are preserved. Only the required audit and targeted test are additional. No application, Jest configuration, CI or MCP-server files changed.

Testing

Unit Testing

The corrected circuit-breaker fixture preserves the previous state coverage and verifies the exact four/five-millisecond execution boundary, with real-timer restoration. The same controlled ten-millisecond delay makes baseline and pre-fix updated fixtures each fail 1 of 6 tests; the corrected fixture passes all six. No production behavior was changed to make the test pass.

Both full Node 20.20.2 suites pass: SDK 41 suites / 692 tests, Copilot 2 suites / 13 tests, including pretest typechecking. The corrected Node 26 metrics suite also passes six tests. SDK still emits an advisory worker-teardown warning while exiting 0; no teardown fix is claimed.

Manual Testing

Windows; npm 12.0.2, Python 3.14.7; initial Node 26.7.0, follow-up exact hosted version Node 20.20.2. Official portable Node 20 (released 2026-03-24) matched official SHA256 56c1520ee33b801e8bdb92fb321cf2e98529735b6d12bd4a2a6dec0ac0bab937; process-local PATH and the existing npm CLI were used, without system configuration changes.

Each command ran in both affected package directories unless noted:

Exact command Result
npm install --package-lock-only --ignore-scripts --legacy-peer-deps --offline --no-audit --no-fund Both passed, exit 0; public-registry locks unchanged after regeneration.
npm ci --ignore-scripts --legacy-peer-deps --no-audit --no-fund Both passed, exit 0; Copilot 500 packages, SDK 373. Isolated main/Jest 30.4.2 SDK baseline also passed with scripts disabled.
npm run build Both passed, exit 0 on Node 26 and Node 20.
npm test -- --runInBand --no-watchman Initial Node 26 suites passed, exit 0; SDK 692, Copilot 13 tests.
npm test -- --maxWorkers=2 --no-watchman Corrected Node 20 suites passed, exit 0; SDK 692, Copilot 13 tests.
npm run lint Both passed, exit 0 on Node 26 and Node 20.
npm test -- --runInBand --no-watchman --runTestsByPath tests/metrics.test.ts Corrected SDK Node 26 fixture passed, exit 0; six tests.

Controlled-delay command from SDK directory:

& "$artifacts\node20\node.exe" node_modules\jest\bin\jest.js --config jest.config.js --runInBand --no-watchman --runTestsByPath tests\metrics.test.ts --setupFilesAfterEnv "$artifacts\circuit-breaker-scheduler-delay.cjs"

Baseline and pre-fix updated fixture each exit 1 at the same assertion; corrected fixture exits 0. The baseline is an isolated origin/main archive. All installations disabled lifecycle scripts. Platform bindings worked without the flagged postinstall. Existing transitive deprecation and teardown warnings are not represented as fixed.

Repository-root checks:

Exact command Result
python scripts/check_install_scripts.py --base origin/main --strict --max-deps 2000 Local failed, exit 1: 122 of 123 candidates unverifiable due to canonical-registry TLS; one existing watcher skip, none unscanned. Hosted audit independently flags resolver postinstall.
python scripts/check_release_age.py --base origin/main --min-age-days 7 Local failed, exit 1 on canonical-registry TLS; hosted replacement checks passed.
python scripts/check_lockfile_integrity.py --base origin/main --max-deps 2000 Local failed, exit 1: 203 entries unverifiable due to canonical-registry TLS; hosted replacement checks passed.
python scripts/check_build_hooks.py --base origin/main --strict Passed, exit 0; no added/modified hooks.
python scripts/check_dependency_scorecard.py --base-ref origin/main --head-ref HEAD --min-score 5.0 --max-deps 50 Passed, exit 0; no new direct names.
python scripts/check_dependency_confusion.py agent-governance-typescript/package.json agent-governance-python/agent-os/extensions/copilot/package.json Passed, exit 0.
python scripts/docs/check_links.py Passed, exit 0; 307 files, 2,852 links, no new broken links.
python scripts/docs/check_frontmatter.py Passed, exit 0; 294 files, no findings.
python scripts/docs/check_frontmatter.py --strict docs/dependency-audits/2026-10-08-jest-30.5.2.md Passed, exit 0.
bash scripts/ci/vendored-patch-audit.sh origin/main Passed, exit 0 with required audit.
git diff --check Passed, exit 0.

Supplementary pre-install mirror review covered 123 changed canonical package/version identities, timestamps, repositories and scripts: all exceeded seven days; youngest approximately 8.37 days. Jest was published 2026-09-18T13:58:07Z; official 30.5.0, 30.5.1 and 30.5.2 notes were read. New lifecycle candidates are already allowlisted @parcel/watcher@2.6.0 (build hook only runs when explicitly requested) and unapproved SDK unrs-resolver@1.12.2. No new script exceptions were added and no flagged script executed.

Hosted evidence: corrected-code head 215fd9dd37f6b547cb07f7e8dae0954594ce8153 passed actual Node 20 install/build/test steps for SDK (113588699999) and Copilot (113588700116), run 37858449141. Independent hashes, cooling-off and audit-document checks also passed; the SDK fixture failure is verified resolved on supported hosted Node 20, not merely on local Node 26.

Latest head 18f6c2dfb30e42979c83c652848af4fccac87eaf changes only audit spelling/evidence. Its spell-check 113589726008, upstream hashes 113589727630, seven-day check 113589785447 and Dependency Audit Trail 113589727025 have passed. Install-script audit 113589785368 remains failed for the resolver. Latest Node 20 jobs 113590175555 (SDK) and 113590175620 (Copilot) were still running at this recorded snapshot; older passes are not claimed as latest-head CI success. Additional unrelated CI remains pending.

All original discussion was read with pagination: 6 comments, 0 reviews, 0 inline comments, 26 timeline events, 0 threads including resolved. No duplicate Jest replacement was open at publication.

Checklist

  • I have linked a related issue above, or completed "Problem & Solution", "Impact on Your Work", and "Alternatives Considered"
  • My code follows the project style guidelines (ruff check)
  • I have added tests that prove my fix/feature works
  • All new and existing tests pass (pytest)
  • I have updated documentation as needed
  • I have signed the Microsoft CLA

Attribution & Prior Art

  • This contribution does not contain code copied or derived from other projects without attribution
  • Any external projects that inspired this design are credited in code comments or documentation
  • If this PR implements functionality similar to an existing open-source project, I have listed it below

Prior art / related projects (if any):

Credit to Dependabot for #4118. Jest: https://github.com/jestjs/jest/releases/tag/v30.5.2. Resolver: https://github.com/unrs/unrs-resolver/blob/v1.12.2/napi/postinstall.js. No new architectural pattern or external source was copied into repository code.

AI Assistance

  • I can explain every meaningful change in this PR: what it does, why, and what tradeoffs were considered
  • I have run tests and verification appropriate for this change
  • No part of this PR was autonomously submitted by an AI agent without my review
  • I have not used AI to generate review comments on others' PRs

If AI tools materially shaped this change, briefly note what was used:

GitHub Copilot assisted with the author-directed original review, dependency/lifecycle inspection, offline lock generation, baseline and compatibility checks, required audit, deterministic fixture correction and draft submission. The author explicitly confirmed the AI Assistance attestations and requested that all four be marked on their behalf. This confirmation does not attest to CLA signing, approve the resolver lifecycle script, or waive required maintainer approval before promotion or merging. No original comment/closure or merge was performed.

IP, Patents, and Licensing

  • This contribution does not implement patent-pending or patent-encumbered techniques
  • This contribution does not require an NDA or licensing agreement to understand or use
  • Any AI tools used have terms compatible with the MIT License

Preserve Dependabot #4118 scope and regenerate the reviewed public-registry lockfiles offline with scripts disabled. The SDK resolver postinstall audit requires a separate maintainer policy decision.

Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

PR Review Summary

Check Status Details
🔍 Code Review ⚠️ Missing No current-run comment
🛡️ Security Scan ⚠️ Missing No current-run comment
🔄 Breaking Changes ⚠️ Missing No current-run comment
📝 Docs Sync ⚠️ Missing No current-run comment
🧪 Test Coverage ⚠️ Missing No current-run comment

Verdict: ⚠️ AI review incomplete; ready for human review

AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

@github-actions github-actions Bot added the size/XL Extra large PR (500+ lines) label Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

📦 Dependency diff (SBOM)

Comparing main → ricky-g-jest-updates.

✅ No dependency changes detected.

Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
@github-actions github-actions Bot added the documentation Improvements or additions to documentation label Oct 8, 2026
Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
@github-actions github-actions Bot added the tests label Oct 8, 2026
Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation size/XL Extra large PR (500+ lines) tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant