Repository navigation
chore(deps-dev): update jest to 30.5.2 in both packages - #4269
Draft
Ricky Gummadi (Ricky-G) wants to merge 4 commits into
Draft
Ricky Gummadi (Ricky-G) wants to merge 4 commits into
Ricky Gummadi (Ricky-G) wants to merge 4 commits into
Conversation
Preserve Dependabot #4118 scope and regenerate the reviewed public-registry lockfiles offline with scripts disabled. The SDK resolver postinstall audit requires a separate maintainer policy decision. Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found. |
📦 Dependency diff (SBOM)Comparing main → ricky-g-jest-updates. ✅ No dependency changes detected. |
Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
Signed-off-by: Microsoft Corporation <agentgovtoolkit@microsoft.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replacement for #4118: update Jest exactly
30.4.2->30.5.2in both the Copilot extension and TypeScript SDK, preserving Dependabot's public-registry lock graph. Include the required dependency audit and a deterministic deadline fixture correction. Draft, not merge-ready: the newly required SDK resolver postinstall needs a maintainer security-policy decision.Related Issue
Replacement for #4118; original stays open. Original head
8868504e4c39edf4d43cb8c77fc02083121aab7f. Shared candidate-cap fix #4151 is already merged.Problem & Solution
The original's latest failure is an install-script policy finding, not tooling capacity: run 37796334509, job 113376782101 uses
--strict --max-deps 2000, scans 123 candidates, and flags SDKunrs-resolver@1.12.2declaringpostinstall: node postinstall.js. Replacement hosted audits reproduce that finding.Jest
30.5.2requiresjest-resolve@30.5.1, which changes the resolver constraint from^1.7.11to^1.12.1. Main's SDK resolver1.11.1is incompatible, so the generated graph selects1.12.2. Both eligible1.12.1and1.12.2declare a postinstall. Copilot already contains1.12.2, but that does not establish approval.Tagged and installed source inspection confirms that the postinstall delegates to
napi-postinstall@0.3.4throughcheckAndPreparePackage(packageJson, true), which checks platform bindings and can install or download a missing binding. This script was not executed. Maintainers must review the lifecycle behavior and decide whether a separate policy change is appropriate or defer the update. No scanner, allowlist, incompatible override, feed/TLS setting, supported Node version, or production code is changed here.Human-owned lockfile changes require the dated audit added here. Initial hosted Node
20.20.2SDK testing also exposed an existing five-millisecond fixture deadline race. A controlled ten-millisecond scheduling delay reproduces the same assertion failure on baseline Jest30.4.2and updated Jest30.5.2. The fixture now uses a scoped fake clock, restores real timers, retains the original failure/open/reset/success assertions, and adds blocked execution at four milliseconds and allowed execution exactly at five milliseconds. The corrected hosted Node 20 install/build/test jobs pass in both packages.Impact on Your Work
Preserves the original two-package update with real compatibility evidence and an explicit unresolved security prerequisite instead of disguising the audit failure.
Timeline
None. Keep draft until the lifecycle-policy decision, latest-head CI and human review are complete.
Alternatives Considered
Resolver
1.11.1violates Jest's new requirement;1.12.1also publishes the script. #4151 already fixes the candidate cap. Incompatible resolutions, unreviewed exceptions, longer test sleeps and weakened assertions were rejected.Online lock-only generation through the configured mirror introduced feed-wide URLs and weaker integrity metadata; that output was discarded.
git diff --exit-code 7b7407d79b6988b54e4535bf4dee4ce6388d9a41 origin/main -- <both manifests and both lockfiles>returned 0: these four files are identical between the original merge-base and main17595e64. Reviewed original public-registry locks were then regenerated offline with npm without losing any landed lock/security changes. Final manifest/lock semantics remain identical to #4118. Offline regeneration establishes graph consistency, not provenance; hosted CI independently verified upstream hashes.Type of Change
Package(s) Affected
Core & runtime:
Governance & security:
Platform & tooling:
CLI plugins:
Shared / other:
Also affected: standalone TypeScript SDK, which has no dedicated checkbox above.
Changes
agent-governance-python/agent-os/extensions/copilot/package.json30.5.2pin; no other direct changes.agent-governance-python/agent-os/extensions/copilot/package-lock.json1.12.2retained.agent-governance-typescript/package.json30.5.2pin; no other direct changes.agent-governance-typescript/package-lock.json1.11.1->1.12.2.agent-governance-typescript/tests/metrics.test.tsdocs/dependency-audits/2026-10-08-jest-30.5.2.mdThe four original manifest/lock surfaces are preserved. Only the required audit and targeted test are additional. No application, Jest configuration, CI or MCP-server files changed.
Testing
Unit Testing
The corrected circuit-breaker fixture preserves the previous state coverage and verifies the exact four/five-millisecond execution boundary, with real-timer restoration. The same controlled ten-millisecond delay makes baseline and pre-fix updated fixtures each fail 1 of 6 tests; the corrected fixture passes all six. No production behavior was changed to make the test pass.
Both full Node
20.20.2suites pass: SDK 41 suites / 692 tests, Copilot 2 suites / 13 tests, including pretest typechecking. The corrected Node 26 metrics suite also passes six tests. SDK still emits an advisory worker-teardown warning while exiting 0; no teardown fix is claimed.Manual Testing
Windows; npm
12.0.2, Python3.14.7; initial Node26.7.0, follow-up exact hosted version Node20.20.2. Official portable Node 20 (released 2026-03-24) matched official SHA25656c1520ee33b801e8bdb92fb321cf2e98529735b6d12bd4a2a6dec0ac0bab937; process-local PATH and the existing npm CLI were used, without system configuration changes.Each command ran in both affected package directories unless noted:
npm install --package-lock-only --ignore-scripts --legacy-peer-deps --offline --no-audit --no-fundnpm ci --ignore-scripts --legacy-peer-deps --no-audit --no-fund30.4.2SDK baseline also passed with scripts disabled.npm run buildnpm test -- --runInBand --no-watchmannpm test -- --maxWorkers=2 --no-watchmannpm run lintnpm test -- --runInBand --no-watchman --runTestsByPath tests/metrics.test.tsControlled-delay command from SDK directory:
& "$artifacts\node20\node.exe" node_modules\jest\bin\jest.js --config jest.config.js --runInBand --no-watchman --runTestsByPath tests\metrics.test.ts --setupFilesAfterEnv "$artifacts\circuit-breaker-scheduler-delay.cjs"Baseline and pre-fix updated fixture each exit 1 at the same assertion; corrected fixture exits 0. The baseline is an isolated
origin/mainarchive. All installations disabled lifecycle scripts. Platform bindings worked without the flagged postinstall. Existing transitive deprecation and teardown warnings are not represented as fixed.Repository-root checks:
python scripts/check_install_scripts.py --base origin/main --strict --max-deps 2000python scripts/check_release_age.py --base origin/main --min-age-days 7python scripts/check_lockfile_integrity.py --base origin/main --max-deps 2000python scripts/check_build_hooks.py --base origin/main --strictpython scripts/check_dependency_scorecard.py --base-ref origin/main --head-ref HEAD --min-score 5.0 --max-deps 50python scripts/check_dependency_confusion.py agent-governance-typescript/package.json agent-governance-python/agent-os/extensions/copilot/package.jsonpython scripts/docs/check_links.pypython scripts/docs/check_frontmatter.pypython scripts/docs/check_frontmatter.py --strict docs/dependency-audits/2026-10-08-jest-30.5.2.mdbash scripts/ci/vendored-patch-audit.sh origin/maingit diff --checkSupplementary pre-install mirror review covered 123 changed canonical package/version identities, timestamps, repositories and scripts: all exceeded seven days; youngest approximately 8.37 days. Jest was published
2026-09-18T13:58:07Z; official 30.5.0, 30.5.1 and 30.5.2 notes were read. New lifecycle candidates are already allowlisted@parcel/watcher@2.6.0(build hook only runs when explicitly requested) and unapproved SDKunrs-resolver@1.12.2. No new script exceptions were added and no flagged script executed.Hosted evidence: corrected-code head
215fd9dd37f6b547cb07f7e8dae0954594ce8153passed actual Node 20 install/build/test steps for SDK (113588699999) and Copilot (113588700116), run37858449141. Independent hashes, cooling-off and audit-document checks also passed; the SDK fixture failure is verified resolved on supported hosted Node 20, not merely on local Node 26.Latest head
18f6c2dfb30e42979c83c652848af4fccac87eafchanges only audit spelling/evidence. Its spell-check113589726008, upstream hashes113589727630, seven-day check113589785447and Dependency Audit Trail113589727025have passed. Install-script audit113589785368remains failed for the resolver. Latest Node 20 jobs113590175555(SDK) and113590175620(Copilot) were still running at this recorded snapshot; older passes are not claimed as latest-head CI success. Additional unrelated CI remains pending.All original discussion was read with pagination: 6 comments, 0 reviews, 0 inline comments, 26 timeline events, 0 threads including resolved. No duplicate Jest replacement was open at publication.
Checklist
Attribution & Prior Art
Prior art / related projects (if any):
Credit to Dependabot for #4118. Jest: https://github.com/jestjs/jest/releases/tag/v30.5.2. Resolver: https://github.com/unrs/unrs-resolver/blob/v1.12.2/napi/postinstall.js. No new architectural pattern or external source was copied into repository code.
AI Assistance
If AI tools materially shaped this change, briefly note what was used:
GitHub Copilot assisted with the author-directed original review, dependency/lifecycle inspection, offline lock generation, baseline and compatibility checks, required audit, deterministic fixture correction and draft submission. The author explicitly confirmed the AI Assistance attestations and requested that all four be marked on their behalf. This confirmation does not attest to CLA signing, approve the resolver lifecycle script, or waive required maintainer approval before promotion or merging. No original comment/closure or merge was performed.
IP, Patents, and Licensing