Skip to content

chore(deps): update dependency ts-jest to ^29.4.12 - #10328

Merged
cryptodev-2s merged 1 commit into
mainfrom
renovate/ts-jest-29.x
Sep 22, 2026
Merged

cryptodev-2s merged 1 commit into
mainfrom
renovate/ts-jest-29.x

Conversation

@metamask-ci

@metamask-ci metamask-ci Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
ts-jest (source) ^29.4.11 → ^29.4.12 age confidence

Release Notes

kulshekhar/ts-jest (ts-jest)

v29.4.12

Compare Source

Features
  • compiler: support TypeScript 7 projects through compatibility aliases (#​5386)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.


Note

Low Risk
Patch-level devDependency update with no runtime or config changes; risk is limited to Jest/TypeScript test compilation behavior.

Overview
This PR bumps the devDependency ts-jest from ^29.4.11 to ^29.4.12 on the root package.json, every workspace package that lists it, and yarn.lock (including ts-jest’s own semver range).

There are no changes to Jest configs or application code—only version pins. 29.4.12 adds compiler support for TypeScript 7 via compatibility aliases, which aligns with packages already using @typescript/native / TS 7 tooling while builds still use @typescript/typescript6 for compilation.

Reviewed by Cursor Bugbot for commit 5e04b85. Bugbot is set up for automated code reviews on this repo. Configure here.

@metamask-ci
metamask-ci Bot requested review from a team as code owners September 21, 2026 18:22
@metamask-ci
metamask-ci Bot requested review from a team as code owners September 21, 2026 18:22
@metamask-ci
metamask-ci Bot deployed to default-branch September 21, 2026 18:22 Active
@socket-security

socket-security Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedts-jest@​29.4.11 ⏵ 29.4.1297 +110095 +192100

View full report

@socket-security

socket-security Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Warning

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Warn Low
Potential code anomaly (AI signal): npm ts-jest is 60.0% likely to have a medium risk anomaly

Notes: No clear evidence of malware (e.g., network exfiltration, command execution, or credential theft) is present in this fragment. However, it implements a high-impact extensibility mechanism: it dynamically imports and executes a hook module specified by the TS_JEST_HOOKS environment variable and passes it full source code and transformer configuration. If the environment variable or hook file can be influenced by an attacker (common in compromised CI/dev environments), this becomes an arbitrary code execution vector during Jest/ts-jest transformation. Additionally, cache-key material and logs may expose sensitive project data if cache/log artifacts are accessible.

Confidence: 0.60

Severity: 0.55

From: packages/messenger/package.json → npm/ts-jest@29.4.12

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ts-jest@29.4.12. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

cryptodev-2s
cryptodev-2s previously approved these changes Sep 22, 2026
@cryptodev-2s
cryptodev-2s added this pull request to the merge queue Sep 22, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 22, 2026
@cryptodev-2s
cryptodev-2s added this pull request to the merge queue Sep 22, 2026
Merged via the queue into main with commit 7f9de38 Sep 22, 2026
344 of 350 checks passed
@cryptodev-2s
cryptodev-2s deleted the renovate/ts-jest-29.x branch September 22, 2026 17:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant