Skip to content

[Snyk] Fix for 1 vulnerabilities - #4133

Open
trajan0x wants to merge 1 commit into
masterfrom
snyk-fix-ea3bce2a9808dc8114e656f5793bc26a
Open

trajan0x wants to merge 1 commit into
masterfrom
snyk-fix-ea3bce2a9808dc8114e656f5793bc26a

Conversation

@trajan0x

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the yarn dependencies of this project.

Snyk changed the following file(s):

  • packages/sdk-router/package.json

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

⚠️ Warning
Failed to update the yarn.lock, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue
high severity Uncontrolled Recursion
SNYK-JS-BRACES-19963945

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled Recursion

@trajan0x

Copy link
Copy Markdown
Contributor Author

Merge Risk: High

This upgrade involves multiple major versions for both jest and babel-jest and introduces significant breaking changes that will require code and configuration updates.

Key Breaking Changes

1. babel-jest from 25.5.1 to 30.3.0:
This is a very large version jump, inheriting all breaking changes from Jest v26 through v30. The most critical changes occurred in Jest v28, which introduced foundational shifts in module resolution and configuration.

  • Jest v28 Changes: Dropped support for Node.js 10 and 15. Configuration options were renamed (e.g., testURL removed, timers became fakeTimers). toHaveProperty behavior was changed to check for existence rather than equality. Full support for package.json exports was added, which can alter module resolution and break tests for packages like uuid or nanoid.
  • Jest v27 Changes: The default test environment was changed from jsdom to node. Stricter rules were enforced for async tests using done callbacks. The modern fake timers implementation became the default.
  • Jest v26 Changes: Dropped support for Node.js 8. resetMocks default was changed to true.

2. jest from 29.7.0 to 30.3.0:
This major upgrade also contains notable breaking changes.

  • Node.js Support: Drops support for Node.js versions 14, 16, 19, and 21. The minimum required version is now 18.
  • Matcher Aliases Removed: Deprecated matcher aliases like toBeCalled() have been removed. You must now use their canonical names, such as toHaveBeenCalled().
  • JSDOM Upgrade: jest-environment-jsdom was upgraded, which may introduce behavioral changes. For example, mocking window.location may no longer work as before.
  • TypeScript: The minimum required TypeScript version is now 5.4.

Recommendation:
This upgrade is high-risk and will likely require significant effort. It is strongly recommended to follow the official migration guides for each major version jump (v26, v27, v28, v29, and v30) to address the breaking changes incrementally. Pay close attention to configuration renames, Node.js version requirements, and changes in matcher behavior. After upgrading, a full test run is essential to identify and fix any resulting failures.

Sources:

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Deploying sanguine-fe with  Cloudflare Pages  Cloudflare Pages

Latest commit: 1ad7561
Status: ✅  Deploy successful!
Preview URL: https://374f6188.sanguine-fe.pages.dev
Branch Preview URL: https://snyk-fix-ea3bce2a9808dc8114e.sanguine-fe.pages.dev

View logs

@vercel

vercel Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
sanguine Error Error Sep 21, 2026 2:26pm UTC

@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Ignore keyword(s) in the title.

⛔ Ignored keywords (2)
  • WIP
  • DO NOT MERGE

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: synapsecns/sanguine/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 53bc8dae-bec7-4b20-9377-8948d929cfbe

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

This PR is stale because it has been open 14 days with no activity. Remove stale label or comment or this will be closed in 5 days.

@github-actions github-actions Bot added the Stale label Oct 6, 2026

This branch had an error being deployed

1 failed deployment
Preview — 1ad75618 Deployed Sep 21, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants