Skip to content

build(deps-dev): Bump jsdom from 30.0.0 to 30.0.1 - #645

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/jsdom-30.0.1
Closed

build(deps-dev): Bump jsdom from 30.0.0 to 30.0.1#645
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/jsdom-30.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps jsdom from 30.0.0 to 30.0.1.

Release notes

Sourced from jsdom's releases.

v30.0.1

  • Fixed getComputedStyle() with calc() and other functions throwing an exception, which regressed in v30.0.0. (@​asamuzaK)
  • Sped up up range operations on large documents (@​leonidaz)
Commits
  • 6584485 30.0.1
  • 0c51df6 Update dependencies and dev dependencies
  • 32adb34 Bump @​asamuzakjp/dom-selector
  • 70f014a Speed up range operations on large documents
  • 250d7ee Partially fix getComputedStyle with calc()
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jsdom](https://github.com/jsdom/jsdom) from 30.0.0 to 30.0.1.
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v30.0.0...v30.0.1)

---
updated-dependencies:
- dependency-name: jsdom
  dependency-version: 30.0.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 3, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedjsdom@​30.0.0 ⏵ 30.0.185 +5100100 +196 +7100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm jsdom is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/jsdom@30.0.1

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/jsdom@30.0.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

NiveditJain added a commit that referenced this pull request Aug 4, 2026
The Supply Chain (OSV-Scanner) gate was red on every open PR, including
all nine Dependabot bumps, on a finding none of them introduced: five
undici advisories published after main's last green scan. undici is
transitive under the jsdom test environment and already pinned via
`overrides` from the previous round of this same fix (#446), so the
repair is a one-line bump of that pin to 7.29.0.

With the shared blocker gone, the nine bumps are folded in here rather
than merged one at a time:

  #641 actions/download-artifact  4      -> 8
  #642 docker/login-action        4.5.1  -> 4.6.0
  #643 actions/upload-artifact    4      -> 7
  #644 posthog-node               5.46.1 -> 5.47.7
  #645 jsdom                      30.0.0 -> 30.0.1
  #646 @tanstack/react-virtual    3.14.8 -> 3.14.9
  #647 lucide-react               1.27.0 -> 1.28.0
  #648 @types/node                26.1.1 -> 26.1.2
  #649 @vitejs/plugin-react       6.0.3  -> 6.0.5

The two artifact actions are major bumps and have to land together,
because build-daemon.yml uploads the failproofaid-* binaries that
publish.yml downloads. Every input in use was checked against each
target's action.yml rather than assumed: name/path/if-no-files-found
and pattern/path/merge-multiple all survive, and the new `archive`
input defaults to true so the zip round trip is unchanged.
translate-docs.yml was already on v7/v8, so this leaves the repo on
one major instead of straddling two.

Verified with CI's own scanner image (osv-scanner-action:v2.3.8)
against the updated lockfile: No issues found, exit 0, with
osv-scanner.toml still holding zero ignored vulnerabilities.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013zdtoUrNwGKm7ZYpQTdBZy
@NiveditJain

Copy link
Copy Markdown
Member

Superseded by #650, which lands this bump along with the other eight open Dependabot PRs (#641#649).

This PR's CI was red only on the Supply Chain (OSV-Scanner) gate, and on a finding it did not introduce: five advisories against undici@7.28.0 that published after main's last green scan, so every open PR went red at once. #650 clears that by bumping the existing undici overrides pin to 7.29.0, then folds in all nine bumps together.

Verified there: CI's own scanner image reports No issues found / exit 0 against the updated lockfile, osv-scanner.toml still holds zero ignored vulnerabilities, and the full suite (lint, tsc, unit, build, e2e) is green.

Closing in favour of #650 — no change is lost.

@NiveditJain NiveditJain closed this Aug 4, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/bun/jsdom-30.0.1 branch August 4, 2026 06:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant