chore: Update `ts-jest`
Explanation
Update ts-jest to resolve peer dependency warning about the version of typescript we're using being too high.
The changelogs for the two breaking changes of ts-jest are here:
- 28: https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md#2800-2022-05-02
- 29: https://github.com/kulshekhar/ts-jest/blob/main/CHANGELOG.md#2900-2022-09-08
None of the breaking changes seem to impact us.
References
N/A
Checklist
- [x] I've updated the test suite for new or updated code as appropriate
- [x] I've updated documentation (JSDoc, Markdown, etc.) for new or updated code as appropriate
- [x] I've communicated my changes to consumers by updating changelogs for packages I've changed, highlighting breaking changes as necessary
- [x] I've prepared draft pull requests for clients and consumer packages to resolve any breaking changes
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
| Diff | Package | Supply Chain Security |
Vulnerability | Quality | Maintenance | License |
|---|---|---|---|---|---|---|
| jest-environment-jsdom@27.5.1 ⏵ 28.1.3 | ||||||
| jest-environment-node@27.5.1 ⏵ 29.7.0 | ||||||
| jest@27.5.1 ⏵ 28.1.3 | ||||||
| @types/jest@27.5.2 ⏵ 28.1.8 | ||||||
| ts-jest@27.1.5 ⏵ 28.0.8 |
[!WARNING] MetaMask internal reviewing guidelines:
- Do not ignore-all
- Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
- Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
@SocketSecurity ignore npm/PACKAGE@VERSION
| Action | Severity | Alert (click "▶" to expand/collapse) |
|---|---|---|
| Warn | Potential code anomaly (AI signal): npm
|
Ignoring alerts on:
@SocketSecurity ignore npm/[email protected]
"new author" from 3 years ago is not a concern. Also this is a well known maintainer