Skip to content

[Snyk] Fix for 1 vulnerabilities - #345

Open
rvu-snyk wants to merge 1 commit into
masterfrom
snyk-fix-8ba7164034ee380ace8ad4bad0283aac
Open

[Snyk] Fix for 1 vulnerabilities#345
rvu-snyk wants to merge 1 commit into
masterfrom
snyk-fix-8ba7164034ee380ace8ad4bad0283aac

Conversation

@rvu-snyk

@rvu-snyk rvu-snyk commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • packages/koa-tracer/package.json
  • packages/koa-tracer/package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Allocation of Resources Without Limits or Throttling
SNYK-JS-BRACEEXPANSION-18512280
  828  

Breaking Change Risk

Merge Risk: High

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Allocation of Resources Without Limits or Throttling

…ock.json to reduce vulnerabilities

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280
@rvu-snyk

rvu-snyk commented Aug 4, 2026

Copy link
Copy Markdown
Contributor Author

Merge Risk: High

This update includes major version upgrades for both @babel/cli and jest, introducing significant breaking changes that require developer action.

@babel/cli 7.28.68.0.0 (High Risk)

Babel 8 is a major overhaul focused on modernization. Key breaking changes include:

  • ESM Only: Babel now ships as native ES Modules. This may require changes to your build and configuration files if you are using CommonJS (require()).
  • Node.js Requirement: Requires Node.js version 22 or newer. Support for older Node versions has been dropped.
  • Default Target: No longer compiles to ES5 by default. The default target is now modern browsers. You may need to configure targets in your Babel configuration if you need to support older browsers.
  • Polyfills: The corejs and useBuiltIns options have been removed from @babel/preset-env. Polyfill injection must now be handled by babel-plugin-polyfill-corejs3.
  • React JSX Runtime: The default for the React JSX transform has changed from classic to automatic.

Recommendation: Review the Babel 8 migration guide and update your configuration. Pay close attention to your project's module system (ESM/CJS), Node.js version, and browser support targets.

jest 29.7.030.0.0 (High Risk)

Jest 30 introduces several breaking changes that will likely require code and configuration updates:

  • Node.js Requirement: Drops support for Node.js 14, 16, 19, and 21. The minimum required version is now 18.
  • Matcher Aliases Removed: Deprecated matcher aliases (e.g., toBeCalled, toReturn) have been removed. You must migrate to their new names (e.g., toHaveBeenCalled, toHaveReturned).
  • JSDOM Upgrade: The jest-environment-jsdom package was upgraded, which may cause subtle behavior changes. Notably, mocking window.location is more difficult.
  • CLI Flag Renamed: The --testPathPattern flag has been renamed to --testPathPatterns.
  • Matcher Behavior Change: expect.objectContaining() no longer works with arrays; use expect.arrayContaining() instead.

Recommendation: Use a codemod like eslint-plugin-jest with its autofixer or other community codemods to automatically update the removed matcher aliases. Carefully review the official migration guide for a complete list of changes and update your test suite accordingly.

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants