Skip to content

chore(deps-dev): bump jsdom from 25.0.1 to 30.1.1 - #857

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/jsdom-30.1.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/jsdom-30.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown

Bumps jsdom from 25.0.1 to 30.1.1.

Release notes

Sourced from jsdom's releases.

v30.1.1

  • Fixed spurious window blur and focusout events and incorrect event.relatedTarget values when focusing an element after removing the previously focused element, which regressed in v30.1.0. (@​asamuzaK)
  • Fixed focus and blur behavior across frames, and focusing the document's viewport through document.documentElement.focus(). (@​asamuzaK)
  • Fixed focus targets removed or disabled by blur listeners becoming active, and text selections made by focus and blur listeners being overwritten. (@​asamuzaK)
  • Fixed element.focus() incorrectly focusing disabled form controls and <input type="hidden"> elements with tabindex="". (@​scttcper)
  • Fixed invalid style.setProperty() calls changing existing !important priorities, serialized styles, or mutation records. (@​FedgeNo)
  • Fixed !important handling when updating CSS longhands after shorthands, using variables or CSS-wide keywords, and assigning style properties directly. (@​FedgeNo)
  • Fixed <noscript> parsing with includeNodeLocations: true or inside frames to honor the runScripts option.
  • Fixed the storageQuota option being ignored by frames.
  • Fixed encoding detection of HTML and XML byte input to honor XML encoding declarations and detect UTF-16 without a byte order mark.
  • Fixed exceptions caused by truncated charset parameters in <meta> elements, and encoding detection incorrectly using incomplete <meta> tags. (@​FedgeNo)
  • Fixed XML serialization errors for namespaces named constructor, toString, __proto__, or "null", and incorrect reuse of namespace prefixes declared on sibling elements.
  • Fixed element.innerHTML and element.outerHTML in XML documents to reject invalid characters in attribute values and avoid stack overflows on large strings.
  • Fixed selector matching for :lang(), :nth-child(... of ...) after mutations, and :has() with duplicate IDs or nested logical pseudo-classes. (@​asamuzaK)

v30.1.0

jsdom is feeling the AGI!

This release is dedicated to @​scttcper, who unleashed @​codex upon jsdom and found tons of performance improvements. Along the way, he found and fixed many correctness issues as well.

We really appreciate his thoughtful PRs, which did a great job following the project's contribution guidelines, and were clearly human-curated, with their PR descriptions edited to be brief and respectful of the maintainers' time.

Thanks to @​scttcper, as well as all the other contributors of this release (most of whom were AI-assisted).

  • Added named access to elements on document, such as document.myForm for <form name="myForm">. (@​vojtisprime11)
  • Added QuotaExceededError, including its use for storage quota errors and oversized crypto.getRandomValues() requests.
  • Added support for the relaxed DOM naming rules when creating elements, attributes, and document types.
  • Improved performance of DOM construction, tree mutations, range operations, and live collection access, especially on large documents. (@​scttcper, @​erezrokah)
  • Improved performance of getComputedStyle(), style changes, and CSS serialization. (@​scttcper, @​jhult)
  • Improved performance of event dispatch, form control and label lookups, and updates to <select> elements and radio button groups. (@​scttcper)
  • Reduced memory use when creating and working with DOM nodes, attributes, event listeners, and mutation observers. (@​scttcper)
  • Changed window.close() to preserve access to the document and its DOM through retained references.
  • Fixed element.querySelectorAll() returning no matches when the first part of the selector matches the element itself, which regressed in v30.0.0. (@​asamuzaK)
  • Fixed case sensitivity in CSS attribute selectors, including selectors matching data-state="", title="", and other case-sensitive values. (@​asamuzaK)
  • Fixed document.querySelector() failing to find a matching element when an earlier element has the same ID but does not match the rest of the selector. (@​vojtisprime11)
  • Fixed :focus matching in shadow trees. (@​asamuzaK)
  • Fixed DOM insertion and replacement, including valid document.replaceChildren() calls, invalid document element and doctype placements, and mutations during element.replaceWith().
  • Fixed the ordering of script execution, custom element callbacks, iframe loading, and mutation observer notifications during DOM insertion, including in shadow trees.
  • Fixed queued events and navigation continuing after window.close() or iframe removal, and prevented new scripts, resource loads, timers, and animation frames from starting in destroyed documents. (@​scttcper)
  • Fixed parent documents waiting indefinitely for loading to finish when a child iframe removes itself during loading.
  • Fixed request cancellation across redirects, during pending requestInterceptor() callbacks, and when reusing an XMLHttpRequest after aborting it.
  • Fixed resource loading and JSDOM.fromURL() potentially hanging when response handling throws and response stream cleanup does not finish.
  • Fixed successful cached resource loads being treated as aborted.
  • Fixed getComputedStyle() and document.styleSheets using the wrong stylesheet order after inserting or updating <style> elements.
  • Fixed getComputedStyle() ignoring nested @import and @media rules in imported stylesheets, and returning stale results after imports finish loading.
  • Fixed style invalidation, stylesheet removal, and frame source updates in shadow trees.
  • Fixed repeated getComputedStyle() calls changing case-sensitive background URLs, and inconsistent resolution of border shorthands containing system colors. (@​scttcper)
  • Fixed computed border widths, including borderless elements incorrectly reporting 16px, which regressed in v30.0.0. (@​Alberto-BaseNet)
  • Fixed getComputedStyle() to resolve 'font-weight' keywords to numeric values. (@​tianrking)
  • Fixed getComputedStyle() to convert lengths to pixels inside CSS math functions containing percentages, and to resolve percentages in 'font-size' math functions. (@​soroushm)

... (truncated)

Commits
  • 0a117f4 30.1.1
  • 103f67d Remove unnecessary window cleanup from API tests
  • cdda00a Test HTTP/2 document and subresource loading
  • 7ab92ce Update @​asamuzakjp/dom-selector to v9.2.1
  • d940c20 Share jsdom settings across descendant windows
  • 6ba40cb Fix and simplify option propagation
  • 3b3be70 Preserve CSS priorities across declaration updates
  • 97b2758 Align focusing and unfocusing with HTML
  • b7b460b Update w3c-xmlserializer to v6
  • 71d562f Update html-encoding-sniffer to v7
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for jsdom since your current version.

Install script changes

This version modifies prepare script that runs during installation. Review the package contents before updating.


@dependabot @github

dependabot Bot commented on behalf of github Sep 24, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies, npm. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown

🔐 Contract Security Scan

cargo audit
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1269 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[32m    Scanning�[0m Cargo.lock for vulnerabilities (193 crate dependencies)
�[0m�[0m�[1m�[33mCrate:    �[0m paste
�[0m�[0m�[1m�[33mVersion:  �[0m 1.0.15
�[0m�[0m�[1m�[33mWarning:  �[0m unmaintained
�[0m�[0m�[1m�[33mTitle:    �[0m paste - no longer maintained
�[0m�[0m�[1m�[33mDate:     �[0m 2024-10-07
�[0m�[0m�[1m�[33mID:       �[0m RUSTSEC-2024-0436
�[0m�[0m�[1m�[33mURL:      �[0m https://rustsec.org/advisories/RUSTSEC-2024-0436

�[0m�[0m�[1m�[33mCrate:    �[0m spin
�[0m�[0m�[1m�[33mVersion:  �[0m 0.9.8
�[0m�[0m�[1m�[33mWarning:  �[0m yanked

�[0m�[0m�[1m�[33mwarning:�[0m 2 allowed warnings found
Soroban pattern check
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:407 — pub fn pause performs writes but has no require_auth()
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:423 — pub fn unpause performs writes but has no require_auth()

2 HIGH severity issue(s) found. Fix before merging.

@dependabot dependabot Bot changed the title chore(deps-dev): bump jsdom from 25.0.1 to 30.1.0 chore(deps-dev): bump jsdom from 25.0.1 to 30.1.1 Sep 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/jsdom-30.1.0 branch from 93713d5 to 0572d55 Compare September 27, 2026 11:05
@github-actions

Copy link
Copy Markdown

🔐 Contract Security Scan

cargo audit
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1271 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[32m    Scanning�[0m Cargo.lock for vulnerabilities (193 crate dependencies)
�[0m�[0m�[1m�[33mCrate:    �[0m paste
�[0m�[0m�[1m�[33mVersion:  �[0m 1.0.15
�[0m�[0m�[1m�[33mWarning:  �[0m unmaintained
�[0m�[0m�[1m�[33mTitle:    �[0m paste - no longer maintained
�[0m�[0m�[1m�[33mDate:     �[0m 2024-10-07
�[0m�[0m�[1m�[33mID:       �[0m RUSTSEC-2024-0436
�[0m�[0m�[1m�[33mURL:      �[0m https://rustsec.org/advisories/RUSTSEC-2024-0436

�[0m�[0m�[1m�[33mCrate:    �[0m spin
�[0m�[0m�[1m�[33mVersion:  �[0m 0.9.8
�[0m�[0m�[1m�[33mWarning:  �[0m yanked

�[0m�[0m�[1m�[33mwarning:�[0m 2 allowed warnings found
Soroban pattern check
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:407 — pub fn pause performs writes but has no require_auth()
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:423 — pub fn unpause performs writes but has no require_auth()

2 HIGH severity issue(s) found. Fix before merging.

Bumps [jsdom](https://github.com/jsdom/jsdom) from 25.0.1 to 30.1.1.
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Commits](jsdom/jsdom@v25.0.1...v30.1.1)

---
updated-dependencies:
- dependency-name: jsdom
  dependency-version: 30.1.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/jsdom-30.1.0 branch from 0572d55 to f56f827 Compare October 4, 2026 12:29
@dependabot
dependabot Bot deployed to staging October 4, 2026 12:29 Active
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🛡️ Frontend Security Scan

npm audit
# npm audit report

fflate  0.7.0 - 0.7.4
Severity: moderate
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives - https://github.com/advisories/GHSA-px8p-9vwx-vf98
fix available via `npm audit fix --force`
Will install @vercel/og@1.0.1, which is a breaking change
node_modules/fflate
  satori  >=0.33.0
  Depends on vulnerable versions of fflate
  node_modules/satori
    @vercel/og  >=1.0.2
    Depends on vulnerable versions of satori
    node_modules/@vercel/og

3 moderate severity vulnerabilities

To address all issues (including breaking changes), run:
  npm audit fix --force
# npm audit report

@vitest/mocker  2.1.0 - 4.1.10
Severity: moderate
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock - https://github.com/advisories/GHSA-82fw-gwwq-j7x9
fix available via `npm audit fix --force`
Will install storybook@10.6.1, which is a breaking change
node_modules/@vitest/mocker
  storybook  9.1.0-alpha.0 - 10.1.0-beta.6
  Depends on vulnerable versions of @vitest/mocker
  node_modules/storybook
    @storybook/addon-docs  <=0.0.0-pr-35259-sha-153697da || 9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of @storybook/csf-plugin
    Depends on vulnerable versions of @storybook/react-dom-shim
    Depends on vulnerable versions of storybook
    node_modules/@storybook/addon-docs
    @storybook/addon-links  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/addon-links
    @storybook/builder-webpack5  *
    Depends on vulnerable versions of @storybook/core-webpack
    Depends on vulnerable versions of fork-ts-checker-webpack-plugin
    Depends on vulnerable versions of storybook
    Depends on vulnerable versions of webpack-dev-middleware
    node_modules/@storybook/builder-webpack5
      @storybook/nextjs  *
      Depends on vulnerable versions of @storybook/builder-webpack5
      Depends on vulnerable versions of @storybook/preset-react-webpack
      Depends on vulnerable versions of @storybook/react
      Depends on vulnerable versions of node-polyfill-webpack-plugin
      Depends on vulnerable versions of storybook
      node_modules/@storybook/nextjs
    @storybook/core-webpack  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/core-webpack
    @storybook/csf-plugin  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/csf-plugin
    @storybook/preset-react-webpack  *
    Depends on vulnerable versions of @storybook/core-webpack
    Depends on vulnerable versions of @storybook/react-docgen-typescript-plugin
    Depends on vulnerable versions of storybook
    node_modules/@storybook/preset-react-webpack
    @storybook/react  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of @storybook/react-dom-shim
    Depends on vulnerable versions of storybook
    node_modules/@storybook/react
    @storybook/react-dom-shim  9.1.0-alpha.0 - 9.2.0-alpha.3
    Depends on vulnerable versions of storybook
    node_modules/@storybook/react-dom-shim

braces  *
Severity: high
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns - https://github.com/advisories/GHSA-vfj7-8cjw-p6xm
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/braces
  chokidar  2.0.0 - 3.6.0
  Depends on vulnerable versions of braces
  node_modules/chokidar
    fork-ts-checker-webpack-plugin  0.4.7 - 4.0.0-beta.5 || 6.0.0-alpha.1 - 9.0.3
    Depends on vulnerable versions of chokidar
    node_modules/fork-ts-checker-webpack-plugin
  micromatch  >=0.2.0
  Depends on vulnerable versions of braces
  node_modules/micromatch
    @storybook/react-docgen-typescript-plugin  *
    Depends on vulnerable versions of micromatch
    node_modules/@storybook/react-docgen-typescript-plugin
    fast-glob  *
    Depends on vulnerable versions of micromatch
    node_modules/@shadcn/registry/node_modules/fast-glob
    node_modules/@ts-morph/common/node_modules/fast-glob
    node_modules/fast-glob
    node_modules/shadcn/node_modules/fast-glob
      @next/eslint-plugin-next  >=14.3.0-canary.0
      Depends on vulnerable versions of fast-glob
      node_modules/@next/eslint-plugin-next
      @shadcn/registry  0.0.0-beta-20261001093212 || >=0.1.0
      Depends on vulnerable versions of fast-glob
      Depends on vulnerable versions of ts-morph
      node_modules/@shadcn/registry
        shadcn  <=0.0.0-beta-20261001093212 || >=2.0.0
        Depends on vulnerable versions of @shadcn/registry
        Depends on vulnerable versions of fast-glob
        Depends on vulnerable versions of ts-morph
        node_modules/shadcn
      @ts-morph/common  0.2.0 - 0.24.0 || 0.26.0 - 0.27.0
      Depends on vulnerable versions of fast-glob
      node_modules/@ts-morph/common
        ts-morph  6.0.1 - 23.0.0 || 25.0.0 - 26.0.0
        Depends on vulnerable versions of @ts-morph/common
        node_modules/ts-morph

elliptic  *
Elliptic Uses a Cryptographic Primitive with a Risky Implementation - https://github.com/advisories/GHSA-848j-6mx2-7j84
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/elliptic
  browserify-sign  >=2.4.0
  Depends on vulnerable versions of elliptic
  node_modules/browserify-sign
    crypto-browserify  >=3.4.0
    Depends on vulnerable versions of browserify-sign
    Depends on vulnerable versions of create-ecdh
    node_modules/crypto-browserify
      node-polyfill-webpack-plugin  <=4.0.0
      Depends on vulnerable versions of crypto-browserify
      node_modules/node-polyfill-webpack-plugin
  create-ecdh  *
  Depends on vulnerable versions of elliptic
  node_modules/create-ecdh

fflate  0.7.0 - 0.7.4
Severity: moderate
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives - https://github.com/advisories/GHSA-px8p-9vwx-vf98
fix available via `npm audit fix --force`
Will install @vercel/og@1.0.1, which is a breaking change
node_modules/fflate
  satori  >=0.33.0
  Depends on vulnerable versions of fflate
  node_modules/satori
    @vercel/og  >=1.0.2
    Depends on vulnerable versions of satori
    node_modules/@vercel/og

webpack-dev-middleware  <7.4.5
Severity: high
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath - https://github.com/advisories/GHSA-g84c-rxfj-3j2c
fix available via `npm audit fix --force`
Will install @storybook/nextjs@10.6.1, which is a breaking change
node_modules/webpack-dev-middleware

31 vulnerabilities (5 low, 11 moderate, 15 high)

To address issues that do not require attention, run:
  npm audit fix

To address all issues (including breaking changes), run:
  npm audit fix --force
ESLint
> flowstar@0.1.0 lint
> eslint .


/home/runner/work/FlowStar/FlowStar/next.config.mjs
  15:5  warning  Unexpected console statement  no-console

/home/runner/work/FlowStar/FlowStar/scripts/check-secrets.mjs
  28:23  warning  Found readdirSync from package "fs" with non literal argument at index 0   security/detect-non-literal-fs-filename
  31:16  warning  Found statSync from package "fs" with non literal argument at index 0      security/detect-non-literal-fs-filename
  47:15  warning  Found readFileSync from package "fs" with non literal argument at index 0  security/detect-non-literal-fs-filename
  52:9   warning  Unexpected console statement                                               no-console
  60:3   warning  Unexpected console statement                                               no-console
  63:3   warning  Unexpected console statement                                               no-console

/home/runner/work/FlowStar/FlowStar/scripts/soroban-security-check.mjs
   14:23  warning  Found readdirSync from package "fs" with non literal argument at index 0   security/detect-non-literal-fs-filename
   16:9   warning  Found statSync from package "fs" with non literal argument at index 0      security/detect-non-literal-fs-filename
  135:15  warning  Found readFileSync from package "fs" with non literal argument at index 0  security/detect-non-literal-fs-filename
  142:7   warning  Unexpected console statement                                               no-console
  150:3   warning  Unexpected console statement                                               no-console
  154:3   warning  Unexpected console statement                                               no-console
  159:3   warning  Unexpected console statement                                               no-console

✖ 14 problems (0 errors, 14 warnings)
Hardcoded secrets check
✅ No hardcoded secrets found.

@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🔐 Contract Security Scan

cargo audit
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1290 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[32m    Scanning�[0m Cargo.lock for vulnerabilities (193 crate dependencies)
�[0m�[0m�[1m�[33mCrate:    �[0m paste
�[0m�[0m�[1m�[33mVersion:  �[0m 1.0.15
�[0m�[0m�[1m�[33mWarning:  �[0m unmaintained
�[0m�[0m�[1m�[33mTitle:    �[0m paste - no longer maintained
�[0m�[0m�[1m�[33mDate:     �[0m 2024-10-07
�[0m�[0m�[1m�[33mID:       �[0m RUSTSEC-2024-0436
�[0m�[0m�[1m�[33mURL:      �[0m https://rustsec.org/advisories/RUSTSEC-2024-0436

�[0m�[0m�[1m�[33mCrate:    �[0m spin
�[0m�[0m�[1m�[33mVersion:  �[0m 0.9.8
�[0m�[0m�[1m�[33mWarning:  �[0m yanked

�[0m�[0m�[1m�[33mwarning:�[0m 2 allowed warnings found
Soroban pattern check
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:407 — pub fn pause performs writes but has no require_auth()
❌ HIGH [SOROBAN-002] contracts/streaming/src/lib.rs:423 — pub fn unpause performs writes but has no require_auth()

2 HIGH severity issue(s) found. Fix before merging.

This branch was successfully deployed

1 active deployment
staging — f56f8278 Deployed Oct 4, 2026 by dependabot[bot] via deploy-staging #308
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants