fix: resolve Dependabot security alerts and upgrade Jest to v30 #8485
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description of changes:
This PR resolves three critical security vulnerabilities identified by Dependabot by upgrading the Jest ecosystem and adding dependency resolutions.
Security Fixes:
Dependency Updates:
Configuration & Test Updates:
Results: All tests passing (54 suites, 195 tests) with no security vulnerabilities remaining. Development server starts successfully with no errors.
Related GitHub issue #, if available:
Fixes Dependabot security alerts for glob and js-yaml vulnerabilities
Instructions
If this PR should not be merged upon approval for any reason, please submit as a DRAFT
Which product(s) are affected by this PR (if applicable)?
Which platform(s) are affected by this PR (if applicable)?
Please add the product(s)/platform(s) affected to the PR title
Checks
ref: MDX:
[link](https://docs.amplify.aws/)HTML:<a href="https://docs.amplify.aws/">link</a>When this PR is ready to merge, please check the box below
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.