Skip to content

chore(deps): update tests to v22 - #1062

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-tests
Open

chore(deps): update tests to v22#1062
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-tests

Conversation

@renovate

@renovate renovate Bot commented May 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change OpenSSF
@types/sinon (source) devDependencies major 21.0.122.0.0 OpenSSF Scorecard
sinon (source) devDependencies major 21.1.222.1.0 OpenSSF Scorecard

Release Notes

sinonjs/sinon (sinon)

v22.1.0

Compare Source

  • d36e921b
    fix: let returns override returnsArg (王胜)

    Signed-off-by: 王胜 <2318857637@​qq.com>

  • 40c4caa0
    fix: align restoreObject docs test with idempotent behavior (#​2745) (Julia Miller)

    restoreObject was made idempotent in #​2737 — it no longer throws
    for objects with no restorable methods. Updates the docs page
    and its corresponding test to reflect this.

  • a68dac19
    fix: throw a clear error when throwArg index equals the argument count (#​2743) (spokodev)
    • fix: throw a clear error when throwArg index equals the argument count

    spyCall.throwArg(pos) guarded with pos > this.args.length, so calling it
    with pos equal to the number of recorded arguments slipped past the guard
    and reached throw this.args[pos], throwing undefined instead of the
    intended TypeError. A thrown undefined cannot be inspected as an Error and
    is reported by test frameworks as no exception thrown.

    Use >= to match ensureArgs in behavior.js and the sibling callArg helpers,
    which already reject an out-of-range index with a clear error.

  • 9ea504e3
    feat: make sinon.restoreObject idempotent (#​2737) (Ilia Choly)

    Passing an object with no live fakes to restoreObject now restores
    nothing instead of throwing, giving it symmetry with sinon.restore()
    and sandbox.restore(). The strict "found no methods" check is retained
    for spy(object) and stub(object), which now use a dedicated
    walkObjectStrict export, while restoreObject uses the loose walkObject.
    Passing a falsy value still throws.

    Fixes #​2736

  • 4db4feff
    fix: preserve fake undefined argument validation (Vishal Kumar Singh)
  • 755a40d7
    fix: isolate callId counter per sandbox for parallel test support (Vishal Kumar Singh)

    The global callId counter in proxy-invoke.js caused calledImmediatelyBefore
    and calledImmediatelyAfter to fail when tests run in parallel with separate
    sandboxes. Each sandbox now maintains its own callId counter, passed through
    the spy/stub/fake creation chain via a context object.

    Fixes #​2472

Released by Morgan Roderick on 2026-07-20.

v22.0.0

Compare Source

  • ed911df5
    Update Ruby gems (Carl-Erik Kopseng)
  • 75a1e5b8
    Update to Node 26 (Carl-Erik Kopseng)
  • 197d6608
    Update documentation on faking timers to reflect the current state of fake-timers (Carl-Erik Kopseng)
  • c5ddf80b
    Update fake-timers@​15.4: includes new Temporal API (Carl-Erik Kopseng)
  • f4ab02f6
    Update updatable packages (Carl-Erik Kopseng)
  • 0536afc8
    Quality: Global mutable call id can grow unbounded across long-lived processes (#​2691) (tuanaiseo)
    • refactor: global mutable call id can grow unbounded across l

    callId is module-scoped and incremented on every invocation. In long-running test runners or embedded usage, this can grow indefinitely and eventually lose integer precision semantics for strict ordering comparisons.

    Affected files: proxy-invoke.js

    Signed-off-by: tuanaiseo 221258316+tuanaiseo@users.noreply.github.com

    • Wrap around for all values that are too high

    Signed-off-by: tuanaiseo 221258316+tuanaiseo@users.noreply.github.com
    Co-authored-by: Carl-Erik Kopseng carlerik@gmail.com

  • f4f7d93b
    Perform additional cleanup when calling callThrough() (#​2670) (Cyrille)
  • 6199e9e4
    improve GitHubworkflows by introducing zizmor for monitoring (#​2686) (Till!)
    • fix(workflows): fetch-depth is for actions/checkout

    • chore(workflows): update

    • pin all actions to precise commits
    • avoid credential leakage from actions/checkout
    • group action updates going forward
    • add zimor config to ignore "secrets outside env"
    • add job to keep validating workflows
  • f7476b59
    Use path.normalize() for path normalization (Carl-Erik Kopseng)
  • 2c975393
    fix: make build and node test scripts cross-platform (laplace young)
  • a7692917
    fix: isolate walk state from Object prototype (laplace young)
  • 66df977a
    Fix sinon.restore() cascade-restoring sub-sandboxes (#​2704) (Charlie Leitheiser)

    The ESM port of createApi (#​2683, shipped in 21.1.0) replaced createSandbox: createSandbox with a wrapper that pushes every newly-created sandbox into the root sandbox's fake collection:

    createSandbox: function createSandbox(config) {
        const s = createConfiguredSandbox(config);
        sandbox.getFakes().push(s);
        return s;
    }
    

    Sandbox#restore then walks that collection and calls .restore() on each entry. Because a sub-sandbox is itself an entry, every top-level sinon.restore() cascades into every sub-sandbox and undoes its stubs/timers/etc. — defeating the whole point of having an isolated sub-sandbox. The same cascade hits resetHistory and
    verifyAndRestore. This is the regression reported in #​2701.

    Restore the pre-21.1 behaviour: hand the root API a direct reference to createConfiguredSandbox. Sub-sandboxes are now isolated; only subSandbox.restore() (or verifyAndRestore) clears their fakes.

    Also flip the four sandbox tests that were locking in the buggy cascade: they now assert the parent's restore/resetHistory leaves the child untouched, with an explicit child-side cleanup at the
    end.

    Closes #​2701

  • f0bd6e1b
    fix: exclude proto from walk() (#​2699) (Kevin Locke)

    __proto__ is a special property to access an object's prototype. It
    has many pitfalls:

    • Setting it to an object value changes an object's prototype, which is
      generally discouraged and may be unexpected by the iterator callback.
    • Setting it to a non-object value does nothing (meaning seen[k] = true has no effect).
    • When Node.js is run with the --disable-proto=throw option, getting
      or setting __proto__ causes an exception with code
      ERR_PROTO_ACCESS to be thrown.

    Additionally, since this property (and all properties of
    Object.prototype) are currently unused in this project by consumers of
    walk(), it is both safe and preferable to exclude.

    Fixes: #​2695

    Signed-off-by: Kevin Locke kevin@kevinlocke.name

  • 1f8afd50
    chore: add context7.json for ownership confirmation (Morgan Roderick)

Released by Carl-Erik Kopseng on 2026-05-05.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • On day 10 and 25 of the month (* * 10,25 * *)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added dependencies Pull requests that update a dependency file tests labels May 10, 2026
@renovate
renovate Bot force-pushed the renovate/major-tests branch 6 times, most recently from 37b0ab7 to 5b6cada Compare May 11, 2026 05:31
@renovate
renovate Bot force-pushed the renovate/major-tests branch from 5b6cada to 539cabc Compare May 18, 2026 04:36
@renovate
renovate Bot force-pushed the renovate/major-tests branch 4 times, most recently from d036032 to 41edbe3 Compare May 25, 2026 17:14
@renovate
renovate Bot force-pushed the renovate/major-tests branch from 41edbe3 to 38da96e Compare June 1, 2026 18:48
@renovate renovate Bot changed the title chore(deps): update dependency sinon to v22 chore(deps): update tests to v22 Jun 2, 2026
@renovate
renovate Bot force-pushed the renovate/major-tests branch 5 times, most recently from ee8b097 to 62455c7 Compare June 10, 2026 23:11
@renovate
renovate Bot force-pushed the renovate/major-tests branch from 62455c7 to e797e59 Compare June 15, 2026 06:35
@renovate
renovate Bot force-pushed the renovate/major-tests branch from e797e59 to b16f275 Compare June 22, 2026 07:10
@renovate renovate Bot changed the title chore(deps): update tests to v22 chore(deps): update tests (major) Jun 22, 2026
@renovate
renovate Bot force-pushed the renovate/major-tests branch 3 times, most recently from feecc80 to 08f5306 Compare June 25, 2026 13:04
@renovate renovate Bot changed the title chore(deps): update tests (major) chore(deps): update dependency sinon to v22 Jun 25, 2026
@renovate
renovate Bot force-pushed the renovate/major-tests branch from 08f5306 to de52fb0 Compare June 25, 2026 22:47
@renovate
renovate Bot force-pushed the renovate/major-tests branch 2 times, most recently from fbe4643 to 55b3003 Compare July 4, 2026 08:51
@renovate renovate Bot changed the title chore(deps): update dependency sinon to v22 chore(deps): update tests to v22 Jul 4, 2026
@renovate
renovate Bot force-pushed the renovate/major-tests branch 4 times, most recently from 1c9f7a8 to 09507bd Compare July 10, 2026 17:45
@renovate
renovate Bot force-pushed the renovate/major-tests branch 3 times, most recently from ceec1b6 to 90fca1e Compare July 23, 2026 18:02
@renovate
renovate Bot force-pushed the renovate/major-tests branch 4 times, most recently from b5f3a25 to a646e69 Compare July 25, 2026 17:55
@renovate
renovate Bot force-pushed the renovate/major-tests branch from a646e69 to 55148f1 Compare July 25, 2026 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants