Skip to content

Conversation

@h-labushkina
Copy link

What:

Replaced the usage of the chalk package with colorette in tests/failOnUnexpectedConsoleCalls.js to address a security issue with the previous dependency.

Why:

The chalk package version in use was flagged as malicious (MAL-2025-46969, Score: 10). Replacing it with colorette removes the security risk and maintains colored output functionality.

How:

  • Uninstalled chalk from the project.
  • Updated imports and color/style function calls in tests/failOnUnexpectedConsoleCalls.js to use colorette as equivalent.
  • Ensured all references to chalk were removed.

Used colorette: "^2.0.20"

  • Documentation added to the
    docs site
  • Tests
  • TypeScript definitions updated
  • Ready to be merged

Issue description:
npm:chalk:0.0.0-ANY is malicious
MAL-2025-46969, Score: 10
Replaced with safe alternative:
colorette: "^2.0.20"
@codesandbox-ci
Copy link

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

Latest deployment of this branch, based on commit 77e42cc:

Sandbox Source
react-testing-library-examples Configuration

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant