npm package intelligence

jest — deep security report

ShadowCanopy's full breakdown of jest on npm: verdict, AI analysis, dependency chain, network behavior, prebuilds, and obfuscated code.

Safe to use
Deep-scanned by ShadowCanopy — no threats found in its code, dependencies, or network behavior.
Scanned 8/7/2026
Approvedjest@30.4.2View on registry ↗latest: 30.4.2

No static findings, standard Jest package layout, sandbox completed cleanly with no suspicious behavior observed. Legitimate testing framework.

Protect your projects free

AI breakdown

Plain-English summary of what this package does and how it behaves.

Jest is a JavaScript testing framework whose manifest describes it as 'Delightful JavaScript Testing.' It exposes a CLI via bin/jest.js and a main module at build/index.js, with dependencies on @jest/core, @jest/types, import-local, and jest-cli.

Capabilities

  • Provides CLI entry point
  • Loads core testing modules via dependencies
  • Supports both CommonJS and ESM entry points

Data access

  • None observed

Network

  • No network access observed

Widely adopted official testing package with empty static findings; install from npm registry and review its transitive dependencies as with any dev tool.

Dependency & execution chain

Every package this one pulls in, colored by verdict. Expand to walk the tree.

235 packages5 direct1 flaggedtruncated
jest@30.4.2
@jest/core@30.4.22 findings
@jest/types@30.4.1
jest-cli@30.4.2

Package metadata

LicenseMIT

Delightful JavaScript Testing.

Homepage ↗Repository ↗

Files in package (14)

LICENSEpackage/LICENSEbuild/index.jspackage/build/index.jsbin/jest.jspackage/bin/jest.jspackage.jsonpackage/package.jsonREADME.mdpackage/README.mdbuild/index.mjspackage/build/index.mjsbuild/index.d.tspackage/build/index.d.ts

How ShadowCanopy checks npm packages

ShadowCanopy blocks every dependency by default and only lets through what it can verify — against live malicious-package advisories, an AI behavior scan, and a byte-for-byte hash check. It protects installs across npm, PyPI, crates.io, pkg.go.dev, RubyGems, Maven Central, NuGet, Packagist, Hex, pub.dev, Swift Package Manager.

Protect your projects freeSee what's being blocked

This report reflects ShadowCanopy's threat intelligence at page load and is informational, not a warranty. Canonical URL: https://shadowcanopy.dev/packages/npm/jest