Skip to content

Bump @babel/plugin-transform-modules-systemjs to 7.29.4#144

Open
niceking wants to merge 1 commit into
mainfrom
bump-babel-plugin-transform-modules-systemjs
Open

Bump @babel/plugin-transform-modules-systemjs to 7.29.4#144
niceking wants to merge 1 commit into
mainfrom
bump-babel-plugin-transform-modules-systemjs

Conversation

@niceking
Copy link
Copy Markdown
Contributor

Patches GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 (high severity code injection in the SystemJS modules transform).

Bumps the transitive lockfile entry from 7.20.117.29.4.

Triage

  • Transitive devDependency via @babel/preset-env (used by Jest's Babel toolchain).
  • Not used at runtime and not shipped in the published buildkite-test-collector package.
  • Vulnerability requires Babel to compile untrusted source with modules: "systemjs", which we do not do.
  • Bumping the lockfile to clear the Dependabot alert.

Closes Dependabot alert #108.

Linear: TE-5847

Patches GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 (high severity code
injection in the SystemJS modules transform).

Transitive devDependency via @babel/preset-env. Not used at runtime
and not shipped in the published package; bumping the lockfile to
clear the Dependabot alert.

Refs: TE-5847
Amp-Thread-ID: https://ampcode.com/threads/T-019e29a5-f93c-76de-8db4-2d2d4c22fa38
Co-authored-by: Amp <amp@ampcode.com>
@niceking
Copy link
Copy Markdown
Contributor Author

@codex review

@niceking niceking requested a review from a team May 15, 2026 03:56
@chatgpt-codex-connector
Copy link
Copy Markdown

Codex Review: Didn't find any major issues. You're on a roll.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants