Skip to content

sec(frontend): upgrade @babel/core past 7.29.0 to fix GHSA-4x5r-pxfx-6jf8 (arbitrary file read) #1270

Description

@cristim

Summary

After PR #872 pinned `@babel/core` to `7.28.5` (matching the existing lockfile), `npm audit` reports:

GHSA-4x5r-pxfx-6jf8 — @babel/core: Arbitrary File Read via sourceMappingURL Comment
Affected: <=7.29.0
Fix: upgrade to 7.29.7+

The fix requires `--force` because 7.29.7 is outside the range `^7.23.0` the project previously used (but the range constraint was the old package.json; after #872 the version is pinned). The fix is: update `@babel/core`, `@babel/preset-env`, `@babel/preset-typescript` to `>=7.29.7` in both `package.json` and run `npm install` to regenerate `package-lock.json`.

Note: this CVE was present in `main`'s lockfile before #872; it is NOT introduced by #872.

Steps

  1. npm install @babel/core@^7.29.7 @babel/preset-env@^7.29.7 @babel/preset-typescript@^7.29.7 --save-dev
  2. Pin the new resolved versions (exact) in package.json to maintain supply-chain discipline from sec(frontend): pin npm dependencies to exact versions (closes #425) #872.
  3. Run npm test to confirm no breakage.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions