You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
sec(frontend): upgrade @babel/core past 7.29.0 to fix GHSA-4x5r-pxfx-6jf8 (arbitrary file read) #1270
After PR #872 pinned `@babel/core` to `7.28.5` (matching the existing lockfile), `npm audit` reports:
GHSA-4x5r-pxfx-6jf8 — @babel/core: Arbitrary File Read via sourceMappingURL Comment
Affected: <=7.29.0
Fix: upgrade to 7.29.7+
The fix requires `--force` because 7.29.7 is outside the range `^7.23.0` the project previously used (but the range constraint was the old package.json; after #872 the version is pinned). The fix is: update `@babel/core`, `@babel/preset-env`, `@babel/preset-typescript` to `>=7.29.7` in both `package.json` and run `npm install` to regenerate `package-lock.json`.
Note: this CVE was present in `main`'s lockfile before #872; it is NOT introduced by #872.
Summary
After PR #872 pinned `@babel/core` to `7.28.5` (matching the existing lockfile), `npm audit` reports:
The fix requires `--force` because 7.29.7 is outside the range `^7.23.0` the project previously used (but the range constraint was the old package.json; after #872 the version is pinned). The fix is: update `@babel/core`, `@babel/preset-env`, `@babel/preset-typescript` to `>=7.29.7` in both `package.json` and run `npm install` to regenerate `package-lock.json`.
Note: this CVE was present in `main`'s lockfile before #872; it is NOT introduced by #872.
Steps
npm install @babel/core@^7.29.7 @babel/preset-env@^7.29.7 @babel/preset-typescript@^7.29.7 --save-devpackage.jsonto maintain supply-chain discipline from sec(frontend): pin npm dependencies to exact versions (closes #425) #872.npm testto confirm no breakage.