fix: upgrade @babel/plugin-transform-modules-systemjs to 7.29.4, 8.0.0-alpha.13 (CVE-2026-44728)#9965
Conversation
Automated dependency upgrade by OrbisAI Security
|
|
|
I have read the CLA Document and I hereby sign the CLA |
13 similar comments
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
|
I have read the CLA Document and I hereby sign the CLA |
Summary
Upgrade @babel/plugin-transform-modules-systemjs from 7.28.5 to 7.29.4, 8.0.0-alpha.13 to fix CVE-2026-44728.
Vulnerability
CVE-2026-44728packages/insomnia-component-docs/package-lock.jsonDescription: @babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
Changes
packages/insomnia-component-docs/package.jsonpackages/insomnia-component-docs/package-lock.jsonVerification
This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface.
Automated security fix by OrbisAI Security