build(deps-dev): bump @babel/core from 7.29.7 to 8.0.1 - #8351
build(deps-dev): bump @babel/core from 7.29.7 to 8.0.1#8351dependabot[bot] wants to merge 1 commit into
9 new alerts including 4 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 4 high
- 4 medium
- 1 low
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check failure on line 5414 in package-lock.json
Code scanning / Trivy
js-yaml: js-yaml: Denial of Service via crafted YAML documents High
Check failure on line 5414 in package-lock.json
Code scanning / Trivy
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported High
Check failure on line 17869 in package-lock.json
Code scanning / Trivy
js-yaml: js-yaml: Denial of Service via crafted YAML documents High
Check failure on line 17869 in package-lock.json
Code scanning / Trivy
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported High
Check warning on line 5414 in package-lock.json
Code scanning / Trivy
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys Medium
Check warning on line 16387 in package-lock.json
Code scanning / Trivy
http-proxy-middleware: http-proxy-middleware: Unintended backend routing due to crafted Host header Medium
Check warning on line 17869 in package-lock.json
Code scanning / Trivy
js-yaml: js-yaml: Denial of Service via crafted YAML merge keys Medium
Check warning on line 19270 in package-lock.json
Code scanning / Trivy
micromatch: vulnerable to Regular Expression Denial of Service Medium
Check notice on line 19666 in package-lock.json
Code scanning / Trivy
jsdiff: denial of service vulnerability in parsePatch and applyPatch Low