Skip to content

build(deps-dev): bump @babel/core from 7.29.7 to 8.0.1 - #8351

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/babel/core-8.0.1
Open

build(deps-dev): bump @babel/core from 7.29.7 to 8.0.1#8351
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/babel/core-8.0.1

build(deps-dev): bump @babel/core from 7.29.7 to 8.0.1

21fcb25
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Aug 31, 2026 in 5s

9 new alerts including 4 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 4 high
  • 4 medium
  • 1 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 5414 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

js-yaml: js-yaml: Denial of Service via crafted YAML documents High

Package: js-yaml
Installed Version: 3.14.2
Vulnerability CVE-2026-59869
Severity: HIGH
Fixed Version: 3.15.0, 4.3.0
Link: CVE-2026-59869

Check failure on line 5414 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported High

Package: js-yaml
Installed Version: 3.14.2
Vulnerability GHSA-5p4m-2wfm-xmqj
Severity: HIGH
Fixed Version: 4.3.1, 3.15.1
Link: GHSA-5p4m-2wfm-xmqj

Check failure on line 17869 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

js-yaml: js-yaml: Denial of Service via crafted YAML documents High

Package: js-yaml
Installed Version: 4.1.1
Vulnerability CVE-2026-59869
Severity: HIGH
Fixed Version: 3.15.0, 4.3.0
Link: CVE-2026-59869

Check failure on line 17869 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported High

Package: js-yaml
Installed Version: 4.1.1
Vulnerability GHSA-5p4m-2wfm-xmqj
Severity: HIGH
Fixed Version: 4.3.1, 3.15.1
Link: GHSA-5p4m-2wfm-xmqj

Check warning on line 5414 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

js-yaml: js-yaml: Denial of Service via crafted YAML merge keys Medium

Package: js-yaml
Installed Version: 3.14.2
Vulnerability CVE-2026-53550
Severity: MEDIUM
Fixed Version: 4.2.0, 3.15.0
Link: CVE-2026-53550

Check warning on line 16387 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

http-proxy-middleware: http-proxy-middleware: Unintended backend routing due to crafted Host header Medium

Package: http-proxy-middleware
Installed Version: 2.0.9
Vulnerability CVE-2026-55602
Severity: MEDIUM
Fixed Version: 3.0.6, 4.1.0, 2.0.10
Link: CVE-2026-55602

Check warning on line 17869 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

js-yaml: js-yaml: Denial of Service via crafted YAML merge keys Medium

Package: js-yaml
Installed Version: 4.1.1
Vulnerability CVE-2026-53550
Severity: MEDIUM
Fixed Version: 4.2.0, 3.15.0
Link: CVE-2026-53550

Check warning on line 19270 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

micromatch: vulnerable to Regular Expression Denial of Service Medium

Package: micromatch
Installed Version: 4.0.5
Vulnerability CVE-2024-4067
Severity: MEDIUM
Fixed Version: 4.0.8
Link: CVE-2024-4067

Check notice on line 19666 in package-lock.json

See this annotation in the file changed.

Code scanning / Trivy

jsdiff: denial of service vulnerability in parsePatch and applyPatch Low

Package: diff
Installed Version: 7.0.0
Vulnerability CVE-2026-24001
Severity: LOW
Fixed Version: 8.0.3, 5.2.2, 4.0.4, 3.5.1
Link: CVE-2026-24001