Skip to content

fix: bump @babel/plugin-transform-modules-systemjs to patched 7.29.7 - #441

Closed
adrian-asher-cko wants to merge 1 commit into
masterfrom
fix/dependabot-113-babel-systemjs
Closed

fix: bump @babel/plugin-transform-modules-systemjs to patched 7.29.7#441
adrian-asher-cko wants to merge 1 commit into
masterfrom
fix/dependabot-113-babel-systemjs

Conversation

@adrian-asher-cko

Copy link
Copy Markdown

Resolves Dependabot alert #113 (GHSA-fv7c-fp4j-7gwp / CVE-2026-44728, high severity). The vulnerable transitive dev dependency @babel/plugin-transform-modules-systemjs 7.28.5 (pulled in via @babel/preset-env) allowed arbitrary code generation when compiling malicious input. Updated the lockfile to 7.29.7 (>= 7.29.4 patched).

Resolves Dependabot alert #113 (GHSA-fv7c-fp4j-7gwp / CVE-2026-44728,
high severity). The vulnerable transitive dev dependency
@babel/plugin-transform-modules-systemjs 7.28.5 (pulled in via
@babel/preset-env) allowed arbitrary code generation when compiling
malicious input. Updated the lockfile to 7.29.7 (>= 7.29.4 patched).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@agent-wall-e

agent-wall-e Bot commented Jul 23, 2026

Copy link
Copy Markdown

🟢 Risk Classification: LOW

Approval route: AI Auto-Approval
Rollback controls: Automated Instant Rollback + feature flags

Classification reasons

  • 2.2.7_dependency_upgrade

Operational gates

  • ✅ jira_ticket (CVE-2026)
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 376219bc71e6…

@agent-wall-e

agent-wall-e Bot commented Jul 23, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
2.2.7_dependency_upgrade classifying §2.2.7 All files are manifest + lockfile, and no security-sensitive package was touched.

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@sonarqubecloud

Copy link
Copy Markdown

@agent-wall-e agent-wall-e Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved — this PR meets all Low-risk criteria.

All checks passed, no unresolved comments, and the change classification is:

  • 2.2.7_dependency_upgrade

wall-e 2026.06.19-02 · policy 376219bc71e6…

@adrian-asher-cko
adrian-asher-cko deleted the fix/dependabot-113-babel-systemjs branch July 23, 2026 09:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant