Skip to content

Fix Dependabot alert #17: update @babel/core to 7.29.7#9

Merged
tidy-dev merged 1 commit into
mainfrom
tidy-dev/fix-dependabot-alert-17
Jun 18, 2026
Merged

Fix Dependabot alert #17: update @babel/core to 7.29.7#9
tidy-dev merged 1 commit into
mainfrom
tidy-dev/fix-dependabot-alert-17

Conversation

@tidy-dev

Copy link
Copy Markdown
Collaborator

Summary

Updates the transitive dependency @babel/core from 7.29.0 to 7.29.7 to resolve Dependabot alert #17.

Vulnerability

  • CVE: CVE-2026-49356
  • Severity: Low
  • Issue: Arbitrary File Read via sourceMappingURL Comment
  • Patched in: 7.29.6

Changes

  • Updated package-lock.json to pull @babel/core@7.29.7 (transitive dep via Jest/ts-jest)

Testing

All 42 existing tests pass.

Update transitive dependency @babel/core from 7.29.0 to 7.29.7 to fix
an arbitrary file read vulnerability via sourceMappingURL comment.

Resolves Dependabot alert #17.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings June 18, 2026 11:19
@tidy-dev tidy-dev requested a review from a team as a code owner June 18, 2026 11:19

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

GitHub Advanced Security started work on behalf of tidy-dev June 18, 2026 11:19 View session
GitHub Advanced Security finished work on behalf of tidy-dev June 18, 2026 11:20
@tidy-dev tidy-dev enabled auto-merge June 18, 2026 11:30
@tidy-dev tidy-dev merged commit 3e1f4c7 into main Jun 18, 2026
4 checks passed
@tidy-dev tidy-dev deleted the tidy-dev/fix-dependabot-alert-17 branch June 18, 2026 11:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants