Skip to content

CVE-2026-49356 @babel/core: Arbitrary File Read via sourceMappingURL Comment #1049

Merged
vharseko merged 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/babel/core-7.29.6
Jun 17, 2026
Merged

CVE-2026-49356 @babel/core: Arbitrary File Read via sourceMappingURL Comment #1049
vharseko merged 1 commit into
masterfrom
dependabot/npm_and_yarn/openam-ui/openam-ui-ria/babel/core-7.29.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 15, 2026

Copy link
Copy Markdown
Contributor

Bumps @babel/core from 7.28.4 to 7.29.6.

Release notes

Sourced from @​babel/core's releases.

v7.29.6 (2026-05-25)

🐛 Bug Fix

Committers: 3

v7.29.5 (2026-05-05)

🏠 Internal

  • babel-preset-env
    • Update @babel/* dependencies

v7.29.4 (2026-05-05)

🐛 Bug Fix

  • babel-plugin-transform-modules-systemjs
    • #17974 [7.x backport]fix(systemjs): improve module string name support (@​JLHwung)

Committers: 1

v7.29.3 (2026-04-30)

👓 Spec Compliance

🐛 Bug Fix

  • babel-helper-create-class-features-plugin, babel-plugin-proposal-decorators
    • #17931 fix(decorators): replace super within all removed static elements (@​JLHwung)
  • babel-register
  • babel-compat-data, babel-plugin-bugfix-safari-rest-destructuring-rhs-array, babel-preset-env

💅 Polish

📝 Documentation

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​babel/core since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jun 15, 2026
@vharseko vharseko changed the title Bump @babel/core from 7.28.4 to 7.29.6 in /openam-ui/openam-ui-ria CVE-2026-49356 @babel/core: Arbitrary File Read via sourceMappingURL Comment Jun 15, 2026
@vharseko

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot dependabot Bot changed the title CVE-2026-49356 @babel/core: Arbitrary File Read via sourceMappingURL Comment Bump @babel/core from 7.28.4 to 7.29.6 in /openam-ui/openam-ui-ria Jun 16, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/openam-ui/openam-ui-ria/babel/core-7.29.6 branch from b0b19a8 to 64627f9 Compare June 16, 2026 18:37
@vharseko vharseko changed the title Bump @babel/core from 7.28.4 to 7.29.6 in /openam-ui/openam-ui-ria CVE-2026-49356 @babel/core: Arbitrary File Read via sourceMappingURL Comment Jun 16, 2026
Bumps [@babel/core](https://github.com/babel/babel/tree/HEAD/packages/babel-core) from 7.28.4 to 7.29.6.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.29.6/packages/babel-core)

---
updated-dependencies:
- dependency-name: "@babel/core"
  dependency-version: 7.29.6
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title CVE-2026-49356 @babel/core: Arbitrary File Read via sourceMappingURL Comment Bump @babel/core from 7.28.4 to 7.29.6 in /openam-ui/openam-ui-ria Jun 16, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/openam-ui/openam-ui-ria/babel/core-7.29.6 branch from 64627f9 to 4d86acc Compare June 16, 2026 19:05
@vharseko vharseko changed the title Bump @babel/core from 7.28.4 to 7.29.6 in /openam-ui/openam-ui-ria CVE-2026-49356 @babel/core: Arbitrary File Read via sourceMappingURL Comment Jun 16, 2026
@vharseko vharseko merged commit 67a263a into master Jun 17, 2026
16 checks passed
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/openam-ui/openam-ui-ria/babel/core-7.29.6 branch June 17, 2026 05:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant