Skip to content

Bump @babel/plugin-transform-modules-systemjs to 7.29.4 (CVE-2026-44728)#1984

Closed
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D110064496
Closed

Bump @babel/plugin-transform-modules-systemjs to 7.29.4 (CVE-2026-44728)#1984
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D110064496

Conversation

@rozele

@rozele rozele commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Summary:
Remediates HIGH-severity advisory GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 in babel/plugin-transform-modules-systemjs (affected >= 7.12.0, <= 7.29.3; fixed in 7.29.4).

This is a transitive dependency pulled in via babel/preset-env. The existing semver selector ^7.29.0 already permits 7.29.4, so this is a minimal lockfile-only edit in xplat/yoga/yarn.lock: bump version, resolved, and integrity for the single resolved entry. The dependencies block and the registry.yarnpkg.com host are unchanged, keeping the open-source lockfile consistent and avoiding an internal-registry rewrite.

Session trajectory link

Differential Revision: D110064496

Summary:
Remediates HIGH-severity advisory GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 in `babel/plugin-transform-modules-systemjs` (affected `>= 7.12.0, <= 7.29.3`; fixed in `7.29.4`).

This is a transitive dependency pulled in via `babel/preset-env`. The existing semver selector `^7.29.0` already permits `7.29.4`, so this is a minimal lockfile-only edit in `xplat/yoga/yarn.lock`: bump `version`, `resolved`, and `integrity` for the single resolved entry. The `dependencies` block and the `registry.yarnpkg.com` host are unchanged, keeping the open-source lockfile consistent and avoiding an internal-registry rewrite.

[Session trajectory link](https://www.internalfb.com/intern/devai/devmate/inspector/?id=a694a3ee-9993-4544-a87b-71b63fb12dfc)

Differential Revision: D110064496
@meta-cla meta-cla Bot added the CLA Signed label Jun 29, 2026
@meta-codesync

meta-codesync Bot commented Jun 29, 2026

Copy link
Copy Markdown

@rozele has exported this pull request. If you are a Meta employee, you can view the originating Diff in D110064496.

@rozele rozele closed this Jun 29, 2026
rozele added a commit to rozele/yoga that referenced this pull request Jun 29, 2026
…) (react#1984)

Summary:

Remediates HIGH-severity advisory GHSA-fv7c-fp4j-7gwp / CVE-2026-44728 in `babel/plugin-transform-modules-systemjs` (affected `>= 7.12.0, <= 7.29.3`; fixed in `7.29.4`).

This is a transitive dependency pulled in via `babel/preset-env`. The existing semver selector `^7.29.0` already permits `7.29.4`, so this is a minimal lockfile-only edit in `xplat/yoga/yarn.lock`: bump `version`, `resolved`, and `integrity` for the single resolved entry. The `dependencies` block and the `registry.yarnpkg.com` host are unchanged, keeping the open-source lockfile consistent and avoiding an internal-registry rewrite.

Reviewed By: javache

Differential Revision: D110064496
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant