Skip to content

BAU: Override @babel/plugin-transform-modules-systemjs to 7.29.4 to fix CVE-2026-44728#8348

Open
alhcomer wants to merge 1 commit into
mainfrom
BAU/constrain-babel-plugin-transform-modules-systemjs-to-7.29.4
Open

BAU: Override @babel/plugin-transform-modules-systemjs to 7.29.4 to fix CVE-2026-44728#8348
alhcomer wants to merge 1 commit into
mainfrom
BAU/constrain-babel-plugin-transform-modules-systemjs-to-7.29.4

Conversation

@alhcomer
Copy link
Copy Markdown
Contributor

What

  • Adds npm override for @babel/plugin-transform-modules-systemjs to >=7.29.4 to fix CVE-2026-44728 (prototype pollution via SystemJS module transform). This is a transitive dependency via @babel/preset-env.

How to review

  1. Code Review

- CVE-2026-44728: prototype pollution via SystemJS module
  transform. Adding npm override to constrain transitive
  dependency (via @babel/preset-env) to >=7.29.4.

See: https://github.com/govuk-one-login/authentication-api/security/dependabot/115
@alhcomer alhcomer requested review from a team as code owners May 18, 2026 14:26
@github-actions
Copy link
Copy Markdown

Java Tests Skipped

No Java files were changed in this pull request. Java tests will be skipped1.

Any Java files that are changed in a subsequent commit will trigger the Java tests.

Footnotes

  1. These tests will still show as passing in the PR status check, but will not actually have run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant