Skip to content

Bump @babel/plugin-transform-modules-systemjs to fix CVE-2026-44728#56775

Closed
CalixTang wants to merge 1 commit into
react:mainfrom
CalixTang:export-D104687110
Closed

Bump @babel/plugin-transform-modules-systemjs to fix CVE-2026-44728#56775
CalixTang wants to merge 1 commit into
react:mainfrom
CalixTang:export-D104687110

Conversation

@CalixTang

Copy link
Copy Markdown
Contributor

Summary:
babel/plugin-transform-modules-systemjs versions >= 7.12.0 and <= 7.29.3 are affected by CVE-2026-44728 (GHSA-fv7c-fp4j-7gwp), a HIGH severity vulnerability. The react-native repo resolves this package at 7.25.9 via babel/preset-env. This adds a Yarn resolution to force the package to ^7.29.4, the first patched version.

#Changelog: [Internal]
[General] - Bump babel/plugin-transform-modules-systemjs to 7.29.4

Reviewed By: robhogan

Differential Revision: D104687110

Summary:
babel/plugin-transform-modules-systemjs versions >= 7.12.0 and <= 7.29.3 are affected by CVE-2026-44728 (GHSA-fv7c-fp4j-7gwp), a HIGH severity vulnerability. The react-native repo resolves this package at 7.25.9 via babel/preset-env. This adds a Yarn resolution to force the package to ^7.29.4, the first patched version.

#Changelog: [Internal]
[General] - Bump `babel/plugin-transform-modules-systemjs` to 7.29.4

Reviewed By: robhogan

Differential Revision: D104687110
@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label May 11, 2026
@meta-codesync

meta-codesync Bot commented May 11, 2026

Copy link
Copy Markdown

@CalixTang has exported this pull request. If you are a Meta employee, you can view the originating Diff in D104687110.

@meta-codesync meta-codesync Bot closed this in 497177f May 11, 2026
@facebook-github-tools facebook-github-tools Bot added the Merged This PR has been merged. label May 11, 2026
@meta-codesync

meta-codesync Bot commented May 11, 2026

Copy link
Copy Markdown

This pull request has been merged in 497177f.

@react-native-bot

Copy link
Copy Markdown
Collaborator

This pull request was successfully merged by @CalixTang in 497177f

When will my fix make it into a release? | How to file a pick request?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. fb-exported Merged This PR has been merged. meta-exported p: Facebook Partner: Facebook Partner

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants