-
-
Notifications
You must be signed in to change notification settings - Fork 6.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: Upgrade babel deps to v7.23.3 #14711
Conversation
✅ Deploy Preview for jestjs ready!Built without sensitive environment variables
To edit notification comments on pull requests, go to your Netlify site configuration. |
Is there a release plan for this? Would love to have this vulnerability patched. cc @isolde-a |
Any chance I can get some reviews on this please 🙏 |
Hi @SimenB, sorry for the tag but I'm struggling for reviews here. |
Hey @reece-white! Sorry, somehow missed the pings in this PR. I don't think we need to do this, as all the versions are within our semver range (as can be seen by no versions changing in our lockfile). Is there any concrete issues we solve by forcing newer versions? |
This pull request has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs. |
Summary
Babel <v7.23.2 contains vulnerability CVE-2023-45133 https://security.snyk.io/vuln/SNYK-JS-BABELTRAVERSE-5962462
Test plan