opossum icon indicating copy to clipboard operation
opossum copied to clipboard

[Snyk] Upgrade: @babel/core, @babel/preset-env

Open lholmquist opened this issue 1 year ago • 1 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together. :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
Name Versions Released on
@babel/corefrom 7.22.9 to 7.23.2 9 versions ahead of your current version a month agoon 2023-10-12
@babel/preset-envfrom 7.22.9 to 7.23.2 5 versions ahead of your current version a month agoon 2023-10-11

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
465/1000
Why? CVSS 9.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @babel/core
  • 7.23.2 - 2023-10-12

    v@babel/[email protected]

  • 7.23.0 - 2023-09-25

    v7.23.0 (2023-09-25)

    Thanks @ lorenzoferre and @ RajShukla1 for your first PRs!

    🚀 New Feature

    • babel-plugin-proposal-import-wasm-source, babel-plugin-syntax-import-source, babel-plugin-transform-dynamic-import
    • babel-helper-module-transforms, babel-helpers, babel-plugin-proposal-import-defer, babel-plugin-syntax-import-defer, babel-plugin-transform-modules-commonjs, babel-runtime-corejs2, babel-runtime-corejs3, babel-runtime, babel-standalone
    • babel-generator, babel-parser, babel-types
    • babel-generator, babel-helper-module-transforms, babel-parser, babel-plugin-transform-dynamic-import, babel-plugin-transform-modules-amd, babel-plugin-transform-modules-commonjs, babel-plugin-transform-modules-systemjs, babel-traverse, babel-types
    • babel-standalone
    • babel-helper-function-name, babel-helper-member-expression-to-functions, babel-helpers, babel-parser, babel-plugin-proposal-destructuring-private, babel-plugin-proposal-optional-chaining-assign, babel-plugin-syntax-optional-chaining-assign, babel-plugin-transform-destructuring, babel-plugin-transform-optional-chaining, babel-runtime-corejs2, babel-runtime-corejs3, babel-runtime, babel-standalone, babel-types
    • babel-helpers, babel-plugin-proposal-decorators
    • babel-traverse, babel-types
    • babel-preset-typescript
    • babel-parser

    🐛 Bug Fix

    • babel-plugin-transform-block-scoping
      • #15962 fix: transform-block-scoping captures the variables of the method in the loop (@ liuxingbaoyu)

    💅 Polish

    • babel-traverse
    • babel-plugin-proposal-explicit-resource-management

    🔬 Output optimization

    • babel-core, babel-helper-module-transforms, babel-plugin-transform-async-to-generator, babel-plugin-transform-classes, babel-plugin-transform-dynamic-import, babel-plugin-transform-function-name, babel-plugin-transform-modules-amd, babel-plugin-transform-modules-commonjs, babel-plugin-transform-modules-umd, babel-plugin-transform-parameters, babel-plugin-transform-react-constant-elements, babel-plugin-transform-react-inline-elements, babel-plugin-transform-runtime, babel-plugin-transform-typescript, babel-preset-env

    Committers: 7

  • 7.22.20 - 2023-09-16

    v7.22.20 (2023-09-16)

    🏠 Internal

    • babel-helper-validator-identifier
    • babel-plugin-transform-dotall-regex

    ↩️ Revert

    • babel-helper-remap-async-to-generator, babel-helper-wrap-function, babel-plugin-proposal-explicit-resource-management, babel-plugin-proposal-function-sent, babel-plugin-transform-async-generator-functions, babel-plugin-transform-async-to-generator, babel-plugin-transform-block-scoping, babel-plugin-transform-class-properties, babel-plugin-transform-classes, babel-plugin-transform-parameters, babel-plugin-transform-runtime, babel-preset-env

    Committers: 3

  • 7.22.19 - 2023-09-14

    v7.22.19 (2023-09-14)

    Re-published 7.22.18, due to a releasing error.

  • 7.22.18 - 2023-09-14

    v7.22.18 (2023-09-14)

    NOTE: This release had a publishing problem -- it has been re-published as 7.22.19.

    Thanks @ dhlolo for your first PR!

    🐛 Bug Fix

    • babel-helper-validator-identifier
    • babel-helper-module-transforms, babel-plugin-transform-modules-amd, babel-plugin-transform-modules-commonjs, babel-plugin-transform-modules-umd
      • #15898 Fix transform of named import with shadowed namespace import (@ dhlolo)

    ↩️ Revert

    Committers: 3

  • 7.22.17 - 2023-09-08

    v7.22.17 (2023-09-08)

    Thanks @ jordanbtucker for your first PR!

    🐛 Bug Fix

    🔬 Output optimization

    • babel-helper-remap-async-to-generator, babel-helper-wrap-function, babel-plugin-proposal-explicit-resource-management, babel-plugin-proposal-function-sent, babel-plugin-transform-async-generator-functions, babel-plugin-transform-async-to-generator, babel-plugin-transform-block-scoping, babel-plugin-transform-class-properties, babel-plugin-transform-classes, babel-plugin-transform-parameters, babel-plugin-transform-runtime, babel-preset-env

    Committers: 3

  • 7.22.15 - 2023-09-04
  • 7.22.11 - 2023-08-24
  • 7.22.10 - 2023-08-07
  • 7.22.9 - 2023-07-12
from @babel/core GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

lholmquist avatar Nov 07 '23 19:11 lholmquist

This pull request is stale because it has been open 30 days with no activity.

github-actions[bot] avatar Dec 08 '23 00:12 github-actions[bot]