Skip to content

chore: upgrade @babel/core to ^7.29.6 to address CVE-2026-49356#1333

Merged
brendan-kellam merged 3 commits into
mainfrom
linear/sou-1357-sourcebot-devsourcebot-cve-2026-49356-babelcore-d29e
Jun 17, 2026
Merged

chore: upgrade @babel/core to ^7.29.6 to address CVE-2026-49356#1333
brendan-kellam merged 3 commits into
mainfrom
linear/sou-1357-sourcebot-devsourcebot-cve-2026-49356-babelcore-d29e

Conversation

@brendan-kellam

Copy link
Copy Markdown
Contributor

Fixes SOU-1357

Refreshes yarn.lock so all transitive @babel/core instances resolve to 7.29.7 (≥ 7.29.6), addressing CVE-2026-49356 (arbitrary file read via a crafted sourceMappingURL comment).

All three instances came in via existing ^7.18.5 / ^7.24.4 / ^7.26.0 ranges that already admit the patched version, so this is a lockfile-only refresh (yarn up -R @babel/core) with no package.json change. Verified with yarn why @babel/core --recursive:

  • @sentry/nextjs → @sentry/bundler-plugin-core → @babel/core@7.29.7
  • eslint-config-next → eslint-plugin-react-hooks → @babel/core@7.29.7
  • react-scan → @babel/core@7.29.7

brendan-kellam and others added 2 commits June 17, 2026 22:23
Refreshed the yarn.lock so all transitive @babel/core instances resolve to
7.29.7 (>= 7.29.6), fixing the arbitrary file read via sourceMappingURL comment.

Generated with [Linear](https://linear.app/sourcebot/issue/SOU-1357/sourcebot-devsourcebot-cve-2026-49356-babelcore-arbitrary-file-read#agent-session-c9dbdeec)

Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@brendan-kellam, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 3 minutes and 58 seconds. Learn how PR review limits work.

Your organization has used up its prepaid credits, and credit purchases are no longer available. Enable the review add-on in the billing tab to keep reviews running — you're only billed for reviews past your plan's rate limits ($0.25/file).

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based credits.

🚦 How do rate limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan refill rate.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, the refill rate gradually slows as usage increases. The highest same-day bursts are limited more strictly.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 373e772d-77c7-48a9-932c-1e827bb8dc98

📥 Commits

Reviewing files that changed from the base of the PR and between be379c4 and 8dc3390.

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock
📒 Files selected for processing (1)
  • CHANGELOG.md
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch linear/sou-1357-sourcebot-devsourcebot-cve-2026-49356-babelcore-d29e

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2130
Resolved (non-standard) 20
Unresolved 0
Strong copyleft 0
Weak copyleft 39

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.0.5 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-wasm32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.11 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (20)
Package Version Original Resolved Source
@react-grab/cli 0.1.23 UNKNOWN MIT local LICENSE file (node_modules)
@react-grab/cli 0.1.29 UNKNOWN MIT local LICENSE file (node_modules)
@react-grab/mcp 0.1.29 UNKNOWN MIT local LICENSE file (node_modules)
@sentry/cli 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
@sentry/cli-darwin 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-arm 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
@sentry/cli-linux-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
@sentry/cli-win32-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT local LICENSE file (Functional Source License 1.1, MIT Future License)
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 local LICENSE file (node_modules)
element-source 0.0.3 UNKNOWN MIT local LICENSE file (node_modules)
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 local LICENSE file (node_modules)
map-stream 0.1.0 UNKNOWN MIT local LICENCE file (node_modules)
memorystream 0.3.1 UNKNOWN MIT extracted from object (package.json licenses array type field) + LICENSE file
pause-stream 0.0.11 MIT,Apache2 MIT OR Apache-2.0 extracted from object (dual MIT/Apache-2.0), confirmed via LICENSE file
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 local LICENSE file (node_modules)
valid-url 1.0.9 UNKNOWN MIT local LICENSE file (node_modules)

@brendan-kellam brendan-kellam marked this pull request as ready for review June 17, 2026 22:30
@brendan-kellam brendan-kellam merged commit fee2191 into main Jun 17, 2026
8 checks passed
@brendan-kellam brendan-kellam deleted the linear/sou-1357-sourcebot-devsourcebot-cve-2026-49356-babelcore-d29e branch June 17, 2026 22:30
brendan-kellam pushed a commit that referenced this pull request Jun 17, 2026
 (#1344)

#1333 addressed CVE-2026-49356 but left the @babel/core entry shared by
^7.24.4 and ^7.26.0 (eslint-plugin-react-hooks, react-scan) pinned to
7.29.0, below the patched 7.29.6. Refresh via yarn up -R @babel/core so
every transitive instance resolves to 7.29.7. Lockfile-only change.

Generated with [Linear](https://linear.app/sourcebot/issue/SOU-1370/sourcebot-devsourcebot-cve-2026-49356-babelcore-arbitrary-file-read#agent-session-a076660e)

Co-authored-by: linear-code[bot] <222613912+linear-code[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant