Skip to content

fix: upgrade babel version#617

Merged
Mercy811 merged 2 commits intov8.xfrom
cursor/sdk-dependency-vulnerabilities-eb37
Feb 4, 2026
Merged

fix: upgrade babel version#617
Mercy811 merged 2 commits intov8.xfrom
cursor/sdk-dependency-vulnerabilities-eb37

Conversation

@Mercy811
Copy link
Contributor

@Mercy811 Mercy811 commented Feb 3, 2026

Summary

Updates @babel/runtime to version 7.28.6 to resolve a known moderate security vulnerability (npm advisory 1104000) related to inefficient RegExp complexity. This ensures the SDK's production dependencies are free of known vulnerabilities.

Checklist

  • Does your PR title have the correct title format?
  • Does your PR have a breaking change?: No

Open in Cursor Open in Web

Co-authored-by: xinyi.ye <xinyi.ye@amplitude.com>
@cursor
Copy link

cursor bot commented Feb 3, 2026

Cursor Agent can help with this pull request. Just @cursor in comments and I'll start working on changes in this branch.
Learn more about Cursor Agents

@macroscopeapp
Copy link

macroscopeapp bot commented Feb 3, 2026

Upgrade @babel/runtime to ^7.28.6 and switch GitHub Actions node_modules caching to actions/cache@v4 across CI workflows

Bumps @babel/runtime to ^7.28.6 in package.json and updates CI workflows to use actions/cache@v4 for node_modules caching.

📍Where to Start

Start with the dependency change in package.json, then review the cache step updates in ./github/workflows/test.yml.


Macroscope summarized 86532ed.

@Mercy811 Mercy811 changed the title Sdk dependency vulnerabilities fix: upgrade babel version Feb 3, 2026
Co-authored-by: xinyi.ye <xinyi.ye@amplitude.com>
@Mercy811 Mercy811 marked this pull request as ready for review February 3, 2026 21:57
@Mercy811 Mercy811 merged commit 427aac2 into v8.x Feb 4, 2026
4 checks passed
@Mercy811 Mercy811 deleted the cursor/sdk-dependency-vulnerabilities-eb37 branch February 4, 2026 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants