Bump @babel/plugin-transform-modules-systemjs from 7.27.1 to 7.29.4 - #485
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [@babel/plugin-transform-modules-systemjs](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-modules-systemjs) from 7.27.1 to 7.29.4. - [Release notes](https://github.com/babel/babel/releases) - [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md) - [Commits](https://github.com/babel/babel/commits/v7.29.4/packages/babel-plugin-transform-modules-systemjs) --- updated-dependencies: - dependency-name: "@babel/plugin-transform-modules-systemjs" dependency-version: 7.29.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
kieran-osgood-shopify
added a commit
that referenced
this pull request
Oct 2, 2026
* Update JavaScript dependencies ## Summary Bottom layer of the dependency-cleanup stack: JavaScript → Ruby/CocoaPods → Android → React Native/sample → CI. - Update Babel core/preset-env to 7.29.7 and the React Native CLI family to 19.1.2; refresh vulnerable transitive dependencies in the current pnpm lockfile. - Upgrade Turbo to 2.9.18, migrate `pipeline` to `tasks`, and preserve existing environment forwarding with loose mode. - Scope fast-xml-parser 5.7.0 overrides to the Android/iOS CLI consumers. Patch query-string's decoder import so it can use the fixed decode-uri-component 0.5.0 without changing React Navigation's API. - Add seven compatibility tests, including the malformed-URL stack-overflow regression, and run the complete Jest suite in CI. React 19.1.0, React Native 0.80.2, and native dependency versions are unchanged in this layer. ## Security status The resolved graph addresses all 52 npm alerts in the [GitHub alert baseline](https://github.com/Shopify/checkout-sheet-kit-react-native/security/dependabot?q=is%3Aopen+ecosystem%3Anpm). These close only after the fixes reach the default branch and GitHub refreshes its dependency graph. The public npm audit decreases from **71 findings to 2 high findings**, with no critical findings remaining. The remaining Metro → image-size advisories are not dismissed or ignored: - GHSA-w3rx-r6r6-pgpr - GHSA-5p2g-fcmc-qvqq Both currently advertise no patched version. Metro expects the image-size 1.x API, so a 2.x override also needs separate compatibility validation. Ruby alerts are reserved for the next stack layer. ## Supersedes Closes #385 Closes #446 Closes #451 Closes #454 Closes #459 Closes #471 Closes #477 Closes #485 Confirm these bot PRs close after landing; do not treat a closed PR as proof that its security alerts are resolved. ## Validation - 130 tests pass across seven suites. - Frozen-lockfile install, TypeScript/ESLint, license checks, module build, API report, and package snapshot pass. The sample retains its existing inline-style warning. - Release-mode Metro bundles succeed for iOS and Android. The React Native CLI discovers Checkout Kit on both platforms. - No manual device sweep yet; perform it once from the completed stack tip. ## How to test **GIVEN** the sample app is configured for a development storefront with products available for purchase **WHEN** you start Metro, build and launch the sample on iOS and Android, browse Catalog → product details → Cart, visit Settings, then open and dismiss checkout **THEN** builds succeed, images and navigation work, and checkout opens and returns to the sample without new runtime errors; behavior should match the base branch Assisted-By: devx/d410d084-ca7b-490b-87be-85f7eac08cb6 * Ignore generated files when checking license headers Assisted-By: devx/d410d084-ca7b-490b-87be-85f7eac08cb6 * Restore module artifacts from the Turbo cache Assisted-By: devx/d410d084-ca7b-490b-87be-85f7eac08cb6
dependabot
Bot
deleted the
dependabot/npm_and_yarn/babel/plugin-transform-modules-systemjs-7.29.4
branch
October 2, 2026 09:46
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps @babel/plugin-transform-modules-systemjs from 7.27.1 to 7.29.4.
Release notes
Sourced from @babel/plugin-transform-modules-systemjs's releases.
... (truncated)
Commits
a458f66v7.29.432ebd5a[7.x backport]fix(systemjs): improve module string name support (#17974)aa8394ev7.29.00053db6Update polyfill packages (#17727)61647aev7.28.5a177d55[Babel 8] Uset.traverseFastto replace somepath.traverse(#17518)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for
@babel/plugin-transform-modules-systemjssince your current version.You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.