SUPPLY-001D8: patch Babel SystemJS compiler chain#454
Merged
Conversation
✅ Deploy Preview for luminous-fox-7c393f ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The root production build graph no longer resolves the high-severity Babel SystemJS compiler defect. The patch stays inside the existing compatible parent range, changes no manifest or application code, and leaves every non-source-map build file byte-identical.
Officer impact: None. Officers use the website and current no-terminal procedures unchanged.
Officer documentation: None — this build-dependency repair changes no public content, navigation, collected data, permissions, deployment procedure, external account, payment, incident, backup, or recovery workflow.
Deployment evidence: Source and lock changed; all local gates passed and hosted PR checks are pending. The website was not published or verified, Firebase was not deployed, outside providers were not configured or contacted, production data was not inspected, and production behavior is unverified.
What changed
@babel/plugin-transform-modules-systemjsnode from affected 7.25.9 to reviewed 7.29.7 through@babel/preset-env@7.26.9's unchanged^7.25.9range.package.jsonbyte-for-byte unchanged (SHA-256af7101c5af46fb704fcf1de8f1dc5f50ab4beba9aeabc03e46dab1d3eff4a68d) with no direct dependency or override.package-lock.jsonto exactly 16 records: 13 Babel records, two Jridgewell mapping records, and removal of one now-unused mapping helper.Invariant and failure behavior
Every SystemJS transform path must resolve once to a patched 7.x release through the unchanged parent. A direct declaration, override, second copy, affected version, missing public-registry identity, changed preset, changed manifest, or unexpected closure now fails the focused test. The fixture also rejects the old malformed identifier output.
There is no schema, data, account, payment, Firebase, provider, or runtime migration. Rollback requires a separately reviewed revert that explicitly reassesses the reopened advisory.
RED proof
On exact main
937e336031ffe064aa120460327538aab0d45d30:_exportObj.default exports, failed the computed-key assertion, and was not valid JavaScript.After the lock refresh, the focused dependency suite passes 14/14 and the fixture emits
_exportObj["default exports"].Verification
npm ls: one SystemJS 7.29.7 through preset-env 7.26.9; passed.demo-rules-test.demo-pay002b2-test.3fa30c6d66827277432dcf7d42b0ead9e9fd543c9907571b092cfa43ba3f1e46. Onlymain.85f5094a.js.mapchanges; its 477 source paths and contents are identical, while mapping/name metadata adds 2,574 bytes.Review
Three independent adversarial reviews inspected the final branch:
a0ca3bdand re-reviewed clean.Residual risk
The separate Babel-core low and brace-expansion/minimatch high findings remain open and are not accepted as safe. The old development-only Firebase CLI critical paths require a separate CLI 15 + Java 21 compatibility child. Functions audit findings remain open. Native
npm sbomremains blocked by the pre-existing@types/reactpeer mismatch; no SBOM was committed or uploaded, and SUPPLY-001G retains dependency-inventory automation.Closes #453