@babel/core updates needed on v20 for CVE
envgap__angular__angular-69608
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
5a693bafcd49ef11ce687bd91a209e1a46652f42- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
angular/angular #69608 · read the original issue
### Which @angular/* package(s) are the source of the bug?
compiler-cli and localize
### Is this a regression?
No
### Description
The `@babel/core` version (7.28.3) used by the latest v20 release of `@angular/compiler-cli` and `@angular/localize` (20.3.25) is affected by CVE-2026-49356. Could that be updated to at least `7.29.6` for both packages to eliminate the CVE from the dependency chain?
### Please provide a link to a minimal reproduction of the bug
_No response_
### Please provide the environment you discovered this bug in (run `ng version`)
```true
Angular CLI: 20.3.31
Node: 22.22.3
Package Manager: npm 11.17.0
OS: win32 x64
Angular: 20.3.25
... animations, common, compiler, compiler-cli, core, forms
... localize, platform-browser, platform-browser-dynamic, router
Package Version
------------------------------------
@angular-devkit/architect 0.2003.31
@angular-devkit/core 20.3.31
@angular-devkit/schematics 20.3.31
@angular/build 20.3.31
@angular/cdk 20.2.14
@angular/cli 20.3.31
@angular/material 20.2.14
@schematics/angular 20.3.31
rxjs 7.8.2
typescript 5.8.3
zone.js 0.15.1
```
### Anything else?
_No response_04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]