CRA Index / npm / @babel/helper-module-transforms
@babel/helper-module-transforms and the Cyber Resilience Act
8 of 9 readable security signals are in place for @babel/helper-module-transforms 8.0.6 (npm). Data checked 2026-10-05.
- passNo known vulnerabilities in the latest version: none listed (Annex I, Part II: address and remediate vulnerabilities without delay)
- passNot deprecated: not marked as deprecated (support period and updates)
- passActively maintained: Scorecard Maintained 10/10 (security updates for the whole support period)
- passSecurity policy: Scorecard Security-Policy 10/10 (Annex I, Part II: coordinated vulnerability disclosure policy and contact address)
- passLicence declared: MIT (component documentation and licence notices)
- passCode review before merge: Scorecard Code-Review 9/10 (secure development process (Annex VII, development and vulnerability handling processes))
- passCI workflow hygiene: Dangerous-Workflow 10, Token-Permissions 9 (integrity of the build and update chain)
- passSigned releases or provenance: build provenance or attestations published (Annex I, Part II: secure distribution of updates)
- missingAutomated security testing: SAST 0, Fuzzing 0 (Annex I, Part II: effective and regular tests and reviews)
@babel/helper-module-transforms 8.0.6 is the current default version of this npm package, published on 2026-09-18. The registry lists 147 versions in total and the licence declared is MIT. The source repository is babel/babel with 44,080 stars.
The OpenSSF Scorecard for the repository was last computed on 2026-08-24 and gives an overall 7.2/10. Signals that are not in place today: automated security testing.
As of 2026-10-05, deps.dev lists no known advisories for this version. That is a snapshot and not a promise: new advisories can be published at any time.
If you ship a product that includes @babel/helper-module-transforms, the Cyber Resilience Act expects you to know which components you ship, to follow their vulnerabilities and to exercise due diligence on third-party components (Annex I, Part II and Article 13). In practice: list @babel/helper-module-transforms 8.0.6 in your SBOM with its package URL pkg:npm/%40babel/[email protected], watch for new advisories, and keep the upstream security contact in your vulnerability handling process.
Put the badge in your README
Check your own project
Run the repository check on babel/babel, or check your own SBOM and create the licence notices.
More in the index
@babel/helper-compilation-targets, @babel/helper-module-imports, @babel/helper-plugin-utils, @babel/helper-string-parser, @babel/helper-validator-identifier, @babel/helpers · all npm packages
Sources and method
Package and version facts, licences, advisories and provenance: deps.dev (generated data under CC BY 4.0; advisories from OSV). Repository signals: the OpenSSF Scorecard. We read them on 2026-10-05 and show them without scoring the people behind a project. The nine signals are our selection; every signal could be read for this package.
Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.