Skip to content

CCD-7780 :: CVE-2026-44288: Remediate CVE-2026-44288 in ccd-admin-web#901

Open
hmcts-github-ccd[bot] wants to merge 2 commits into
masterfrom
cve-2026-44288-1d0d18de-04bf-4954-9080-3e07119fd055
Open

CCD-7780 :: CVE-2026-44288: Remediate CVE-2026-44288 in ccd-admin-web#901
hmcts-github-ccd[bot] wants to merge 2 commits into
masterfrom
cve-2026-44288-1d0d18de-04bf-4954-9080-3e07119fd055

Conversation

@hmcts-github-ccd

Copy link
Copy Markdown
Contributor

Summary:
Remediated CVE-2026-44288 using Yarn 4 descriptor resolutions after Yarn 4.16.0 rejected the planned bare package descriptor. yarn.lock now resolves protobufjs@npm:^7.5.3 to 7.6.2, protobufjs@npm:8.0.1 to 8.5.0, and the remaining @protobufjs/utf8 path to 1.1.1. Regenerated yarn-audit-known-issues; CVE-2026-44288 / GHSA-q6x5-8v7m-xcrf and protobufjs audit findings are absent, though the production audit still exits nonzero for unrelated existing advisories/deprecations. Verification ran under active Node v18.20.8 from .nvmrc with packageManager yarn@4.16.0 using the checked-in Yarn release because the global shim attempted a network download. yarn install --immutable passed; yarn lint passed; yarn test passed with 237 passing and 1 pending; yarn sass passed with pre-existing Sass deprecation warnings.

Plan ID: 1d0d18de-04bf-4954-9080-3e07119fd055

@dinesh1patel dinesh1patel changed the title CVE-2026-44288: Remediate CVE-2026-44288 in ccd-admin-web CCD-7780 :: CVE-2026-44288: Remediate CVE-2026-44288 in ccd-admin-web Jun 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant