Skip to content

CCD-7780 :: CVE-2026-44289: Remediate CVE-2026-44289 in ccd-admin-web protobufjs dependency#906

Open
hmcts-github-ccd[bot] wants to merge 2 commits into
masterfrom
cve-2026-44289-739ac3d1-be23-45c4-af0b-9c7f9b5fee02
Open

CCD-7780 :: CVE-2026-44289: Remediate CVE-2026-44289 in ccd-admin-web protobufjs dependency#906
hmcts-github-ccd[bot] wants to merge 2 commits into
masterfrom
cve-2026-44289-739ac3d1-be23-45c4-af0b-9c7f9b5fee02

Conversation

@hmcts-github-ccd

Copy link
Copy Markdown
Contributor

Summary:
Applied CVE-2026-44289 remediation by adding a protobufjs resolution to 8.5.0 and updating yarn.lock with Yarn 4. Verified Node v18.20.8 from .nvmrc and Yarn 4.16.0. yarn install --immutable passed after lockfile update. yarn why protobufjs now resolves all protobufjs paths to 8.5.0. Regenerated yarn-audit-known-issues; CVE-2026-44289 / GHSA-685m-2w69-288q is absent, though unrelated pre-existing production audit findings remain. Baseline checks passed: yarn sass, yarn lint, yarn test (237 passing, 1 pending).

Plan ID: 739ac3d1-be23-45c4-af0b-9c7f9b5fee02

@dinesh1patel dinesh1patel changed the title CVE-2026-44289: Remediate CVE-2026-44289 in ccd-admin-web protobufjs dependency CCD-7780 :: CVE-2026-44289: Remediate CVE-2026-44289 in ccd-admin-web protobufjs dependency Jun 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant