Skip to content

CVE-2026-48069: Remediate CVE-2026-48069 in ccd-admin-web @grpc/grpc-js#917

Open
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-48069-3659c043-1119-451e-9a05-c64389f8ad6a
Open

CVE-2026-48069: Remediate CVE-2026-48069 in ccd-admin-web @grpc/grpc-js#917
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-48069-3659c043-1119-451e-9a05-c64389f8ad6a

Conversation

@hmcts-github-ccd

Copy link
Copy Markdown
Contributor

Summary:
Remediated CVE-2026-48069 by resolving @grpc/grpc-js@npm:^1.14.3 to 1.14.4 with Yarn 4 after Yarn rejected the bare package descriptor. Verified Node v18.20.8 from .nvmrc and Yarn 4.16.0. yarn install --immutable passed, yarn why shows @grpc/grpc-js resolves to 1.14.4, and the regenerated production audit no longer contains CVE-2026-48069/GHSA-99f4-grh7-6pcq or @grpc/grpc-js. Unrelated audit findings remain. Baseline checks passed: yarn lint, yarn test (237 passing, 1 pending), and yarn sass with existing Sass deprecation warnings.

Plan ID: 3659c043-1119-451e-9a05-c64389f8ad6a

Approved by: dinesh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants