Skip to content

CVE-2026-48068: Remediate CVE-2026-48068 in ccd-admin-web @grpc/grpc-js dependency#918

Open
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-48068-30b17fe7-6456-4dfa-9d34-a0c254f8e979
Open

CVE-2026-48068: Remediate CVE-2026-48068 in ccd-admin-web @grpc/grpc-js dependency#918
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-48068-30b17fe7-6456-4dfa-9d34-a0c254f8e979

Conversation

@hmcts-github-ccd

Copy link
Copy Markdown
Contributor

Summary:
Remediated CVE-2026-48068 by resolving @grpc/grpc-js@npm:^1.14.3 to @grpc/grpc-js@1.14.4 in yarn.lock using Yarn 4. The literal package-level yarn set resolution command failed as an invalid Yarn descriptor for the scoped package, so the approved descriptor-level fallback was used. Expected Node source was .nvmrc=18.20.8; active verification Node was v18.20.8; Yarn was 4.16.0. yarn install --immutable passed after remediation. yarn why shows all @grpc/grpc-js consumers resolving to 1.14.4. Regenerated yarn-audit-known-issues; production audit still exits nonzero for unrelated findings, but no longer reports CVE-2026-48068, GHSA-5375-pq7m-f5r2, @grpc/grpc-js, or 1.14.3. Verification: yarn lint passed, yarn sass passed with pre-existing Sass deprecation warnings, yarn test passed with 237 passing and 1 pending, yarn test:unit retains the pre-existing no matching files failure.

Plan ID: 30b17fe7-6456-4dfa-9d34-a0c254f8e979

Approved by: dinesh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants