Skip to content

CVE-2026-44290: Remediation plan for CVE-2026-44290 in ccd-api-gateway#746

Open
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-44290-0494431e-d0f5-4cb9-a052-4d02f0e1c256
Open

CVE-2026-44290: Remediation plan for CVE-2026-44290 in ccd-api-gateway#746
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-44290-0494431e-d0f5-4cb9-a052-4d02f0e1c256

Conversation

@hmcts-github-ccd

Copy link
Copy Markdown
Contributor

Summary:
Applied the approved descriptor-level Yarn fallback after Yarn 4.16.0 rejected the bare package-level descriptor. protobufjs descriptors ^7.3.0 and ^7.5.3 now resolve to protobufjs@8.6.1 in yarn.lock. Verified with Node v22.22.3 from .nvmrc and Yarn 4.16.0: yarn install --immutable passed, yarn why protobufjs shows only 8.6.1, and regenerated production audit snapshot has no CVE-2026-44290/GHSA-jvwf-75h9-cwgg/protobufjs entries. yarn lint passed with the existing .yarn release warning; yarn test:unit passed with 94 passing. yarn test still fails due the pre-existing nested Corepack shim network issue described in the plan. No compile/build script or Dockerfile-derived compile/build check is configured.

Plan ID: 0494431e-d0f5-4cb9-a052-4d02f0e1c256

Approved by: dinesh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants