Skip to content

CVE-2026-44902: Remediate CVE-2026-44902 in ccd-api-gateway#748

Open
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-44902-eacdc33f-f799-4a14-8202-8b395ba4c84e
Open

CVE-2026-44902: Remediate CVE-2026-44902 in ccd-api-gateway#748
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-44902-eacdc33f-f799-4a14-8202-8b395ba4c84e

Conversation

@hmcts-github-ccd

Copy link
Copy Markdown
Contributor

Summary:
Upgraded root dependency applicationinsights from 3.14.0 to 3.15.0 using Yarn 4.16.0, which resolved the vulnerable OpenTelemetry path to @azure/monitor-opentelemetry 1.18.1, @opentelemetry/sdk-node 0.218.0, and @opentelemetry/exporter-prometheus 0.218.0. Activated expected Node v22.22.3 from .nvmrc via /usr/local/nvm; repo-local Yarn 4.16.0 was used because the global Corepack yarn shim cannot fetch Yarn in this environment. yarn install --immutable passed after remediation. Regenerated yarn-audit-known-issues; CVE-2026-44902/GHSA-q7rr-3cgh-j5r3 and the affected OpenTelemetry packages are absent from the production audit, though unrelated known advisories remain. Verification: lint passed with the known unused eslint-disable warning, test:unit passed with 94 passing tests, direct yarn node --version returned v22.22.3. The test and setup wrapper scripts still fail due the internal Corepack yarn network-fetch limitation, matching the plan's environment-limited baseline. No compile/build or Dockerfile-derived non-mutating build script is configured or feasible.

Plan ID: eacdc33f-f799-4a14-8202-8b395ba4c84e

Approved by: james

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant