Skip to content

CVE-2026-48068: Remediate CVE-2026-48068 in ccd-case-print-service#767

Open
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-48068-7cb02e54-7396-4ca3-94fd-26be74b4e695
Open

CVE-2026-48068: Remediate CVE-2026-48068 in ccd-case-print-service#767
hmcts-github-ccd[bot] wants to merge 1 commit into
masterfrom
cve-2026-48068-7cb02e54-7396-4ca3-94fd-26be74b4e695

Conversation

@hmcts-github-ccd

Copy link
Copy Markdown
Contributor

Summary:
Applied CVE remediation with Yarn 4 by resolving @grpc/grpc-js@npm:^1.14.3 to 1.14.4 after the package-name form was rejected by Yarn 4 as an invalid descriptor. Regenerated yarn-audit-known-issues; CVE-2026-48068/GHSA-5375-pq7m-f5r2 and the related @grpc/grpc-js 1.14.3 audit entries are absent, while unrelated existing audit findings remain. Verification: yarn install --immutable passed before and after; yarn why shows @grpc/grpc-js only at 1.14.4; yarn lint passed; yarn sass passed; yarn test:unit still fails with the pre-existing no-files pattern. Expected Node source is .nvmrc 18.20.8, but nvm is unavailable in this environment, so checks ran on active node v20.20.2 using the checked-in Yarn 4.16.0 release.

Plan ID: 7cb02e54-7396-4ca3-94fd-26be74b4e695

Approved by: james

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants