Skip to content

exui 4177 vulnerabilities fixes#1269

Merged
RiteshHMCTS merged 21 commits intomasterfrom
exui-4177-vulnerability-fixes
Mar 12, 2026
Merged

exui 4177 vulnerabilities fixes#1269
RiteshHMCTS merged 21 commits intomasterfrom
exui-4177-vulnerability-fixes

Conversation

@balajisridharanhmcts
Copy link
Contributor

@balajisridharanhmcts balajisridharanhmcts commented Feb 16, 2026

Jira link

See EXUI-4177

Change description

  • Axios has been updated to latest version 1.13.5
  • bn.js resolution added. It comes from session-file-store comes -> kruptein -> asn1.js > bn.js.
    A ticket has been created to check on session-file-store library usage.
    https://tools.hmcts.net/jira/browse/EXUI-4248
  • Angular patch versions has been updated to fix new cves generated on angular/ssr

Forcefully updating it to 10.2.1 version by resolution creates issues in Karma test. So suppressed minimatch for now.

Testing done

Security Vulnerability Assessment

CVE Suppression: Are there any CVEs present in the codebase (either newly introduced or pre-existing) that are being intentionally suppressed or ignored by this commit?

  • Yes
  • No

Checklist

  • commit messages are meaningful and follow good commit message guidelines
  • README and other documentation has been updated / added (if needed)
  • tests have been updated / new tests has been added (if needed)
  • Does this PR introduce a breaking change

@balajisridharanhmcts balajisridharanhmcts changed the title vulnerabilities fixes exui 4177 vulnerabilities fixes Feb 26, 2026
@RiteshHMCTS RiteshHMCTS merged commit 9014af2 into master Mar 12, 2026
6 checks passed
@RiteshHMCTS RiteshHMCTS deleted the exui-4177-vulnerability-fixes branch March 12, 2026 12:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants