Skip to content

UID2-7294: fix(deps): upgrade @grpc/grpc-js to fix CVE-2026-48068, CVE-2026-48069#190

Merged
sunnywu merged 1 commit into
mainfrom
syw-UID2-7294-grpc-js-cve-fix
Jun 13, 2026
Merged

UID2-7294: fix(deps): upgrade @grpc/grpc-js to fix CVE-2026-48068, CVE-2026-48069#190
sunnywu merged 1 commit into
mainfrom
syw-UID2-7294-grpc-js-cve-fix

fix(deps): upgrade @grpc/grpc-js to >=1.13.5 to fix CVE-2026-48068, C…

3dc3ce7
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy completed Jun 13, 2026 in 2s

1 configuration not found

Warning: Code scanning may not have found all the alerts introduced by this pull request, because 1 configuration present on refs/heads/main was not found:

Actions workflow (release-tc-portal-image.yaml)

  • ❓  .github/workflows/release-tc-portal-image.yaml:buildImage

New alerts in code changed by this pull request

Security Alerts:

  • 1 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 4586 in yarn.lock

See this annotation in the file changed.

Code scanning / Trivy

### Summary `qs.stringify` throws `TypeError` when called with `arr ... Medium

Package: qs
Installed Version: 6.15.0
Vulnerability CVE-2026-8723
Severity: MEDIUM
Fixed Version: 6.15.2
Link: CVE-2026-8723