UKHomeOfficeForms / hof

Bootstrap a HOF project
MIT License
15 stars 17 forks source link

Hof 403 fv vuln #470

Closed shamiluwais closed 2 months ago

shamiluwais commented 2 months ago

What?

Update security vulnerabilities - HOFF-403

Why?

Update vulnerabilities that are flagged up by trivy in file-vault

How? Updated express-partial-templates and notifications-node-client to later versions that did not have vulnerabilities

Testing?

Updated file-vault module with the hof beta with the above fixes and the built file-vault image tested using ROTM service

Other fs-tree-traverse npm has a vulnerability but cannot be resolved as it in a private npm space: https://www.npmjs.com/package/fs-tree-traverse