department-of-veterans-affairs / va.gov-cms

Editor-centered management for Veteran-centered content.
https://prod.cms.va.gov
GNU General Public License v2.0
99 stars 69 forks source link

Update expressjs/body-parser in docroot/designsystem for cms and cms-test #19336

Open edmund-dunn opened 1 month ago

edmund-dunn commented 1 month ago

User Story or Problem Statement

According to https://github.com/advisories/GHSA-qwcr-r2fm-qrc7/dependabot?query=user:department-of-veterans-affairs, there is a recent vulnerability in expressjs/body-parser. We need to update to >=v4.20.

For cms and cms-test this is only an issue for storybook. Storybook has not been updated yet, but an issue exists.

Description or Additional Context

Waiting for this PR to be merged for storybook

Steps for Implementation

Acceptance Criteria

edmund-dunn commented 1 month ago

@gracekretschmer-metrostar this needs to be done soonish https://dsva.slack.com/archives/CT4GZBM8F/p1727364013031559 We will need to wait, though until storybook releases an update

gracekretschmer-metrostar commented 1 month ago

Per @edmund-dunn: we have dependency on for the team managing storybook to merge this PR before we can do this work. Marked as blocked and we will touch base on ticket before each new sprint.