Skip to content

fix(sandbox): resolve trivy vulnerability findings in sandbox services - #2615

Merged
a-ganguly merged 2 commits into
masterfrom
fix/trivy
Sep 30, 2026
Merged

a-ganguly merged 2 commits into
masterfrom
fix/trivy

Conversation

@piyushsinghgaur1

@piyushsinghgaur1 piyushsinghgaur1 commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Bumped dependencies in chat-notification-pubnub-example, chat-notification-socketio-example, and telemed-app sandbox services
  • Regenerated package-lock.json files to resolve security vulnerabilities flagged by Trivy

Test plan

  • Trivy scan passes on updated sandbox services
  • Existing sandbox service functionality unaffected

bump dependencies in chat-notification-pubnub-example, chat-notification-socketio-example, and telemed-app sandbox services to address security vulnerabilities flagged by trivy
@sonarqubecloud

Copy link
Copy Markdown

@piyushsinghgaur1
piyushsinghgaur1 marked this pull request as ready for review September 29, 2026 11:09
@piyushsinghgaur1
piyushsinghgaur1 requested a review from a team as a code owner September 29, 2026 11:09

@rohit-sourcefuse rohit-sourcefuse left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@piyushsinghgaur1

Approving. The sandbox lockfiles go from 61 HIGH to 6 on a Trivy scan, and CI is green.

One thing worth a follow-up: the root package-lock.json was regenerated as well, and a few packages went backwards there. loopback-connector-kv-redis's nested loopback-connector dropped from 4.11.1 to 4.2.2, which pulls in cross-spawn 5.1.0 (CVE-2024-21538).

postman-request went from postman.49 to postman.8-beta.1, nx from 22.7.8 to 22.6.4, and ejs from 5 to 3. Overall the root lock is still better (20 → 18 HIGH), so not blocking.

But it'd be good to restore those in the next pass, e.g. update from the existing lockfile rather than a fresh resolve, or add an overrides entry for loopback-connector.

Also, adding fast-uri as a direct dependency in the sandbox package.json files works, but an overrides entry would keep it out of each app's own dependency list.

@a-ganguly
a-ganguly merged commit c262018 into master Sep 30, 2026
9 checks passed
@a-ganguly
a-ganguly deleted the fix/trivy branch September 30, 2026 06:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants