fix(security): CVE-2026-27212 and CVE-2026-26996 addressed for release/3.12 (#5831)

* fix(security):  CVE-2026-27212 patched.
Various dependency updates as a result of CVE-2026-26996.
Ultimately CVE-2026-26996 was ignored because it is only exposed in itk-wasm via CLI and OHIF's other use of minimatch is limited to build/dev environments.

* Switched to eslint 9.39.3 for compatibility with .eslintrc.json.
This commit is contained in:
Joe Boccanfuso authored and GitHub committed 2026-02-23 14:51:42 -05:00
1 parent c5c18f9516
commit 51d267e707
11 files changed
+1872 -1046

No files matched your search

+2
View File
@@ -121,6 +121,8 @@ jobs:
# Define ignored vulnerabilities with comments
IGNORED_VULNS=(
"GHSA-3ppc-4f35-3m26" # CVE-2026-26996 - OHIF's use of minimatch via glob is safe because it does NOT use the CLI
# CVE-2026-26996 - OHIF's other uses of minimatch are strictly for building and CI/CD purposes
)
# Build ignore flags