fix(security): CVE-2026-27212 and CVE-2026-26996 addressed for release/3.12 (#5831)
* fix(security): CVE-2026-27212 patched. Various dependency updates as a result of CVE-2026-26996. Ultimately CVE-2026-26996 was ignored because it is only exposed in itk-wasm via CLI and OHIF's other use of minimatch is limited to build/dev environments. * Switched to eslint 9.39.3 for compatibility with .eslintrc.json.
This commit is contained in:
1 parent
c5c18f9516
commit
51d267e707
11 files changed
+1872
-1046
No files matched your search
@@ -121,6 +121,8 @@ jobs:
|
||||
|
||||
# Define ignored vulnerabilities with comments
|
||||
IGNORED_VULNS=(
|
||||
"GHSA-3ppc-4f35-3m26" # CVE-2026-26996 - OHIF's use of minimatch via glob is safe because it does NOT use the CLI
|
||||
# CVE-2026-26996 - OHIF's other uses of minimatch are strictly for building and CI/CD purposes
|
||||
)
|
||||
|
||||
# Build ignore flags
|
||||
|
||||
Reference in new issue
Block a user