Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix Security Vulnerabilities #3648

Open
wants to merge 13 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from 7 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions bin/run-smoke-tests.sh
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
#!/bin/bash
set -ex

pip3 install --upgrade requests
pip3 install docker==6.1.3

ADDITIONAL_COMPOSE_FILE="docker-compose.smoke-tests.yml -f docker-compose.yml"

function shutdownDocker() {
Expand Down
74 changes: 53 additions & 21 deletions charts/cmc-citizen-frontend/values.preview.template.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -83,26 +83,58 @@ cmc-claim-store:
cmc:
resourceGroup: cmc
secrets:
- AppInsightsInstrumentationKey
- citizen-oauth-client-secret
- claim-store-s2s-secret
- anonymous-caseworker-username
- anonymous-caseworker-password
- system-update-username
- system-update-password
- notify-api-key
- milo-recipient
- staff-email
- live-support-email
- rpa-email-sealed-claim
- rpa-email-more-time-requested
- rpa-email-response
- rpa-email-ccj
- rpa-email-paid-in-full
- launchDarkly-sdk-key
- sendgrid-api-key
- staff-email-legal-rep
- rpa-email-breathing-space
- name: claim-store-db-password
alias: CLAIM_STORE_DB_PASSWORD
- name: AppInsightsInstrumentationKey
alias: azure.application-insights.instrumentation-key
- name: cmc-db-password-v15
alias: CMC_DB_PASSWORD
- name: cmc-db-username-v15
alias: CMC_DB_USERNAME
- name: cmc-db-host-v15
alias: CMC_DB_HOST
- name: citizen-oauth-client-secret
alias: oauth2.client.secret
- name: claim-store-s2s-secret
alias: idam.s2s-auth.totp_secret
- name: anonymous-caseworker-username
alias: idam.caseworker.anonymous.username
- name: anonymous-caseworker-password
alias: idam.caseworker.anonymous.password
- name: system-update-username
alias: idam.caseworker.system.username
- name: system-update-password
alias: idam.caseworker.system.password
- name: notify-api-key
alias: GOV_NOTIFY_API_KEY
- name: milo-recipient
alias: MILO_CSV_RECIPIENT
- name: staff-email
alias: staff-notifications.recipient
- name: live-support-email
alias: live-support.recipient
- name: rpa-email-sealed-claim
alias: rpa.notifications.sealedClaimRecipient
- name: rpa-email-breathing-space
alias: rpa.notifications.breathingSpaceRecipient
- name: rpa-email-legal-sealed-claim
alias: rpa.notifications.legalSealedClaimRecipient
- name: rpa-email-more-time-requested
alias: rpa.notifications.moreTimeRequestedRecipient
- name: rpa-email-response
alias: rpa.notifications.responseRecipient
- name: rpa-email-ccj
alias: rpa.notifications.countyCourtJudgementRecipient
- name: rpa-email-paid-in-full
alias: rpa.notifications.paidInFullRecipient
- name: launchDarkly-sdk-key
alias: LAUNCH_DARKLY_SDK_KEY
- name: sendgrid-api-key
alias: SENDGRID_API_KEY
- name: staff-email-legal-rep
alias: staff-notifications.legalRecipient
- name: appinsights-connection-string
alias: appinsights-connection-string
environment:
LOG_LEVEL: DEBUG
DOC_ASSEMBLY_URL: http://dg-docassembly-aat.service.core-compute-aat.internal
Expand Down Expand Up @@ -270,4 +302,4 @@ ccd:
logstash:
image:
tag: ccd-cmc-logstash-latest

33 changes: 11 additions & 22 deletions yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -11940,11 +11940,11 @@ __metadata:
linkType: hard

"semver@npm:2 || 3 || 4 || 5, semver@npm:^5.3.0, semver@npm:^5.4.1, semver@npm:^5.5.0, semver@npm:^5.5.1, semver@npm:^5.6.0, semver@npm:^5.7.0, semver@npm:^5.7.1":
version: 5.7.1
resolution: "semver@npm:5.7.1"
version: 5.7.2
resolution: "semver@npm:5.7.2"
bin:
semver: ./bin/semver
checksum: 57fd0acfd0bac382ee87cd52cd0aaa5af086a7dc8d60379dfe65fea491fb2489b6016400813930ecd61fd0952dae75c115287a1b16c234b1550887117744dfaf
semver: bin/semver
checksum: fb4ab5e0dd1c22ce0c937ea390b4a822147a9c53dbd2a9a0132f12fe382902beef4fbf12cf51bb955248d8d15874ce8cd89532569756384f994309825f10b686
languageName: node
linkType: hard

Expand All @@ -11958,33 +11958,22 @@ __metadata:
linkType: hard

"semver@npm:^6.0.0, semver@npm:^6.2.0, semver@npm:^6.3.0":
version: 6.3.0
resolution: "semver@npm:6.3.0"
bin:
semver: ./bin/semver.js
checksum: 1b26ecf6db9e8292dd90df4e781d91875c0dcc1b1909e70f5d12959a23c7eebb8f01ea581c00783bbee72ceeaad9505797c381756326073850dc36ed284b21b9
languageName: node
linkType: hard

"semver@npm:^7.3.0, semver@npm:^7.3.4":
version: 7.3.5
resolution: "semver@npm:7.3.5"
dependencies:
lru-cache: ^6.0.0
version: 6.3.1
resolution: "semver@npm:6.3.1"
bin:
semver: bin/semver.js
checksum: 5eafe6102bea2a7439897c1856362e31cc348ccf96efd455c8b5bc2c61e6f7e7b8250dc26b8828c1d76a56f818a7ee907a36ae9fb37a599d3d24609207001d60
checksum: ae47d06de28836adb9d3e25f22a92943477371292d9b665fb023fae278d345d508ca1958232af086d85e0155aee22e313e100971898bbb8d5d89b8b1d4054ca2
languageName: node
linkType: hard

"semver@npm:^7.3.5, semver@npm:^7.3.7":
version: 7.5.1
resolution: "semver@npm:7.5.1"
"semver@npm:^7.3.0, semver@npm:^7.3.4, semver@npm:^7.3.5, semver@npm:^7.3.7":
version: 7.5.4
resolution: "semver@npm:7.5.4"
dependencies:
lru-cache: ^6.0.0
bin:
semver: bin/semver.js
checksum: d16dbedad53c65b086f79524b9ef766bf38670b2395bdad5c957f824dcc566b624988013564f4812bcace3f9d405355c3635e2007396a39d1bffc71cfec4a2fc
checksum: 12d8ad952fa353b0995bf180cdac205a4068b759a140e5d3c608317098b3575ac2f1e09182206bf2eb26120e1c0ed8fb92c48c592f6099680de56bb071423ca3
languageName: node
linkType: hard

Expand Down
Loading