Skip to content

fix(HNT-3493): upgrade jwks-rsa to 3.2.2 to drop vulnerable axios - #389

Draft
mmiermans wants to merge 2 commits into
mainfrom
mmiermans/HNT-3493-jwks-rsa-3
Draft

mmiermans wants to merge 2 commits into
mainfrom
mmiermans/HNT-3493-jwks-rsa-3

Conversation

@mmiermans

@mmiermans mmiermans commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Goal

Remove axios@0.21.4 (and its advisories) from admin-api's JWKS path by upgrading jwks-rsa 1.12.3 → 3.2.2.

  • getSigningKeyAsync → promise-based getSigningKey (the 2.x+ API)
  • npm audit fix for transitive advisories, including jws 3.2.3 (HMAC verification fix on the JWT path)
  • Production advisories: 42 → 21 (critical 3 → 1, high 22 → 10)

Implementation Decisions

Deployment steps

  • Confirm admin-api accepts curation tools and lambda JWTs after deploy

References

JIRA ticket:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant