Skip to content

Restrict access to the metrics actuator endpoint#3106

Open
dzmitrydd wants to merge 1 commit into
developfrom
fix/3690_springboot_actuator
Open

Restrict access to the metrics actuator endpoint#3106
dzmitrydd wants to merge 1 commit into
developfrom
fix/3690_springboot_actuator

Conversation

@dzmitrydd

Copy link
Copy Markdown
Collaborator

Description:

Fixes a security finding on uui.epam.com where /actuator/metrics was publicly accessible and exposed runtime details (memory usage, uptime, etc.).
####Changes:

  1. Removed express-actuator dependency from server/package.json
  2. Replaced the full actuator middleware with a minimal /actuator/health endpoint that returns { "status": "UP" } /actuator/metrics and /actuator/info are no longer exposed

@MSt1ch MSt1ch self-requested a review June 11, 2026 15:16
@github-actions

Copy link
Copy Markdown

Generated by: track-bundle-size
Generated at: Thu, 11 Jun 2026 15:20:28 GMT
Bundle size diff (in kBytes). Not gzipped. Both CSS & JS included.
Baseline: v6.3.1 (2025-12-03)
CI Status: ok

Module Baseline Size
(v6.3.1)
Size Diff Within
Threshold
Threshold
(min - max)
templateApp 693.09 705.55 +12.47
js:+5.29
css:+7.18
🆗 623.78 - 762.39
@epam/app 5586.96 5537.34 -49.61
js:-55.25
css:+5.64
🆗 5028.26 - 6145.65
@epam/electric 5.04 5.04 0
js:0
css:0
🆗 4.53 - 5.54
@epam/promo 55.61 55.57 -0.05
js:0
css:-0.05
🆗 50.05 - 61.17
@epam/uui-extra 0.21 0.21 0
js:0
css:0
🆗 0.19 - 0.23
@epam/loveship 92.81 96.25 +3.44
js:+3.48
css:-0.04
🆗 83.53 - 102.09
@epam/uui-components 257.49 263.04 +5.54
js:+4.03
css:+1.51
🆗 231.75 - 283.25
@epam/uui-core 324.75 330.13 +5.38
js:+5.38
css:0
🆗 292.27 - 357.23
@epam/uui-db 41.63 41.72 +0.08
js:+0.08
css:0
🆗 37.47 - 45.8
@epam/uui-docs 181.03 194.75 +13.72
js:+13.72
css:+0.01
🆗 162.92 - 199.13
@epam/uui-editor 174.1 173.26 -0.84
js:-0.83
css:-0.01
🆗 156.69 - 191.51
@epam/uui-timeline 75.5 75.49 -0.01
js:0
css:0
🆗 67.95 - 83.05
@epam/uui 527.51 561.06 +33.55
js:+10.74
css:+22.81
🆗 474.76 - 580.26
new sizes (raw)

To set the sizes as a new baseline, you can copy/paste next content to the uui-build/config/bundleSizeBaseLine.json and commit the file.

{
  "version": "6.5.0",
  "timestamp": "2026-06-11",
  "sizes": {
    "templateApp": {
      "css": 264820,
      "js": 457669
    },
    "@epam/app": {
      "css": 726287,
      "js": 4943954
    },
    "@epam/electric": {
      "css": 2275,
      "js": 2883
    },
    "@epam/promo": {
      "css": 47756,
      "js": 9145
    },
    "@epam/uui-extra": {
      "css": 0,
      "js": 213
    },
    "@epam/loveship": {
      "css": 55336,
      "js": 43224
    },
    "@epam/uui-components": {
      "css": 25145,
      "js": 244200
    },
    "@epam/uui-core": {
      "css": 0,
      "js": 338056
    },
    "@epam/uui-db": {
      "css": 0,
      "js": 42718
    },
    "@epam/uui-docs": {
      "css": 2162,
      "js": 197259
    },
    "@epam/uui-editor": {
      "css": 12944,
      "js": 164475
    },
    "@epam/uui-timeline": {
      "css": 2199,
      "js": 75104
    },
    "@epam/uui": {
      "css": 222096,
      "js": 352432
    }
  }
}

Generated by: generate-components-api
CI Status: ok

Total amount of exported types/props without JSDoc comments

Amount
Types 341 (+0) 🆗
Props 220 (+0) 🆗

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant