Skip to content

fix(deps): vuln minor: aws-cdk-lib · patch: brace-expansion, fast-uri [examples/step-functions-typescript-stack/package.json] - #738

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/step-functions-typescript-stack/2-1791201757
Open

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/step-functions-typescript-stack/2-1791201757

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

⚠️ One or more lockfile regeneration steps failed. The updates listed below may not all have been applied — verify against the diff before merging. Package counts and totals reflect what was attempted, not what landed. See the engraver logs for details.

Summary: High-severity security update — 3 packages upgraded (MINOR changes included)

Manifests changed:

  • examples/step-functions-typescript-stack/package.json (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
brace-expansion 1.1.18 1.1.21 patch Transitive 4 HIGH, 2 MEDIUM
aws-cdk-lib 2.189.1 2.272.0 minor Direct 4 HIGH, 2 LOW
fast-uri 3.1.7 3.1.8 patch Transitive 2 MEDIUM

Security Details

🚨 Critical & High Severity (8 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
aws-cdk-lib CVE-2026-11417 HIGH OS Command Injection in NodejsFunction Bundling in aws-cdk-lib 2.189.1 - -
aws-cdk-lib GHSA-vcrf-j523-4mrf HIGH aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling 2.189.1 2.260.0 -
aws-cdk-lib CVE-2026-13760 HIGH OS Command Injection in aws-cdk-lib Docker Bundling 2.189.1 - -
aws-cdk-lib GHSA-999r-qq7v-r334 HIGH aws-cdk-lib: OS Command Injection in NodejsFunction Bundling 2.189.1 2.246.0 -
brace-expansion GHSA-6j4f-fj2g-mc7p HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 1.1.18 5.0.10 -
brace-expansion CVE-2026-102278 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 1.1.18 - -
brace-expansion GHSA-qhr7-859c-m2p7 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 1.1.18 5.0.11 -
brace-expansion CVE-2026-102276 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 1.1.18 - -
ℹ️ Other Vulnerabilities (6)
Package CVE Severity Summary Unsafe Version Fixed In Case
brace-expansion GHSA-q2hr-2g5m-vwhr MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 1.1.18 5.0.12 -
brace-expansion CVE-2026-102277 MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 1.1.18 - -
fast-uri GHSA-hrr3-gc8f-f4qj MODERATE fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets 3.1.7 2.4.7 -
fast-uri CVE-2026-86472 MODERATE fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets 3.1.7 - -
aws-cdk-lib GO-2026-6093 LOW AWS CDK CodeBuild S3 Log Encryption Boolean Inversion in github.com/aws/aws-cdk-go/awscdk 2.189.1 - -
aws-cdk-lib GHSA-464c-974j-9xm6 LOW AWS CDK CodeBuild S3 Log Encryption Boolean Inversion 2.189.1 2.253.0 -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

…mples/step-functions-typescript-stack/package.json]
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor Author

Auto-rebase failed

Lockfile regeneration failed during rebase onto main. Your branch was not updated. You may need to rebase and regenerate lockfiles manually.

Error details

child workflow execution error (type: engraver.Engraver_AllManagersWorkflow, workflowID: 01a11191-0166-78a5-9365-b749dfc42fe1_69, runID: 01a11191-2232-70c7-b5b3-a8fe5d91fdfb, initiatedEventID: 69, startedEventID: 70): custom action(s) failed and produced no changes: [registry.ddbuild.io/images/engraver-custom-action:update-yarn-lockfile]


Auto-Rebase · Add no-auto-rebase to opt out

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants