mirror of
https://github.com/Sea-Haven-Industries/seahaven-door-unlock-api.git
synced 2026-09-30 09:23:11 +00:00
aws-cdk-lib 2.261.0 bundles brace-expansion 5.0.6, which is vulnerable to CVE-2026-13149 (GHSA-3jxr-9vmj-r5cp), an exponential-time DoS in expand(). This was the only path pulling the vulnerable package into the tree. 2.262.0 vendors the patched 5.0.7, resolving Dependabot alert 7. Because brace-expansion arrives bundled inside the aws-cdk-lib tarball rather than resolved by npm, the aws-cdk-lib bump is the only way to move it. Signed-off-by: Adam Moussa <adam@seahavenind.com>
28 lines
599 B
JSON
28 lines
599 B
JSON
{
|
|
"name": "seahaven-door-unlock",
|
|
"version": "1.0.0",
|
|
"bin": {
|
|
"app": "bin/app.js"
|
|
},
|
|
"scripts": {
|
|
"build": "tsc",
|
|
"cdk": "cdk",
|
|
"synth": "cdk synth",
|
|
"deploy": "cdk deploy",
|
|
"diff": "cdk diff"
|
|
},
|
|
"devDependencies": {
|
|
"@aws-sdk/client-ssm": "^3.1091.0",
|
|
"@types/node": "^24.13.3",
|
|
"@types/source-map-support": "^0.5.10",
|
|
"aws-cdk": "^2.1132.0",
|
|
"esbuild": "^0.28.1",
|
|
"source-map-support": "^0.5.21",
|
|
"tsx": "4.23.1",
|
|
"typescript": "~7.0.2"
|
|
},
|
|
"dependencies": {
|
|
"aws-cdk-lib": "2.262.0",
|
|
"constructs": "^10.7.1"
|
|
}
|
|
}
|