seahaven-door-unlock-api/package.json
Adam Moussa 164c9e79cc
build(deps): bump aws-cdk-lib to 2.262.0 to patch brace-expansion
aws-cdk-lib 2.261.0 bundles brace-expansion 5.0.6, which is vulnerable to CVE-2026-13149 (GHSA-3jxr-9vmj-r5cp), an exponential-time DoS in expand(). This was the only path pulling the vulnerable package into the tree. 2.262.0 vendors the patched 5.0.7, resolving Dependabot alert 7.

Because brace-expansion arrives bundled inside the aws-cdk-lib tarball rather than resolved by npm, the aws-cdk-lib bump is the only way to move it.

Signed-off-by: Adam Moussa <adam@seahavenind.com>
2026-07-23 16:08:17 -04:00

28 lines
599 B
JSON

{
"name": "seahaven-door-unlock",
"version": "1.0.0",
"bin": {
"app": "bin/app.js"
},
"scripts": {
"build": "tsc",
"cdk": "cdk",
"synth": "cdk synth",
"deploy": "cdk deploy",
"diff": "cdk diff"
},
"devDependencies": {
"@aws-sdk/client-ssm": "^3.1091.0",
"@types/node": "^24.13.3",
"@types/source-map-support": "^0.5.10",
"aws-cdk": "^2.1132.0",
"esbuild": "^0.28.1",
"source-map-support": "^0.5.21",
"tsx": "4.23.1",
"typescript": "~7.0.2"
},
"dependencies": {
"aws-cdk-lib": "2.262.0",
"constructs": "^10.7.1"
}
}