chore(security): suppress npmaudit-brace-expansion (bundled in latest aws-cdk-lib, synth-time only)
This commit is contained in:
parent
1cb9bb9b4d
commit
7dad128d1f
1 changed files with 8 additions and 0 deletions
8
.security-review/suppressions.json
Normal file
8
.security-review/suppressions.json
Normal file
|
|
@ -0,0 +1,8 @@
|
|||
{
|
||||
"suppressions": [
|
||||
{
|
||||
"id": "npmaudit-brace-expansion",
|
||||
"justification": "Bundled transitive of aws-cdk-lib (node_modules/aws-cdk-lib/node_modules/brace-expansion). The latest aws-cdk-lib release (2.261.0 as of 2026-07-21) still ships the vulnerable range; npm cannot override bundled deps, so no fix is available until upstream rebundles (GHSA-3jxr-9vmj-r5cp). Exposure is synth-time only: aws-cdk-lib runs during cdk synth in CI on trusted repo input, never in the deployed Lambda/socket-mode runtime, and the ReDoS requires attacker-controlled brace patterns. Revisit/remove on the next aws-cdk-lib bump that clears npm audit."
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in a new issue