diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index c855392..b416806 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -9,7 +9,9 @@ jobs: review: uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@3f746774229d41770727e2e4fd63ed5f5555a8b3 # v1.0.3 with: - # GHSA-3jxr-9vmj-r5cp (brace-expansion ReDoS): bundled transitive inside - # aws-cdk-lib (inBundle, not overridable via lockfile); adjudicated in - # .security-review/suppressions.json. Remove when aws-cdk-lib bundles >=5.0.8. - allow-ghsas: GHSA-3jxr-9vmj-r5cp + # GHSA-rgw5-rvv9-x895 (brace-expansion DoS bypass of CVE-2026-14257): + # bundled transitive inside aws-cdk-lib (inBundle, not overridable via + # lockfile); adjudicated in .security-review/suppressions.json. + # aws-cdk-lib 2.263.0 bundles 5.0.8 (fixes GHSA-3jxr-9vmj-r5cp). Remove + # when aws-cdk-lib bundles >=5.0.9. + allow-ghsas: GHSA-rgw5-rvv9-x895 diff --git a/.security-review/suppressions.json b/.security-review/suppressions.json index 75b7b76..41436b3 100644 --- a/.security-review/suppressions.json +++ b/.security-review/suppressions.json @@ -2,7 +2,7 @@ "suppressions": [ { "id": "npmaudit-brace-expansion", - "justification": "Bundled transitive of aws-cdk-lib (node_modules/aws-cdk-lib/node_modules/brace-expansion, inBundle: true). aws-cdk-lib 2.262.1 (latest as of 2026-07-28) still bundles the vulnerable range (GHSA-3jxr-9vmj-r5cp); npm cannot override bundled deps, so no fix is available until upstream rebundles >=5.0.8. Exposure is synth-time only: aws-cdk-lib runs during cdk synth in CI on trusted repo input, and this stack deploys an EC2 syslog host with no Node.js runtime artifacts. This entry also adjudicates the allow-ghsas exception in .github/workflows/dependency-review.yml, which would otherwise block Dependabot PRs that move the bundled copy (e.g. #15, 5.0.6 -> 5.0.7). Remove this entry AND the allow-ghsas input on the first aws-cdk-lib bump that bundles >=5.0.8 / clears npm audit." + "justification": "Bundled transitive of aws-cdk-lib (node_modules/aws-cdk-lib/node_modules/brace-expansion, inBundle: true). aws-cdk-lib 2.263.0 bundles brace-expansion 5.0.8, which clears GHSA-3jxr-9vmj-r5cp / CVE-2026-14257 but remains in range for GHSA-rgw5-rvv9-x895 / CVE-2026-69152 (fixed in >=5.0.9). npm cannot override bundled deps, so no fix is available until upstream rebundles >=5.0.9. Exposure is synth-time only: aws-cdk-lib runs during cdk synth in CI on trusted repo input, and this stack deploys an EC2 syslog host with no Node.js runtime artifacts. This entry also adjudicates the allow-ghsas exception in .github/workflows/dependency-review.yml. Remove this entry AND the allow-ghsas input on the first aws-cdk-lib bump that bundles >=5.0.9 / clears npm audit." } ] } diff --git a/package-lock.json b/package-lock.json index f463632..abb1876 100644 --- a/package-lock.json +++ b/package-lock.json @@ -8,15 +8,15 @@ "name": "syslog-server", "version": "1.0.0", "dependencies": { - "aws-cdk-lib": "2.262.1", - "constructs": "^10.7.1" + "aws-cdk-lib": "2.263.0", + "constructs": "^10.7.2" }, "bin": { "app": "bin/app.js" }, "devDependencies": { "@types/node": "^26.1.2", - "aws-cdk": "^2.1133.0", + "aws-cdk": "^2.1134.0", "source-map-support": "^0.5.21", "tsx": "4.23.1", "typescript": "~7.0.2" @@ -863,9 +863,9 @@ } }, "node_modules/aws-cdk": { - "version": "2.1133.0", - "resolved": "https://registry.npmjs.org/aws-cdk/-/aws-cdk-2.1133.0.tgz", - "integrity": "sha512-DGlCBwqxSHTe1u/IoT5WV+Bbd2K3UhwFHsdMqb2nQa1fkJmaQgoNFu0It+p3HxyMWeW+gKsVzT5KcjQPQ6Kzuw==", + "version": "2.1134.0", + "resolved": "https://registry.npmjs.org/aws-cdk/-/aws-cdk-2.1134.0.tgz", + "integrity": "sha512-Fy/g+gdpMpkhAAoCNlZtX0s4mD7q58bHlDV6QfbnTeifmQ5cEge26c5rB+U4qKB/bDudxNuJjQk/mSSk0ysnug==", "dev": true, "license": "Apache-2.0", "bin": { @@ -876,9 +876,9 @@ } }, "node_modules/aws-cdk-lib": { - "version": "2.262.1", - "resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.262.1.tgz", - "integrity": "sha512-B6YP4r6ojUZCDhl+qBu/CrWzcipR8sIgshcqYvgw013sghPXmVkYdJ3yuI9+DKML3YLSjQrHy1nGJs+Nqq7JCg==", + "version": "2.263.0", + "resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.263.0.tgz", + "integrity": "sha512-cXC9wnOr+LknMee9x0kYwofgVs8aN8eBKsbzcE90sDUtpLTgWG2Bd+9koqxBKPeIU8kig/GGBFwJ69Wr+hLKDg==", "bundleDependencies": [ "@aws/cloudformation-validate", "@balena/dockerignore", @@ -899,7 +899,7 @@ "@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2", "@aws-cdk/cloud-assembly-api": "^2.2.6", "@aws-cdk/cloud-assembly-schema": "^54.11.0", - "@aws/cloudformation-validate": "1.5.1-beta", + "@aws/cloudformation-validate": "1.6.0-beta", "@balena/dockerignore": "^1.0.2", "case": "1.6.3", "fs-extra": "^11.3.6", @@ -934,7 +934,7 @@ } }, "node_modules/aws-cdk-lib/node_modules/@aws/cloudformation-validate": { - "version": "1.5.1-beta", + "version": "1.6.0-beta", "inBundle": true, "license": "Apache-2.0", "engines": { @@ -955,14 +955,14 @@ } }, "node_modules/aws-cdk-lib/node_modules/brace-expansion": { - "version": "5.0.7", + "version": "5.0.8", "inBundle": true, "license": "MIT", "dependencies": { "balanced-match": "^4.0.2" }, "engines": { - "node": "18 || 20 || >=22" + "node": "20 || >=22" } }, "node_modules/aws-cdk-lib/node_modules/case": { @@ -1094,9 +1094,9 @@ "license": "MIT" }, "node_modules/constructs": { - "version": "10.7.1", - "resolved": "https://registry.npmjs.org/constructs/-/constructs-10.7.1.tgz", - "integrity": "sha512-ulK25Sg2Nv1jW+A9VeV7fu9GFN9KdVTNWdXMoapNRwqkQzSdToro/Tttk3Ak5BGI80NRA/d2nSzKnoZ27LizLw==", + "version": "10.7.2", + "resolved": "https://registry.npmjs.org/constructs/-/constructs-10.7.2.tgz", + "integrity": "sha512-vA7JOqvO/xwq2HBCuq3qc6V2R9mHZCxJ8HPoucUcUWJY88YULe7bzMcsdBy27/gJJIphZi73U1oIXDY2Eqg6nA==", "license": "Apache-2.0" }, "node_modules/esbuild": { diff --git a/package.json b/package.json index e5b199e..e21e423 100644 --- a/package.json +++ b/package.json @@ -13,13 +13,13 @@ }, "devDependencies": { "@types/node": "^26.1.2", - "aws-cdk": "^2.1133.0", + "aws-cdk": "^2.1134.0", "source-map-support": "^0.5.21", "tsx": "4.23.1", "typescript": "~7.0.2" }, "dependencies": { - "aws-cdk-lib": "2.262.1", - "constructs": "^10.7.1" + "aws-cdk-lib": "2.263.0", + "constructs": "^10.7.2" } }