chore(deps): bump aws-cdk and allowlist brace-expansion GHSA-rgw5 (PLAT-83) (#23)

* chore(deps): bump the minor-and-patch group with 3 updates

Bumps the minor-and-patch group with 3 updates: [aws-cdk-lib](https://github.com/aws/aws-cdk/tree/HEAD/packages/aws-cdk-lib), [constructs](https://github.com/aws/constructs) and [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk).


Updates `aws-cdk-lib` from 2.262.1 to 2.263.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](https://github.com/aws/aws-cdk/commits/v2.263.0/packages/aws-cdk-lib)

Updates `constructs` from 10.7.1 to 10.7.2
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.7.1...v10.7.2)

Updates `aws-cdk` from 2.1133.0 to 2.1134.0
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1134.0/packages/aws-cdk)

---
updated-dependencies:
- dependency-name: aws-cdk-lib
  dependency-version: 2.263.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: constructs
  dependency-version: 10.7.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1134.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* chore(security): allowlist brace-expansion GHSA-rgw5-rvv9-x895

Swap the dependency-review exception to the follow-on advisory that
still affects aws-cdk-lib's bundled 5.0.8, and refresh the suppression
until upstream rebundles >=5.0.9.

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This commit is contained in:
Adam Moussa 2026-08-05 19:05:49 -04:00 • committed by GitHub
parent 2829cad07a
commit 34824a24d6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
4 changed files with 26 additions and 24 deletions

View file

@ -9,7 +9,9 @@ jobs:
review: review:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@3f746774229d41770727e2e4fd63ed5f5555a8b3 # v1.0.3 uses: Sea-Haven-Industries/.github/.github/workflows/callable-dependency-review.yaml@3f746774229d41770727e2e4fd63ed5f5555a8b3 # v1.0.3
with: with:
# GHSA-3jxr-9vmj-r5cp (brace-expansion ReDoS): bundled transitive inside # GHSA-rgw5-rvv9-x895 (brace-expansion DoS bypass of CVE-2026-14257):
# aws-cdk-lib (inBundle, not overridable via lockfile); adjudicated in # bundled transitive inside aws-cdk-lib (inBundle, not overridable via
# .security-review/suppressions.json. Remove when aws-cdk-lib bundles >=5.0.8. # lockfile); adjudicated in .security-review/suppressions.json.
allow-ghsas: GHSA-3jxr-9vmj-r5cp # aws-cdk-lib 2.263.0 bundles 5.0.8 (fixes GHSA-3jxr-9vmj-r5cp). Remove
# when aws-cdk-lib bundles >=5.0.9.
allow-ghsas: GHSA-rgw5-rvv9-x895

View file

@ -2,7 +2,7 @@
"suppressions": [ "suppressions": [
{ {
"id": "npmaudit-brace-expansion", "id": "npmaudit-brace-expansion",
"justification": "Bundled transitive of aws-cdk-lib (node_modules/aws-cdk-lib/node_modules/brace-expansion, inBundle: true). aws-cdk-lib 2.262.1 (latest as of 2026-07-28) still bundles the vulnerable range (GHSA-3jxr-9vmj-r5cp); npm cannot override bundled deps, so no fix is available until upstream rebundles >=5.0.8. Exposure is synth-time only: aws-cdk-lib runs during cdk synth in CI on trusted repo input, and this stack deploys an EC2 syslog host with no Node.js runtime artifacts. This entry also adjudicates the allow-ghsas exception in .github/workflows/dependency-review.yml, which would otherwise block Dependabot PRs that move the bundled copy (e.g. #15, 5.0.6 -> 5.0.7). Remove this entry AND the allow-ghsas input on the first aws-cdk-lib bump that bundles >=5.0.8 / clears npm audit." "justification": "Bundled transitive of aws-cdk-lib (node_modules/aws-cdk-lib/node_modules/brace-expansion, inBundle: true). aws-cdk-lib 2.263.0 bundles brace-expansion 5.0.8, which clears GHSA-3jxr-9vmj-r5cp / CVE-2026-14257 but remains in range for GHSA-rgw5-rvv9-x895 / CVE-2026-69152 (fixed in >=5.0.9). npm cannot override bundled deps, so no fix is available until upstream rebundles >=5.0.9. Exposure is synth-time only: aws-cdk-lib runs during cdk synth in CI on trusted repo input, and this stack deploys an EC2 syslog host with no Node.js runtime artifacts. This entry also adjudicates the allow-ghsas exception in .github/workflows/dependency-review.yml. Remove this entry AND the allow-ghsas input on the first aws-cdk-lib bump that bundles >=5.0.9 / clears npm audit."
} }
] ]
} }

32
package-lock.json generated
View file

@ -8,15 +8,15 @@
"name": "syslog-server", "name": "syslog-server",
"version": "1.0.0", "version": "1.0.0",
"dependencies": { "dependencies": {
"aws-cdk-lib": "2.262.1", "aws-cdk-lib": "2.263.0",
"constructs": "^10.7.1" "constructs": "^10.7.2"
}, },
"bin": { "bin": {
"app": "bin/app.js" "app": "bin/app.js"
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^26.1.2", "@types/node": "^26.1.2",
"aws-cdk": "^2.1133.0", "aws-cdk": "^2.1134.0",
"source-map-support": "^0.5.21", "source-map-support": "^0.5.21",
"tsx": "4.23.1", "tsx": "4.23.1",
"typescript": "~7.0.2" "typescript": "~7.0.2"
@ -863,9 +863,9 @@
} }
}, },
"node_modules/aws-cdk": { "node_modules/aws-cdk": {
"version": "2.1133.0", "version": "2.1134.0",
"resolved": "https://registry.npmjs.org/aws-cdk/-/aws-cdk-2.1133.0.tgz", "resolved": "https://registry.npmjs.org/aws-cdk/-/aws-cdk-2.1134.0.tgz",
"integrity": "sha512-DGlCBwqxSHTe1u/IoT5WV+Bbd2K3UhwFHsdMqb2nQa1fkJmaQgoNFu0It+p3HxyMWeW+gKsVzT5KcjQPQ6Kzuw==", "integrity": "sha512-Fy/g+gdpMpkhAAoCNlZtX0s4mD7q58bHlDV6QfbnTeifmQ5cEge26c5rB+U4qKB/bDudxNuJjQk/mSSk0ysnug==",
"dev": true, "dev": true,
"license": "Apache-2.0", "license": "Apache-2.0",
"bin": { "bin": {
@ -876,9 +876,9 @@
} }
}, },
"node_modules/aws-cdk-lib": { "node_modules/aws-cdk-lib": {
"version": "2.262.1", "version": "2.263.0",
"resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.262.1.tgz", "resolved": "https://registry.npmjs.org/aws-cdk-lib/-/aws-cdk-lib-2.263.0.tgz",
"integrity": "sha512-B6YP4r6ojUZCDhl+qBu/CrWzcipR8sIgshcqYvgw013sghPXmVkYdJ3yuI9+DKML3YLSjQrHy1nGJs+Nqq7JCg==", "integrity": "sha512-cXC9wnOr+LknMee9x0kYwofgVs8aN8eBKsbzcE90sDUtpLTgWG2Bd+9koqxBKPeIU8kig/GGBFwJ69Wr+hLKDg==",
"bundleDependencies": [ "bundleDependencies": [
"@aws/cloudformation-validate", "@aws/cloudformation-validate",
"@balena/dockerignore", "@balena/dockerignore",
@ -899,7 +899,7 @@
"@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2", "@aws-cdk/asset-node-proxy-agent-v6": "^2.1.2",
"@aws-cdk/cloud-assembly-api": "^2.2.6", "@aws-cdk/cloud-assembly-api": "^2.2.6",
"@aws-cdk/cloud-assembly-schema": "^54.11.0", "@aws-cdk/cloud-assembly-schema": "^54.11.0",
"@aws/cloudformation-validate": "1.5.1-beta", "@aws/cloudformation-validate": "1.6.0-beta",
"@balena/dockerignore": "^1.0.2", "@balena/dockerignore": "^1.0.2",
"case": "1.6.3", "case": "1.6.3",
"fs-extra": "^11.3.6", "fs-extra": "^11.3.6",
@ -934,7 +934,7 @@
} }
}, },
"node_modules/aws-cdk-lib/node_modules/@aws/cloudformation-validate": { "node_modules/aws-cdk-lib/node_modules/@aws/cloudformation-validate": {
"version": "1.5.1-beta", "version": "1.6.0-beta",
"inBundle": true, "inBundle": true,
"license": "Apache-2.0", "license": "Apache-2.0",
"engines": { "engines": {
@ -955,14 +955,14 @@
} }
}, },
"node_modules/aws-cdk-lib/node_modules/brace-expansion": { "node_modules/aws-cdk-lib/node_modules/brace-expansion": {
"version": "5.0.7", "version": "5.0.8",
"inBundle": true, "inBundle": true,
"license": "MIT", "license": "MIT",
"dependencies": { "dependencies": {
"balanced-match": "^4.0.2" "balanced-match": "^4.0.2"
}, },
"engines": { "engines": {
"node": "18 || 20 || >=22" "node": "20 || >=22"
} }
}, },
"node_modules/aws-cdk-lib/node_modules/case": { "node_modules/aws-cdk-lib/node_modules/case": {
@ -1094,9 +1094,9 @@
"license": "MIT" "license": "MIT"
}, },
"node_modules/constructs": { "node_modules/constructs": {
"version": "10.7.1", "version": "10.7.2",
"resolved": "https://registry.npmjs.org/constructs/-/constructs-10.7.1.tgz", "resolved": "https://registry.npmjs.org/constructs/-/constructs-10.7.2.tgz",
"integrity": "sha512-ulK25Sg2Nv1jW+A9VeV7fu9GFN9KdVTNWdXMoapNRwqkQzSdToro/Tttk3Ak5BGI80NRA/d2nSzKnoZ27LizLw==", "integrity": "sha512-vA7JOqvO/xwq2HBCuq3qc6V2R9mHZCxJ8HPoucUcUWJY88YULe7bzMcsdBy27/gJJIphZi73U1oIXDY2Eqg6nA==",
"license": "Apache-2.0" "license": "Apache-2.0"
}, },
"node_modules/esbuild": { "node_modules/esbuild": {

View file

@ -13,13 +13,13 @@
}, },
"devDependencies": { "devDependencies": {
"@types/node": "^26.1.2", "@types/node": "^26.1.2",
"aws-cdk": "^2.1133.0", "aws-cdk": "^2.1134.0",
"source-map-support": "^0.5.21", "source-map-support": "^0.5.21",
"tsx": "4.23.1", "tsx": "4.23.1",
"typescript": "~7.0.2" "typescript": "~7.0.2"
}, },
"dependencies": { "dependencies": {
"aws-cdk-lib": "2.262.1", "aws-cdk-lib": "2.263.0",
"constructs": "^10.7.1" "constructs": "^10.7.2"
} }
} }