Repository navigation
fix: bump bundled brace-expansion to 5.0.12 - #38929
Conversation
|
Exemption Request Please review whether this lockfile-only third-party dependency update can be exempted from the construct unit-test and cloud integration-snapshot requirements. The diff updates only the version, registry URL and integrity for Focused local checks installed minimatch 10.2.5 from the updated lockfile with Yarn 1.22.22 A cloud deployment snapshot would not exercise the affected brace parser or prove which dependency version is bundled. If additional repository-level dependency tests are preferred, please advise on the appropriate existing test location. |
…visories (#431) The Security workflow went red on main at 50d86cd, a tree identical to PR #429's head, whose Security run passed hours earlier. Advisories published on 2026-09-29 reached the Trivy and npm databases in between. - Debian DSA-6531-1 (CVE-2026-75804, CVE-2026-84782) fixes OpenSSL in 3.5.7-1~deb13u3. The six service images and the dev image still had deb13u2 from the cached upgrade layer. APT_SECURITY_EPOCH moves to 2026-09-30 in the seven Debian Dockerfiles, which rebuilds that layer. - npm audit: GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 and GHSA-q2hr-2g5m-vwhr affect the brace-expansion 5.0.9 that aws-cdk-lib bundles, which the root graph reaches only through cdk-dia. The latest aws-cdk-lib, 2.271.0, still bundles 5.0.9 (the fix is pending in aws/aws-cdk#38929), and overrides cannot reach a bundled copy. The three get exact .npm-audit-ignore entries until 2026-10-30. cdk-dia never loads aws-cdk-lib at runtime. - Trivy on the dev image: CVE-2026-102276 and CVE-2026-102278 affect the brace-expansion 5.0.7 that npm vendors, and CVE-2026-19534 the undici 6.27.0 that npm vendors for node-gyp, which uses it only for fetch. The latest npm, 12.1.0, still vendors 5.0.9 and 6.28.0, so the three join the other npm-vendored .trivyignore entries and expire with them on 2026-10-22. Verified locally: the rebuilt health-monitor and dev images carry libssl3t64 3.5.7-1~deb13u3 and scan clean with the CI's Trivy v0.74.0, flags and ignore file. Without the ignore file, the dev image reports only the existing suppressions plus the three new IDs. The CI npm audit gate passes on both package graphs.
|
Thank you for preparing this fix. We independently verified the official aws-cdk-lib 2.271.0 npm tarball against its published SHA-512 integrity and found bundled brace-expansion 5.0.9. Our pinned 2.268.0 dependency is also affected, and our high-severity audit gate is blocking merges. We are keeping the gate in place rather than suppressing the advisories. Could a maintainer please review the lockfile-only update and exemption request, and advise whether the fix can be prioritized for the next official release? If a separate tracking issue is required, please let us know. We will verify the bundled code in the published artifact and a clean installation before considering the issue resolved. Thank you for your help. |
…aws-cdk-lib aws-cdk-lib bundles brace-expansion 5.0.9 (GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr). No aws-cdk-lib release ships a fixed copy (2.272.0 checked), and npm overrides cannot rewrite a bundled dependency, so the repository cannot remove it. Upstream: aws/aws-cdk#38929 and aws/aws-cdk#38932. The maintainer approved accepting the risk until 2026-10-30. Every entry expires then. Entries, keyed the way each scanner reports the finding: - grype, in .ash/.ash.yaml: <GHSA>-brace-expansion on deploy/cdk/package-lock.json - npm-audit, in .ash/.ash.yaml: <GHSA> on node_modules/aws-cdk-lib/brace-expansion/package.json. That is the path npm-audit gives only the bundled copy. - trivy-repo, in .ash/.ash_community_plugins.yaml: the CVE aliases on deploy/cdk/package-lock.json Known limit: ASH matches on rule id, path and line range only. The grype and trivy entries therefore cover these three advisories for any brace-expansion copy in deploy/cdk/package-lock.json, not only the bundled one. Today the bundled copy is the only vulnerable one left there. The npm-audit entry has no such gap. These entries should be tightened once ASH can match on package and version.
…ories (#686) * fix(deps): move pyjwt and brace-expansion off versions with new advisories Advisories published 2026-09-29 made main's own scan fail. Every open PR inherits the failure because none of their diffs touch these packages. pyjwt 2.13.0 -> 2.15.1 in uv.lock. It is transitive via mcp[crypto], whose range (>=2.10.1) already allows the fix, so this is a lock refresh plus a >=2.14 floor in pyproject.toml, matching how cryptography is floored. That clears ten advisories, GHSA-ffc3-869f-jxw9 (critical) among them; 2.14.0 is the first patched release for all ten. brace-expansion, via `npm update brace-expansion` in each tree. The parent ranges already allowed the patched releases, so no override was needed: deploy/cdk: 1.1.18 -> 1.1.21 deploy/cdk-constructs: 5.0.9 -> 5.0.12, test-exclude's copy 2.1.4 -> 2.1.7 That clears GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 and GHSA-q2hr-2g5m-vwhr for those copies. npm also rewrote some lockfile metadata: it added `engines` from package.json and corrected `dev` flags on five deploy/cdk entries whose only dependents are dev dependencies. Not fixed: the brace-expansion 5.0.9 that aws-cdk-lib bundles in both trees. Every aws-cdk-lib release through 2.272.0 (the current latest) ships 5.0.9, and npm `overrides` cannot rewrite a bundled dependency (tested). The upstream fix is aws/aws-cdk#38929. * chore(config): time-boxed suppression for brace-expansion bundled in aws-cdk-lib aws-cdk-lib bundles brace-expansion 5.0.9 (GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr). No aws-cdk-lib release ships a fixed copy (2.272.0 checked), and npm overrides cannot rewrite a bundled dependency, so the repository cannot remove it. Upstream: aws/aws-cdk#38929 and aws/aws-cdk#38932. The maintainer approved accepting the risk until 2026-10-30. Every entry expires then. Entries, keyed the way each scanner reports the finding: - grype, in .ash/.ash.yaml: <GHSA>-brace-expansion on deploy/cdk/package-lock.json - npm-audit, in .ash/.ash.yaml: <GHSA> on node_modules/aws-cdk-lib/brace-expansion/package.json. That is the path npm-audit gives only the bundled copy. - trivy-repo, in .ash/.ash_community_plugins.yaml: the CVE aliases on deploy/cdk/package-lock.json Known limit: ASH matches on rule id, path and line range only. The grype and trivy entries therefore cover these three advisories for any brace-expansion copy in deploy/cdk/package-lock.json, not only the bundled one. Today the bundled copy is the only vulnerable one left there. The npm-audit entry has no such gap. These entries should be tightened once ASH can match on package and version.
Home Screen web app (following Portfolio/Elytra): - Web manifest, apple-touch-icon, status-bar and viewport-fit meta tags - Generated icons + og-default.png via `npm run generate:icons` (sharp) - theme-color tracks the resolved theme background - Safe-area insets for navbar, footer, toasts, timeline, sheet and map overlays Dependencies (package.json only; lockfiles regenerated from a clean install): - Client: maplibre-gl ^6.11.2, axios ^1.20.0, react-router-dom ^7.18.4, vite ^7.3.6 -> npm audit: 0 vulnerabilities - maplibre v6 is ESM-only: namespace imports, and the worker is registered once in src/lib/map/maplibre.ts (Vite ?worker&url) - Server: aws-cdk-lib ^2.272.0. Its bundled brace-expansion@5.0.9 is still flagged; waiting on aws/aws-cdk#38929 - Python: cryptography 50.0.2; fastapi 0.142.2 + pydantic 2.13.5 (pulls a patched starlette) -> pip-audit: no known vulnerabilities
|
Tested the effect of this bump on a downstream CDK app (aws-cdk-lib 2.272.0, aws-cdk CLI 2.1144.0, Node 26.3.0, npm).
|
|
@rix0rrr Thanks for approving this PR. Could you also take another look at the GitHub workflows included in this PR? As far as I know, they still require approval because this is @burger66leo's first PR in this repository.
|
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
Merge Queue Status
This pull request spent 16 minutes 36 seconds in the queue, with no time running CI. ReasonPull request #38929 has been dequeued Queue conditions are not satisfied:
HintYou should look at the reason for the failure and decide if the pull request needs to be fixed or if you want to requeue it. Requeued — the merge queue status continues in this comment ↓. |
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
Merge Queue Status
This pull request spent 43 minutes 34 seconds in the queue, with no time running CI. ReasonThe pull request can't be updated
HintYou should update or rebase your pull request manually. If you do, this pull request will automatically be requeued once the queue conditions match again. Tick the box to put this pull request back in the merge queue (same as
|
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
Merge Queue Status
This pull request spent 59 minutes 18 seconds in the queue, including 37 minutes 35 seconds running CI. Required conditions to merge
|
☑️ This pull request is already queued |
|
Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork). |
|
Comments on closed issues and PRs are hard for our team to see. |
Issue # (if applicable)
Fixes #38932
Follow-up to the bundled dependency update in #38520. This updates an already publicly disclosed third-party dependency; no new vulnerability is disclosed here.
Reason for this change
The published
aws-cdk-lib@2.271.0bundlesbrace-expansion@5.0.9throughminimatch@10.2.5. Thebrace-expansion@^5.0.5entry in the current root lockfile also resolves to5.0.9.That version is affected by these published advisories:
Consumer-side npm overrides and
npm audit fixcannot replace the copy shipped inside the CDK bundle. Updating the source lockfile allows subsequent official builds to bundle the patched dependency.Description of changes
Update only the
brace-expansion@^5.0.5lockfile entry from5.0.9to5.0.12, including the npm registry tarball URL, SHA-1 and SHA-512 integrity. Metadata was read from the official npm registry. The dependency remains within the existing semver range;balanced-match@^4.0.2is unchanged. No overrides, audit exceptions, public APIs or construct behavior are added.This follows the same lockfile-only approach used in #38520. Other brace-expansion major-version entries in the monorepo are outside this bundled 5.x dependency update.
Describe any new or updated permissions being added
None.
Description of how you validated changes
git diff --checkpasses.minimatch@10.2.5, copied the updated rootyarn.lockand installed using Yarn 1.22.22 with--frozen-lockfile --ignore-scripts --ignore-engines. Verified that the installed brace-expansion version is5.0.12.npm audit --jsonafter creating its npm lockfile.These are focused dependency checks, not a full monorepo build or a rebuilt
aws-cdk-libdistribution. Full build, package and repository tests have not been run locally and remain for upstream CI. No AWS resources were deployed. No construct source or cloud topology is changed, so no cloud integration snapshot is added.Checklist
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license