Skip to content

fix: bump bundled brace-expansion to 5.0.12 - #38929

Merged
mergify[bot] merged 3 commits into
aws:mainfrom
burger66leo:fix/bundled-brace-expansion-5-0-12
Oct 6, 2026
Merged

mergify[bot] merged 3 commits into
aws:mainfrom
burger66leo:fix/bundled-brace-expansion-5-0-12

Conversation

@burger66leo

@burger66leo burger66leo commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Issue # (if applicable)

Fixes #38932

Follow-up to the bundled dependency update in #38520. This updates an already publicly disclosed third-party dependency; no new vulnerability is disclosed here.

Reason for this change

The published aws-cdk-lib@2.271.0 bundles brace-expansion@5.0.9 through minimatch@10.2.5. The brace-expansion@^5.0.5 entry in the current root lockfile also resolves to 5.0.9.

That version is affected by these published advisories:

Consumer-side npm overrides and npm audit fix cannot replace the copy shipped inside the CDK bundle. Updating the source lockfile allows subsequent official builds to bundle the patched dependency.

Description of changes

Update only the brace-expansion@^5.0.5 lockfile entry from 5.0.9 to 5.0.12, including the npm registry tarball URL, SHA-1 and SHA-512 integrity. Metadata was read from the official npm registry. The dependency remains within the existing semver range; balanced-match@^4.0.2 is unchanged. No overrides, audit exceptions, public APIs or construct behavior are added.

This follows the same lockfile-only approach used in #38520. Other brace-expansion major-version entries in the monorepo are outside this bundled 5.x dependency update.

Describe any new or updated permissions being added

None.

Description of how you validated changes

  • git diff --check passes.
  • In an isolated dependency fixture with minimatch@10.2.5, copied the updated root yarn.lock and installed using Yarn 1.22.22 with --frozen-lockfile --ignore-scripts --ignore-engines. Verified that the installed brace-expansion version is 5.0.12.
  • Verified ordinary brace alternatives, numeric ranges, and positive/negative minimatch matches.
  • Exercised the published comma-recursion, deeply nested group and rewrite-loop reproduction shapes against the patched dependency. Each completed without a stack overflow; the rewrite case used 32,000 trailing braces and completed in approximately 20 ms on this machine.
  • The isolated installed dependency graph reports zero vulnerabilities via npm audit --json after creating its npm lockfile.

These are focused dependency checks, not a full monorepo build or a rebuilt aws-cdk-lib distribution. Full build, package and repository tests have not been run locally and remain for upstream CI. No AWS resources were deployed. No construct source or cloud topology is changed, so no cloud integration snapshot is added.

Checklist


By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license

@aws-cdk-automation
aws-cdk-automation requested a review from a team September 30, 2026 03:52
@github-actions github-actions Bot added beginning-contributor [Pilot] contributed between 0-2 PRs to the CDK p2 labels Sep 30, 2026

@aws-cdk-automation aws-cdk-automation left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

(This review is outdated)

@burger66leo

Copy link
Copy Markdown
Contributor Author

Exemption Request

Please review whether this lockfile-only third-party dependency update can be exempted from the construct unit-test and cloud integration-snapshot requirements.

The diff updates only the version, registry URL and integrity for brace-expansion@^5.0.5, from 5.0.9 to 5.0.12. No construct source, API, IAM permission or CloudFormation topology changes. This follows the lockfile-only update previously merged in #38520.

Focused local checks installed minimatch 10.2.5 from the updated lockfile with Yarn 1.22.22 --frozen-lockfile, verified brace-expansion 5.0.12, checked normal alternatives/ranges and minimatch matches, and exercised the publicly documented recursion and rewrite inputs. The isolated dependency graph reports zero npm audit vulnerabilities. Full CDK build/package verification still requires upstream CI; these fixture checks do not establish that the published CDK artifact has changed.

A cloud deployment snapshot would not exercise the affected brace parser or prove which dependency version is bundled. If additional repository-level dependency tests are preferred, please advise on the appropriate existing test location.

@aws-cdk-automation aws-cdk-automation added the pr-linter/exemption-requested The contributor has requested an exemption to the PR Linter feedback. label Sep 30, 2026
Jmevorach added a commit to aws-solutions-library-samples/global-capacity-orchestrator-on-aws that referenced this pull request Sep 30, 2026
…visories (#431)

The Security workflow went red on main at 50d86cd, a tree identical to
PR #429's head, whose Security run passed hours earlier. Advisories
published on 2026-09-29 reached the Trivy and npm databases in between.

- Debian DSA-6531-1 (CVE-2026-75804, CVE-2026-84782) fixes OpenSSL in
  3.5.7-1~deb13u3. The six service images and the dev image still had
  deb13u2 from the cached upgrade layer. APT_SECURITY_EPOCH moves to
  2026-09-30 in the seven Debian Dockerfiles, which rebuilds that layer.
- npm audit: GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 and
  GHSA-q2hr-2g5m-vwhr affect the brace-expansion 5.0.9 that aws-cdk-lib
  bundles, which the root graph reaches only through cdk-dia. The latest
  aws-cdk-lib, 2.271.0, still bundles 5.0.9 (the fix is pending in
  aws/aws-cdk#38929), and overrides cannot reach a bundled copy. The
  three get exact .npm-audit-ignore entries until 2026-10-30. cdk-dia
  never loads aws-cdk-lib at runtime.
- Trivy on the dev image: CVE-2026-102276 and CVE-2026-102278 affect the
  brace-expansion 5.0.7 that npm vendors, and CVE-2026-19534 the undici
  6.27.0 that npm vendors for node-gyp, which uses it only for fetch. The
  latest npm, 12.1.0, still vendors 5.0.9 and 6.28.0, so the three join
  the other npm-vendored .trivyignore entries and expire with them on
  2026-10-22.

Verified locally: the rebuilt health-monitor and dev images carry
libssl3t64 3.5.7-1~deb13u3 and scan clean with the CI's Trivy v0.74.0,
flags and ignore file. Without the ignore file, the dev image reports
only the existing suppressions plus the three new IDs. The CI npm audit
gate passes on both package graphs.
@KB903

KB903 commented Sep 30, 2026

Copy link
Copy Markdown

Thank you for preparing this fix. We independently verified the official aws-cdk-lib 2.271.0 npm tarball against its published SHA-512 integrity and found bundled brace-expansion 5.0.9. Our pinned 2.268.0 dependency is also affected, and our high-severity audit gate is blocking merges. We are keeping the gate in place rather than suppressing the advisories.

Could a maintainer please review the lockfile-only update and exemption request, and advise whether the fix can be prioritized for the next official release? If a separate tracking issue is required, please let us know. We will verify the bundled code in the published artifact and a clean installation before considering the issue resolved.

Thank you for your help.

awsmadi added a commit to awslabs/automated-security-helper that referenced this pull request Sep 30, 2026
…aws-cdk-lib

aws-cdk-lib bundles brace-expansion 5.0.9 (GHSA-6j4f-fj2g-mc7p,
GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr). No aws-cdk-lib release ships a
fixed copy (2.272.0 checked), and npm overrides cannot rewrite a bundled
dependency, so the repository cannot remove it. Upstream: aws/aws-cdk#38929
and aws/aws-cdk#38932. The maintainer approved accepting the risk until
2026-10-30. Every entry expires then.

Entries, keyed the way each scanner reports the finding:
- grype, in .ash/.ash.yaml: <GHSA>-brace-expansion on
  deploy/cdk/package-lock.json
- npm-audit, in .ash/.ash.yaml: <GHSA> on
  node_modules/aws-cdk-lib/brace-expansion/package.json. That is the path
  npm-audit gives only the bundled copy.
- trivy-repo, in .ash/.ash_community_plugins.yaml: the CVE aliases on
  deploy/cdk/package-lock.json

Known limit: ASH matches on rule id, path and line range only. The grype and
trivy entries therefore cover these three advisories for any brace-expansion
copy in deploy/cdk/package-lock.json, not only the bundled one. Today the
bundled copy is the only vulnerable one left there. The npm-audit entry has
no such gap. These entries should be tightened once ASH can match on package
and version.
awsmadi added a commit to awslabs/automated-security-helper that referenced this pull request Sep 30, 2026
…ories (#686)

* fix(deps): move pyjwt and brace-expansion off versions with new advisories

Advisories published 2026-09-29 made main's own scan fail. Every open PR
inherits the failure because none of their diffs touch these packages.

pyjwt 2.13.0 -> 2.15.1 in uv.lock. It is transitive via mcp[crypto], whose
range (>=2.10.1) already allows the fix, so this is a lock refresh plus a
>=2.14 floor in pyproject.toml, matching how cryptography is floored. That
clears ten advisories, GHSA-ffc3-869f-jxw9 (critical) among them; 2.14.0 is
the first patched release for all ten.

brace-expansion, via `npm update brace-expansion` in each tree. The parent
ranges already allowed the patched releases, so no override was needed:
  deploy/cdk:            1.1.18 -> 1.1.21
  deploy/cdk-constructs: 5.0.9 -> 5.0.12, test-exclude's copy 2.1.4 -> 2.1.7
That clears GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 and GHSA-q2hr-2g5m-vwhr
for those copies. npm also rewrote some lockfile metadata: it added `engines`
from package.json and corrected `dev` flags on five deploy/cdk entries whose
only dependents are dev dependencies.

Not fixed: the brace-expansion 5.0.9 that aws-cdk-lib bundles in both trees.
Every aws-cdk-lib release through 2.272.0 (the current latest) ships 5.0.9,
and npm `overrides` cannot rewrite a bundled dependency (tested). The upstream
fix is aws/aws-cdk#38929.

* chore(config): time-boxed suppression for brace-expansion bundled in aws-cdk-lib

aws-cdk-lib bundles brace-expansion 5.0.9 (GHSA-6j4f-fj2g-mc7p,
GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr). No aws-cdk-lib release ships a
fixed copy (2.272.0 checked), and npm overrides cannot rewrite a bundled
dependency, so the repository cannot remove it. Upstream: aws/aws-cdk#38929
and aws/aws-cdk#38932. The maintainer approved accepting the risk until
2026-10-30. Every entry expires then.

Entries, keyed the way each scanner reports the finding:
- grype, in .ash/.ash.yaml: <GHSA>-brace-expansion on
  deploy/cdk/package-lock.json
- npm-audit, in .ash/.ash.yaml: <GHSA> on
  node_modules/aws-cdk-lib/brace-expansion/package.json. That is the path
  npm-audit gives only the bundled copy.
- trivy-repo, in .ash/.ash_community_plugins.yaml: the CVE aliases on
  deploy/cdk/package-lock.json

Known limit: ASH matches on rule id, path and line range only. The grype and
trivy entries therefore cover these three advisories for any brace-expansion
copy in deploy/cdk/package-lock.json, not only the bundled one. Today the
bundled copy is the only vulnerable one left there. The npm-audit entry has
no such gap. These entries should be tightened once ASH can match on package
and version.
@github-actions github-actions Bot added the bug This issue is a bug. label Sep 30, 2026
shalev396 added a commit to shalev396/Red-Alerts that referenced this pull request Oct 1, 2026
Home Screen web app (following Portfolio/Elytra):
- Web manifest, apple-touch-icon, status-bar and viewport-fit meta tags
- Generated icons + og-default.png via `npm run generate:icons` (sharp)
- theme-color tracks the resolved theme background
- Safe-area insets for navbar, footer, toasts, timeline, sheet and map overlays

Dependencies (package.json only; lockfiles regenerated from a clean install):
- Client: maplibre-gl ^6.11.2, axios ^1.20.0, react-router-dom ^7.18.4,
  vite ^7.3.6 -> npm audit: 0 vulnerabilities
- maplibre v6 is ESM-only: namespace imports, and the worker is registered
  once in src/lib/map/maplibre.ts (Vite ?worker&url)
- Server: aws-cdk-lib ^2.272.0. Its bundled brace-expansion@5.0.9 is still
  flagged; waiting on aws/aws-cdk#38929
- Python: cryptography 50.0.2; fastapi 0.142.2 + pydantic 2.13.5 (pulls a
  patched starlette) -> pip-audit: no known vulnerabilities
rix0rrr
rix0rrr previously approved these changes Oct 2, 2026
@rix0rrr rix0rrr added pr-linter/exempt-test The PR linter will not require test changes pr-linter/exempt-integ-test The PR linter will not require integ test changes labels Oct 2, 2026
@fschmutz

fschmutz commented Oct 4, 2026

Copy link
Copy Markdown

Tested the effect of this bump on a downstream CDK app (aws-cdk-lib 2.272.0, aws-cdk CLI 2.1144.0, Node 26.3.0, npm).
Replaced the bundled aws-cdk-lib/node_modules/brace-expansion 5.0.9 with 5.0.12 (same integrity as this PR's lockfile), minimatch 10.2.5 unchanged.

  • jest suite: 258/258 pass, unchanged
  • cdk synth of 15 stacks: output byte-identical to the unpatched synth, asset hashes included (asset exclude globs exercise minimatch)
  • npm audit: the brace-expansion high (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p) goes from 1 to 0

@jumic

jumic commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

@rix0rrr Thanks for approving this PR. Could you also take another look at the GitHub workflows included in this PR? As far as I know, they still require approval because this is @burger66leo's first PR in this repository.

14 workflows awaiting approval
This workflow requires approval from a maintainer.

gasolima
gasolima previously approved these changes Oct 6, 2026
@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork).

@mergify

mergify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Merge Queue Status

  • ✅ Entered queue — 2026-10-06 08:51 UTC · Rule: default-squash · triggered by rule automatic merge
  • 🚫 Left the queue — 2026-10-06 09:08 UTC · at 8e692ca353623929129ada0d042a58bf902aa8f0

This pull request spent 16 minutes 36 seconds in the queue, with no time running CI.

Reason

Pull request #38929 has been dequeued

Queue conditions are not satisfied:

  • -label~=(blocked|do-not-merge|agent-docs-review-needed|no-squash|two-approvers|priority-pr)
  • check-success=validate-pr

Hint

You should look at the reason for the failure and decide if the pull request needs to be fixed or if you want to requeue it.
If you do update this pull request, it will automatically be requeued once the queue conditions match again.
If you think this was a flaky issue instead, you can requeue the pull request, without updating it, by posting a @mergifyio queue comment.

Requeued — the merge queue status continues in this comment ↓.

@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork).

@mergify

mergify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Merge Queue Status

  • ✅ Entered queue — 2026-10-06 09:10 UTC · Rule: priority-squash · triggered by rule automatic priority merge
  • 🚫 Left the queue — 2026-10-06 09:53 UTC · at 8e692ca353623929129ada0d042a58bf902aa8f0

This pull request spent 43 minutes 34 seconds in the queue, with no time running CI.

Reason

The pull request can't be updated

GitHub response: refusing to allow a GitHub App to create or update workflow .github/workflows/pr-linter.yml without workflows permission
GitHub only lets Mergify write to .github/workflows/ with the workflows permission. An organization owner can accept Mergify's pending permissions at https://dashboard.mergify.com/orgs/aws/repositories.

Hint

You should update or rebase your pull request manually. If you do, this pull request will automatically be requeued once the queue conditions match again.
If you think this was a flaky issue, you can requeue the pull request, without updating it, by posting a @mergifyio queue comment.

Tick the box to put this pull request back in the merge queue (same as @mergifyio queue).

  • Requeue this pull request

@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork).

@mergify

mergify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Merge Queue Status

  • ✅ Entered queue — 2026-10-06 10:35 UTC · Rule: priority-squash · triggered by rule automatic priority merge
  • ✅ Checks passed · in-place
  • ✅ Merged — 2026-10-06 11:34 UTC · at ff25def6c473addeafc091d93a01fcb5b5b5cb25 · squash

This pull request spent 59 minutes 18 seconds in the queue, including 37 minutes 35 seconds running CI.

Required conditions to merge

@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

queue

☑️ This pull request is already queued

@mergify

mergify Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Thank you for contributing! Your pull request will be updated from main and then merged automatically (do not update manually, and be sure to allow changes to be pushed to your fork).

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Comments on closed issues and PRs are hard for our team to see.
If you need help, please open a new issue that references this one.

This branch was successfully deployed

1 active deployment
automation — 210d5bb9 Deployed Oct 6, 2026 by mergify[bot] via validate-pr #371099
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

beginning-contributor [Pilot] contributed between 0-2 PRs to the CDK bug This issue is a bug. p2 pr/needs-further-review PR requires additional review from our team specialists due to the scope or complexity of changes. pr-linter/exempt-integ-test The PR linter will not require integ test changes pr-linter/exempt-test The PR linter will not require test changes pr-linter/exemption-requested The contributor has requested an exemption to the PR Linter feedback. priority-pr push the PR to priority squash queue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

(core): Bump bundled brace-expansion to 5.0.12 to address CVE-2026-102276 / CVE-2026-102278

8 participants