Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
87 changes: 87 additions & 0 deletions .ash/.ash.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,93 @@ external_reports_to_include: []
global_settings:
severity_threshold: MEDIUM
suppressions:
# === Time-boxed: brace-expansion bundled inside aws-cdk-lib (expires 2026-10-30) ===
# Remove when an aws-cdk-lib release bundles brace-expansion >= 5.0.12 and the
# lockfiles move to it. Tighten to package-aware matching once ASH supports it.
- rule_id: "GHSA-6j4f-fj2g-mc7p-brace-expansion"
path: "deploy/cdk/package-lock.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Known limit: the matcher keys on rule id and path only, so this entry covers
this advisory for ANY brace-expansion copy in this lockfile, not just the
bundled one; a vulnerable copy reintroduced here before expiry would be hidden.
- rule_id: "GHSA-qhr7-859c-m2p7-brace-expansion"
path: "deploy/cdk/package-lock.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Known limit: the matcher keys on rule id and path only, so this entry covers
this advisory for ANY brace-expansion copy in this lockfile, not just the
bundled one; a vulnerable copy reintroduced here before expiry would be hidden.
- rule_id: "GHSA-q2hr-2g5m-vwhr-brace-expansion"
path: "deploy/cdk/package-lock.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Known limit: the matcher keys on rule id and path only, so this entry covers
this advisory for ANY brace-expansion copy in this lockfile, not just the
bundled one; a vulnerable copy reintroduced here before expiry would be hidden.
- rule_id: "GHSA-6j4f-fj2g-mc7p"
path: "node_modules/aws-cdk-lib/brace-expansion/package.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Scope: npm-audit reports the bundled copy at this path and every other copy at a
different one, so this entry matches only the aws-cdk-lib-bundled copy (in any
tree whose aws-cdk-lib bundles it).
- rule_id: "GHSA-qhr7-859c-m2p7"
path: "node_modules/aws-cdk-lib/brace-expansion/package.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Scope: npm-audit reports the bundled copy at this path and every other copy at a
different one, so this entry matches only the aws-cdk-lib-bundled copy (in any
tree whose aws-cdk-lib bundles it).
- rule_id: "GHSA-q2hr-2g5m-vwhr"
path: "node_modules/aws-cdk-lib/brace-expansion/package.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Scope: npm-audit reports the bundled copy at this path and every other copy at a
different one, so this entry matches only the aws-cdk-lib-bundled copy (in any
tree whose aws-cdk-lib bundles it).
# === detect-secrets: broad patterns by path (no inline nosec support) ===
- rule_id: "SECRET-*"
path: "tests/**"
Expand Down
45 changes: 45 additions & 0 deletions .ash/.ash_community_plugins.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,51 @@ external_reports_to_include: []
global_settings:
severity_threshold: MEDIUM
suppressions:
# === Time-boxed: brace-expansion bundled inside aws-cdk-lib (expires 2026-10-30) ===
# Remove when an aws-cdk-lib release bundles brace-expansion >= 5.0.12 and the
# lockfiles move to it. Tighten to package-aware matching once ASH supports it.
- rule_id: "CVE-2026-102276"
path: "deploy/cdk/package-lock.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Known limit: the matcher keys on rule id and path only, so this entry covers
this advisory for ANY brace-expansion copy in this lockfile, not just the
bundled one; a vulnerable copy reintroduced here before expiry would be hidden.
- rule_id: "CVE-2026-102278"
path: "deploy/cdk/package-lock.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Known limit: the matcher keys on rule id and path only, so this entry covers
this advisory for ANY brace-expansion copy in this lockfile, not just the
bundled one; a vulnerable copy reintroduced here before expiry would be hidden.
- rule_id: "CVE-2026-102277"
path: "deploy/cdk/package-lock.json"
expiration: "2026-10-30"
reason: >-
brace-expansion 5.0.9 is bundled inside aws-cdk-lib (inBundle: true in the
lockfile). No aws-cdk-lib release ships a fixed copy: 2.272.0, the latest when
this was written, still bundles 5.0.9. npm `overrides` cannot rewrite a bundled
dependency, so this repository has no way to remove it. Upstream fix:
https://github.com/aws/aws-cdk/pull/38929, tracked in
https://github.com/aws/aws-cdk/issues/38932. Time-boxed risk acceptance
approved by the maintainer.
Known limit: the matcher keys on rule id and path only, so this entry covers
this advisory for ANY brace-expansion copy in this lockfile, not just the
bundled one; a vulnerable copy reintroduced here before expiry would be hidden.
- path: automated_security_helper/schemas/cyclonedx_bom_1_6_schema/__init__.py
rule_id: API_KEY_OR_SECRET
reason: "False positive — generated CycloneDX schema definitions contain field names that match secret patterns"
Expand Down
15 changes: 9 additions & 6 deletions deploy/cdk-constructs/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

14 changes: 11 additions & 3 deletions deploy/cdk/package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 4 additions & 0 deletions pyproject.toml
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,10 @@ dependencies = [
# Transitive via pyjwt[crypto] <- mcp[crypto]; pinned to patch GHSA-g6cj-pr64-35w5.
# >=50.0 keeps that floor: the advisory affects >= 44.0.0, < 50.0.0, so 50.0.0 is the fix.
"cryptography>=50.0,<51",
# Transitive via mcp[crypto]. The floor keeps a resolver from picking 2.13.0, which ten
# advisories published 2026-09-29 cover (GHSA-ffc3-869f-jxw9 critical among them); every
# one of them is fixed in 2.14.0.
"pyjwt>=2.14,<3",
"uvicorn>=0.53.0,<1",
"jsonpatch>=1.33,<2",
]
Expand Down
8 changes: 5 additions & 3 deletions uv.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading