mirror of
https://github.com/swift-server/swift-aws-lambda-runtime.git
synced 2026-06-02 07:27:33 +00:00
## Issue \# Fixes Dependabot alert #11 (minimatch ReDoS) and Dependabot alert #12 (ajv ReDoS). ## Description of changes Upgrades CDK dependencies in `Examples/CDK/infra/` to resolve two ReDoS vulnerabilities in bundled transitive dependencies: - `aws-cdk`: `2.1003.0` → `2.1015.0` - `aws-cdk-lib`: `^2.189.1` → `^2.215.0` (resolves to `2.240.0`) The new `aws-cdk-lib` bundles `minimatch@^10.2.1` (was `3.1.2`) and `ajv@8.18.0` (was `8.17.1`), which address the reported vulnerabilities. `npm audit` now reports 0 vulnerabilities. ## New/existing dependencies impact assessment, if applicable No new dependencies were added. Existing dependencies `aws-cdk` and `aws-cdk-lib` were updated to their latest versions. `package-lock.json` was regenerated. ## Conventional Commits `fix: upgrade CDK dependencies to resolve minimatch and ajv ReDoS vulnerabilities` By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license. Co-authored-by: Sebastien Stormacq <stormacq@amazon.lu>
Welcome to your CDK TypeScript project
This is a blank project for CDK development with TypeScript.
The cdk.json file tells the CDK Toolkit how to execute your app.
Useful commands
npm run buildcompile typescript to jsnpm run watchwatch for changes and compilenpm run testperform the jest unit testsnpx cdk deploydeploy this stack to your default AWS account/regionnpx cdk diffcompare deployed stack with current statenpx cdk synthemits the synthesized CloudFormation template