Skip to content
This repository was archived by the owner on Feb 19, 2025. It is now read-only.

Commit add1e52

Browse files
verinderpbverind
andauthored
fix: security vulnerabilities from fast-xml-parser and semver packages (#18)
Co-authored-by: Verinder Singh <[email protected]>
1 parent 43f8e21 commit add1e52

File tree

10 files changed

+135
-509
lines changed

10 files changed

+135
-509
lines changed

NOTICE.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,8 +16,8 @@ This software includes third party software subject to the following copyrights:
1616
@aws-cdk/[email protected] Apache-2.0
1717
@aws-cdk/[email protected] Apache-2.0
1818
@aws-cdk/[email protected] Apache-2.0
19-
@aws-cdk/aws-servicecatalogappregistry-alpha@2.76.0-alpha.0 Apache-2.0
20-
@aws-cdk/aws-synthetics-alpha@2.76.0-alpha.0 Apache-2.0
19+
@aws-cdk/aws-servicecatalogappregistry-alpha@2.85.0-alpha.0 Apache-2.0
20+
@aws-cdk/aws-synthetics-alpha@2.85.0-alpha.0 Apache-2.0
2121
@balena/[email protected] Apache-2.0
2222
@colors/[email protected] MIT
2323
@@ -30,7 +30,7 @@ [email protected] MIT
3030
3131
3232
33-
aws-cdk-lib@2.76.0 Apache-2.0
33+
aws-cdk-lib@2.85.0 Apache-2.0
3434
3535
3636
@@ -248,7 +248,7 @@ [email protected] Python-2.0
248248
249249
250250
251-
aws-cdk-lib@2.76.0 Apache-2.0
251+
aws-cdk-lib@2.85.0 Apache-2.0
252252
253253
254254

source/blueprint-infrastructure/package-lock.json

Lines changed: 38 additions & 77 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

source/blueprint-infrastructure/package.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@
2626
"@types/node": "^18.14.5",
2727
"@typescript-eslint/eslint-plugin": "^5.54.1",
2828
"@typescript-eslint/parser": "^5.54.1",
29-
"aws-cdk": "^2.76.0",
29+
"aws-cdk": "^2.85.0",
3030
"aws-lambda": "^1.0.7",
3131
"aws-sdk-client-mock": "^2.0.1",
3232
"constructs": "^10.1.84",
@@ -53,10 +53,14 @@
5353
"@aws-sdk/client-sns": "^3.310.0",
5454
"@aws-sdk/lib-dynamodb": "^3.310.0",
5555
"@octokit/rest": "^19.0.3",
56-
"aws-cdk-lib": "^2.76.0",
56+
"aws-cdk-lib": "^2.85.0",
5757
"js-yaml": "^4.1.0",
5858
"js-yaml-cloudformation-schema": "^1.0.0",
5959
"source-map-support": "^0.5.21",
6060
"winston": "^3.8.1"
61+
},
62+
"overrides": {
63+
"fast-xml-parser": "^4.2.5",
64+
"semver": "^7.5.3"
6165
}
6266
}

source/blueprint-ui/package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,7 @@
8181
"nth-check": "^2.0.1",
8282
"jest": "^29.3.1",
8383
"webpack": "^5.81.0",
84-
"yaml": "^2.2.2"
84+
"yaml": "^2.2.2",
85+
"fast-xml-parser": "^4.2.5"
8586
}
8687
}

source/blueprint-ui/yarn.lock

Lines changed: 6 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -7916,17 +7916,12 @@ fast-levenshtein@^2.0.6, fast-levenshtein@~2.0.6:
79167916
resolved "https://registry.yarnpkg.com/fast-levenshtein/-/fast-levenshtein-2.0.6.tgz#3d8a5c66883a16a30ca8643e851f19baa7797917"
79177917
integrity sha512-DCXu6Ifhqcks7TZKY3Hxp3y6qphY5SJZmrWMDrKcERSOXWQdMhU9Ig/PYrzyw/ul9jOIyh0N4M0tbC5hodg8dw==
79187918

7919-
7920-
version "3.19.0"
7921-
resolved "https://registry.yarnpkg.com/fast-xml-parser/-/fast-xml-parser-3.19.0.tgz#cb637ec3f3999f51406dd8ff0e6fc4d83e520d01"
7922-
integrity sha512-4pXwmBplsCPv8FOY1WRakF970TjNGnGnfbOnLqjlYvMiF1SR3yOHyxMR/YCXpPTOspNF5gwudqktIP4VsWkvBg==
7923-
7924-
fast-xml-parser@^3.16.0:
7925-
version "3.21.1"
7926-
resolved "https://registry.yarnpkg.com/fast-xml-parser/-/fast-xml-parser-3.21.1.tgz#152a1d51d445380f7046b304672dd55d15c9e736"
7927-
integrity sha512-FTFVjYoBOZTJekiUsawGsSYV9QL0A+zDYCRj7y34IO6Jg+2IMYEtQa+bbictpdpV8dHxXywqU7C0gRDEOFtBFg==
7919+
[email protected], fast-xml-parser@^3.16.0, fast-xml-parser@^4.2.5:
7920+
version "4.2.5"
7921+
resolved "https://registry.yarnpkg.com/fast-xml-parser/-/fast-xml-parser-4.2.5.tgz#a6747a09296a6cb34f2ae634019bf1738f3b421f"
7922+
integrity sha512-B9/wizE4WngqQftFPmdaMYlXoJlJOYxGQOanC77fq9k8+Z0v5dDSVh+3glErdIROP//s/jgb7ZuxKfB8nVyo0g==
79287923
dependencies:
7929-
strnum "^1.0.4"
7924+
strnum "^1.0.5"
79307925

79317926
fastq@^1.6.0:
79327927
version "1.15.0"
@@ -13069,7 +13064,7 @@ strip-json-comments@^3.1.0, strip-json-comments@^3.1.1:
1306913064
resolved "https://registry.yarnpkg.com/strip-json-comments/-/strip-json-comments-3.1.1.tgz#31f1281b3832630434831c310c01cccda8cbe006"
1307013065
integrity sha512-6fPc+R4ihwqP6N/aIv2f1gMH8lOVtWQHoqC4yK6oSDVVocumAsfCqjkXnqiYMhmMwS/mEHLp7Vehlt3ql6lEig==
1307113066

13072-
strnum@^1.0.4:
13067+
strnum@^1.0.5:
1307313068
version "1.0.5"
1307413069
resolved "https://registry.yarnpkg.com/strnum/-/strnum-1.0.5.tgz#5c4e829fe15ad4ff0d20c3db5ac97b73c9b072db"
1307513070
integrity sha512-J8bbNyKKXl5qYcR36TIO8W3mVGVHrmmxsd5PAItGkmyzwJvybiw2IVq5nqd0i4LSNSkB/sx9VHllbfFdr9k1JA==

source/lambda/blueprintgovernanceservice/initialRepoTemplates/cdk/packages/cdk-test-app/package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -15,14 +15,14 @@
1515
"devDependencies": {
1616
"@types/jest": "^28.1.7",
1717
"@types/node": "^18.7.11",
18-
"aws-cdk": "^2.76.0",
18+
"aws-cdk": "^2.85.0",
1919
"jest": "^26.4.2",
2020
"ts-jest": "^28.0.8",
2121
"ts-node": "^10.9.1",
2222
"typescript": "^4.8.4"
2323
},
2424
"dependencies": {
25-
"aws-cdk-lib": "^2.76.0",
25+
"aws-cdk-lib": "^2.85.0",
2626
"constructs": "^10.1.84",
2727
"source-map-support": "^0.5.16"
2828
}

0 commit comments

Comments
 (0)