Skip to content

fix: update aws-lc-sys, minimatch, underscore (security)#9

Merged
mostafa merged 1 commit intomainfrom
fix/dependabot-alerts
Mar 10, 2026
Merged

fix: update aws-lc-sys, minimatch, underscore (security)#9
mostafa merged 1 commit intomainfrom
fix/dependabot-alerts

Conversation

@mostafa
Copy link
Copy Markdown
Member

@mostafa mostafa commented Mar 10, 2026

Summary

Updates transitive dependencies to resolve 6 high-severity Dependabot alerts.

Cargo.lock (alerts 7, 8, 9)

Package From To
aws-lc-sys 0.37.1 0.38.0
aws-lc-rs 1.16.0 1.16.1
  • PKCS7_verify Signature Validation Bypass
  • Timing Side-Channel in AES-CCM Tag Verification
  • PKCS7_verify Certificate Chain Validation Bypass

editors/vscode/package-lock.json (alerts 4, 6, 10)

Package From To Issue
minimatch 3.1.2 3.1.5 ReDoS via GLOBSTAR segments
minimatch 10.2.1 10.2.4 ReDoS via extglobs
underscore 1.13.7 1.13.8 DoS via unlimited recursion

Only lockfiles are modified — no code or dependency spec changes.

Cargo.lock:
- aws-lc-sys 0.37.1 -> 0.38.0 (with aws-lc-rs 1.16.0 -> 1.16.1)
  Addresses alerts #7, #8, #9:
  - PKCS7_verify Signature Validation Bypass
  - Timing Side-Channel in AES-CCM Tag Verification
  - PKCS7_verify Certificate Chain Validation Bypass

editors/vscode/package-lock.json:
- minimatch 3.1.2 -> 3.1.5 (alert #6: ReDoS via GLOBSTAR segments)
- minimatch 10.2.1 -> 10.2.4 (alert #4: ReDoS via extglobs)
- underscore 1.13.7 -> 1.13.8 (alert #10: DoS via unlimited recursion)
@mostafa mostafa self-assigned this Mar 10, 2026
@mostafa mostafa changed the title fix: update dependencies to resolve security vulnerabilities fix: update aws-lc-sys, minimatch, underscore (security) Mar 10, 2026
@mostafa mostafa merged commit 23cd266 into main Mar 10, 2026
9 checks passed
@mostafa mostafa deleted the fix/dependabot-alerts branch March 10, 2026 09:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant