Skip to content

@aws-amplify/cli-extensibility-helper low severity vulnerability with aws-cdk-lib dependency #14090

@brianlenz

Description

@brianlenz

Is this feature request related to a new or existing Amplify category?

No response

Is this related to another service?

No response

Describe the feature you'd like to request

@aws-amplify/cli-extensibility-helper has a dependency on aws-cdk-lib ~2.129.0 which has a low severity vulnerability that would be worth updating at some point:

GHSA-v4mq-x674-ff73

Describe the solution you'd like

Update the aws-cdk-lib dependency to allow for the patched 2.177.0 version.

Is there a reason the dependency on aws-cdk-lib needs to use a tilde range instead of a caret range (which would allow updates to the patched version)?

Describe alternatives you've considered

You'd have to override the resolution to update aws-cdk-lib to the patched version.

Additional context

No response

Is this something that you'd be interested in working on?

  • 👋 I may be able to implement this feature request

Would this feature include a breaking change?

  • ⚠️ This feature might incur a breaking change

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependency-issueIssue with another dependency usedfeature-requestRequest a new featurepending-releaseCode has been merged but pending release

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions