Skip to content

[Aikido] Fix 23 security issues in fast-xml-parser, fast-uri, aws-cdk-lib and 6 more - #46

Closed
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-update-packages-70602530-8n4q
Closed

[Aikido] Fix 23 security issues in fast-xml-parser, fast-uri, aws-cdk-lib and 6 more#46
aikido-autofix[bot] wants to merge 1 commit into
masterfrom
fix/aikido-security-update-packages-70602530-8n4q

Conversation

@aikido-autofix

Copy link
Copy Markdown

Upgrade dependencies to fix critical XSS via XML entity shadowing, XML entity expansion DoS attacks, stack overflow in XML builder, SSRF bypass via URI parsing, and other security vulnerabilities.

⚠️ Breaking changes analysis not available for: aws-cdk-lib, minimatch, ajv, fs-extra

✅ No breaking changes for: fast-xml-parser, fast-uri, brace-expansion, yaml, @smithy/config-resolver

✅ 23 CVEs resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
CVE-2026-25896
🚨 CRITICAL
[fast-xml-parser] A dot (.) in DOCTYPE entity names is treated as a regex wildcard, allowing attackers to shadow built-in XML entities with arbitrary values and bypass entity encoding. This leads to XSS when parsed output is rendered.
CVE-2026-26278
HIGH
[fast-xml-parser] XML entity expansion vulnerability allows attackers to cause denial of service by forcing unlimited entity expansion with minimal input, potentially freezing the application for extended periods.
CVE-2026-27942
HIGH
[fast-xml-parser] XML builder with preserveOrder:true causes stack overflow leading to denial of service when processing certain inputs. The application crashes due to improper recursion handling during XML construction.
CVE-2026-33036
HIGH
[fast-xml-parser] Numeric character references and standard XML entities bypass entity expansion limits, allowing attackers to cause XML entity expansion Denial of Service by forcing excessive memory allocation and CPU usage through crafted XML payloads.
CVE-2026-33349
MEDIUM
[fast-xml-parser] XML entity expansion vulnerability where setting maxEntityCount or maxEntitySize to 0 is bypassed due to JavaScript falsy checks, allowing attackers to cause denial of service through memory exhaustion. The vulnerability affects configurations explicitly set to restrict or disable entities.
AIKIDO-2026-878106
HIGH
[fast-uri] URI authority parsing fails to treat backslashes as delimiters, allowing different host interpretations compared to Node's WHATWG URL parser, enabling bypass of host allowlists, SSRF filters, and redirect validation checks. The vulnerability permits attackers to circumvent security controls through crafted URIs containing backslashes.
AIKIDO-2026-10784
HIGH
[fast-uri] A path normalization vulnerability allows attackers to bypass security checks by using percent-encoded slashes and dots that are decoded before dot-segment removal, causing distinct URIs to normalize identically and compare equal.
CVE-2026-6321
HIGH
[fast-uri] A vulnerability in URI normalization allows attackers to bypass path-based access controls by using percent-encoded separators and dot segments that normalize to unintended paths. This enables policy bypass attacks where restricted paths can be accessed through specially crafted encoded URLs.
CVE-2026-6322
HIGH
[fast-uri] Normalize function improperly decodes percent-encoded authority delimiters in the host component, re-emitting them as raw delimiters during serialization. This allows attackers to bypass host allowlist checks and redirect requests to unintended authorities.
AIKIDO-2026-507986
HIGH
[fast-uri] A security bypass vulnerability exists in host canonicalization for Unicode/IDN values due to inconsistent ASCII/Unicode host handling, which could allow attackers to bypass security checks through improper host normalization.
CVE-2026-11417
HIGH
[aws-cdk-lib] OS command injection vulnerability in NodejsFunction local bundling pipeline allows arbitrary command execution if an attacker controls bundling properties like externalModules, define, loader, inject, or esbuildArgs through shell metacharacters injection.
AIKIDO-2026-577363
HIGH
[aws-cdk-lib] OS command injection vulnerability in Docker-based NodejsFunction bundling when using the nodeModules option allows attackers to inject shell commands through dependency version strings, leading to arbitrary code execution with the privileges of the CDK toolchain user.
AIKIDO-2026-237551
MEDIUM
[brace-expansion] A recursive expansion function computes unnecessary segments before early returns, causing exponential time complexity when processing consecutive non-expanding brace groups, enabling denial-of-service attacks through short malicious inputs that can stall processes or workers.
CVE-2026-33750
LOW
[brace-expansion] A brace pattern with zero step value causes an infinite loop, leading to denial of service through process hangs and excessive memory allocation. The vulnerability affects string expansion operations when malicious or malformed patterns are processed.
AIKIDO-2026-10477
LOW
[brace-expansion] A denial-of-service vulnerability allows attackers to craft malicious brace patterns with repeated numeric ranges that cause exponential expansion, consuming excessive CPU and memory until process failure. The fix introduces an optional maximum limit parameter to bound expansion work.
CVE-2026-33532
MEDIUM
[yaml] A stack overflow vulnerability in the YAML parser's node resolution phase allows attackers to trigger a RangeError via deeply nested YAML structures (~2-10 KB), potentially causing denial of service or process termination in applications that don't catch non-YAMLParseError exceptions.
CVE-2026-26996
LOW
[minimatch] A Regular Expression Denial of Service (ReDoS) vulnerability exists when glob patterns contain many consecutive * wildcards followed by a literal character, causing exponential backtracking with O(4^N) complexity. Applications passing user-controlled strings as patterns to minimatch() are vulnerable to severe performance degradation or hangs.
CVE-2026-27903
LOW
[minimatch] A ReDoS vulnerability in glob pattern matching causes unbounded recursive backtracking with multiple GLOBSTAR segments, enabling attackers to stall the event loop for tens of seconds via crafted patterns in build tools, CI/CD pipelines, or multi-tenant systems.
CVE-2026-27904
LOW
[minimatch] Nested extglobs (*() and +()) generate regexps with catastrophic backtracking, causing severe ReDoS denial-of-service attacks with minimal input patterns triggering multi-second hangs.
GHSA-6475-r3vj-m8vf
LOW
[@smithy/config-resolver] An attacker with environment access could set an invalid region value, potentially routing AWS API calls to non-AWS hosts. A validation enhancement was added to prevent improper endpoint construction through region input validation.
CVE-2025-69873
LOW
[ajv] A ReDoS vulnerability allows attackers to inject malicious regex patterns via the $data option, causing catastrophic backtracking and CPU exhaustion. A 31-character payload can block execution for ~44 seconds, enabling complete denial of service with minimal effort.
AIKIDO-2026-273849
LOW
[ajv] A prototype pollution vulnerability allows attackers to bypass format validation when the $data option is enabled by using inherited property names like constructor or toString as format values, causing unexpected validation behavior or errors.
AIKIDO-2026-57045
LOW
[fs-extra] A symlink in the destination path allows bypassing self-subdirectory protection, causing copy/move operations to recurse infinitely into the source tree until resource exhaustion or path length limits are exceeded (DoS).
🤖 Remediation details

Fix multiple critical/high/medium/low severity vulnerabilities in transitive and direct dependencies

This PR remediates security vulnerabilities in nine packages: fast-xml-parser, fast-uri, aws-cdk-lib, brace-expansion, yaml, minimatch, @smithy/config-resolver, ajv, and fs-extra. Changes touch the root package.json (three direct dependency version bumps) and package-lock.json (lockfile-only resolution updates for all transitive instances).

fast-xml-parser

fast-xml-parser was a transitive dependency pulled in by @aws-sdk/core, which itself was pinned to an exact version by @aws-sdk/client-secrets-manager and @aws-sdk/credential-providers. Bumping both of those direct dependencies in package.json from ^3.348.0 to ^3.844.0 caused npm to resolve @aws-sdk/core to 3.975.3, which ships fast-xml-parser@5.x (well above the patched floor of 4.5.5). After the parent bump the vulnerable package no longer appears as a separate lockfile entry.

fast-uri

fast-uri was a transitive dependency of ajv@8.x, which was itself nested under aws-cdk-lib. Bumping aws-cdk-lib in package.json from ^2.78.0 to ^2.260.0 resolved aws-cdk-lib to 2.261.0, which no longer carries a separately-resolved fast-uri entry at a vulnerable version. The package no longer appears in the lockfile tree.

aws-cdk-lib

aws-cdk-lib is a direct dependency declared in package.json. Its version spec was raised from ^2.78.0 to ^2.260.0, resolving to 2.261.0 in the lockfile. This was required both to fix the vulnerabilities attributed directly to aws-cdk-lib and to pull in patched versions of several of its bundled transitives (yaml, minimatch, ajv, fast-uri, fs-extra).

brace-expansion

brace-expansion appears in three lockfile locations. The root instance (under minimatch@3.x) was updated from 1.1.12 to 1.1.16 and the filelist-nested instance (under minimatch@5.x) from 2.0.2 to 2.1.2 via npm update brace-expansion minimatch --package-lock-only after the aws-cdk-lib parent bump freed up resolution. The third instance nested under aws-cdk-lib/node_modules/minimatch (a 5.x copy) moved from 1.1.12 to 5.0.6; the parent minimatch@10.2.5 declares ^5.0.5 which permits 5.0.7, but npm resolved to the minimum satisfying version and no override shape successfully forced a higher patch — this instance is a partial fix at 5.0.6.

yaml

yaml was a transitive dependency pinned exactly as 1.10.2 by aws-cdk-lib@2.204.0. Bumping aws-cdk-lib to ^2.260.0 (resolving to 2.261.0) caused the nested yaml copy to move to 1.10.3, which is the patched version.

minimatch

minimatch appears in multiple lockfile locations. The root instance (shared by eslint, glob, jake, and others) moved from 3.1.2 to 3.1.5 via npm update minimatch --package-lock-only, satisfying the patched floor of 3.1.4. The aws-cdk-lib-nested instance moved from 3.1.2 to 10.2.5 as a result of the aws-cdk-lib parent bump. The filelist-nested instance moved from 5.1.6 to 5.1.9, also via the lockfile update.

@smithy/config-resolver

@smithy/config-resolver was a transitive dependency of @aws-sdk/client-secrets-manager and related AWS SDK packages, declared as ^4.1.4. The patched floor is 4.4.0, which falls within that declared range. Bumping @aws-sdk/client-secrets-manager and @aws-sdk/credential-providers to ^3.844.0 in package.json caused npm to resolve the AWS SDK suite to 3.1090.0, which pulls in @smithy/config-resolver at a version satisfying >=4.4.0. The package no longer appears as a separately-tracked vulnerable instance in the lockfile.

ajv

ajv appears in two lockfile locations. The root instance (used by eslint and @eslint/eslintrc, declared as ^6.12.4) moved from 6.12.6 to 6.15.0 via npm update ajv --package-lock-only, satisfying the patched floor of 6.14.0. The aws-cdk-lib-nested 8.x instance was resolved away entirely by the aws-cdk-lib parent bump to 2.261.0.

fs-extra

fs-extra is a transitive dependency nested under aws-cdk-lib. The aws-cdk-lib parent bump to 2.261.0 updated the declared range for fs-extra to ^11.3.5. The patched floor is 11.3.6; aws-cdk-lib@2.261.0 permits 11.3.6 under its declared range, but npm resolved to the minimum satisfying version 11.3.5. Multiple npm update invocations and override shapes were attempted without success in advancing this patch; this instance is a partial fix at 11.3.5.

Version changes

Package From To Why updated
aws-cdk-lib ^2.78.02.204.0 ^2.260.02.261.0 Direct CVE fix; manifest spec and lockfile resolution both updated
@aws-sdk/client-secrets-manager ^3.348.03.840.0 ^3.844.03.1090.0 Parent bump to fix fast-xml-parser and @smithy/config-resolver transitives
@aws-sdk/credential-providers ^3.348.03.840.0 ^3.844.03.1090.0 Parent bump to fix fast-xml-parser and @smithy/config-resolver transitives
@aws-sdk/core 3.840.0 3.975.3 Transitive after parent bump of @aws-sdk/client-secrets-manager
fast-xml-parser 4.4.1 (removed from tree) Resolved away by @aws-sdk/core upgrade; no longer a separate lockfile entry
fast-uri 3.0.6 (removed from tree) Resolved away by aws-cdk-lib upgrade; no longer a separate lockfile entry
yaml (aws-cdk-lib nested) 1.10.2 1.10.3 Transitive after parent bump of aws-cdk-lib
minimatch (aws-cdk-lib nested) 3.1.2 10.2.5 Transitive after parent bump of aws-cdk-lib
minimatch (root) 3.1.2 3.1.5 Lockfile update via npm update minimatch
minimatch (filelist nested) 5.1.6 5.1.9 Lockfile update via npm update minimatch
brace-expansion (root) 1.1.12 1.1.16 Transitive after minimatch root lockfile update
brace-expansion (filelist nested) 2.0.2 2.1.2 Transitive after minimatch filelist lockfile update
brace-expansion (aws-cdk-lib nested) 1.1.12 5.0.6 Transitive after parent bump of aws-cdk-lib; partial fix (5.0.7 target not achievable)
ajv (root) 6.12.6 6.15.0 Lockfile update via npm update ajv
ajv (aws-cdk-lib nested) 8.17.1 (removed from tree) Resolved away by aws-cdk-lib upgrade
@smithy/config-resolver 4.1.4 (resolved via AWS SDK parent bump) Transitive after parent bump of @aws-sdk/client-secrets-manager
fs-extra (aws-cdk-lib nested) 11.3.0 11.3.5 Transitive after parent bump of aws-cdk-lib; partial fix (11.3.6 target not achievable)
@aws-sdk/client-cognito-identity 3.840.0 3.1090.0 Transitive after parent bump of @aws-sdk/credential-providers
@aws-sdk/client-sso 3.840.0 (updated) Transitive after AWS SDK parent bumps
@aws-sdk/nested-clients 3.840.0 3.997.33 Transitive after AWS SDK parent bumps
@aws-sdk/token-providers 3.840.0 3.1088.0 Transitive after AWS SDK parent bumps

@github-actions

Copy link
Copy Markdown

Package lock diff

 2.4.1 -> 2.6.1
node_modules/@ampproject/remapping removed
node_modules/@aws-cdk/asset-awscli-v1 2.2.242 -> 2.2.282
node_modules/@aws-cdk/asset-node-proxy-agent-v6 2.1.0 -> 2.1.2
node_modules/@aws-cdk/cloud-assembly-schema 45.2.0 -> 54.12.0
node_modules/@aws-cdk/cloud-assembly-schema/node_modules/jsonschema 1.4.1 -> 1.5.0
node_modules/@aws-cdk/cloud-assembly-schema/node_modules/semver 7.7.2 -> 7.8.5
node_modules/@aws-crypto/sha256-browser removed
node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/is-array-buffer removed
node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/util-buffer-from removed
node_modules/@aws-crypto/sha256-browser/node_modules/@smithy/util-utf8 removed
node_modules/@aws-crypto/sha256-js removed
node_modules/@aws-crypto/supports-web-crypto removed
node_modules/@aws-crypto/util removed
node_modules/@aws-crypto/util/node_modules/@smithy/is-array-buffer removed
node_modules/@aws-crypto/util/node_modules/@smithy/util-buffer-from removed
node_modules/@aws-crypto/util/node_modules/@smithy/util-utf8 removed
node_modules/@aws-sdk/client-cognito-identity removed
node_modules/@aws-sdk/client-secrets-manager 3.840.0 -> 3.1090.0
node_modules/@aws-sdk/client-sso removed
node_modules/@aws-sdk/core 3.840.0 -> 3.975.3
node_modules/@aws-sdk/credential-provider-cognito-identity 3.840.0 -> 3.972.58
node_modules/@aws-sdk/credential-provider-env 3.840.0 -> 3.972.59
node_modules/@aws-sdk/credential-provider-http 3.840.0 -> 3.972.61
node_modules/@aws-sdk/credential-provider-ini 3.840.0 -> 3.973.4
node_modules/@aws-sdk/credential-provider-node 3.840.0 -> 3.972.70
node_modules/@aws-sdk/credential-provider-process 3.840.0 -> 3.972.59
node_modules/@aws-sdk/credential-provider-sso 3.840.0 -> 3.973.3
node_modules/@aws-sdk/credential-provider-web-identity 3.840.0 -> 3.972.65
node_modules/@aws-sdk/credential-providers 3.840.0 -> 3.1090.0
node_modules/@aws-sdk/middleware-host-header removed
node_modules/@aws-sdk/middleware-logger removed
node_modules/@aws-sdk/middleware-recursion-detection removed
node_modules/@aws-sdk/middleware-user-agent removed
node_modules/@aws-sdk/nested-clients 3.840.0 -> 3.997.33
node_modules/@aws-sdk/region-config-resolver removed
node_modules/@aws-sdk/token-providers 3.840.0 -> 3.1088.0
node_modules/@aws-sdk/types 3.840.0 -> 3.974.2
node_modules/@aws-sdk/util-endpoints removed
node_modules/@aws-sdk/util-locate-window removed
node_modules/@aws-sdk/util-user-agent-browser removed
node_modules/@aws-sdk/util-user-agent-node removed
node_modules/@aws-sdk/xml-builder 3.821.0 -> 3.972.36
node_modules/@babel/code-frame 7.27.1 -> 7.29.7
node_modules/@babel/compat-data 7.28.0 -> 7.29.7
node_modules/@babel/core 7.28.0 -> 7.29.7
node_modules/@babel/generator 7.28.0 -> 7.29.7
node_modules/@babel/helper-compilation-targets 7.27.2 -> 7.29.7
node_modules/@babel/helper-globals 7.28.0 -> 7.29.7
node_modules/@babel/helper-module-imports 7.27.1 -> 7.29.7
node_modules/@babel/helper-module-transforms 7.27.3 -> 7.29.7
node_modules/@babel/helper-plugin-utils 7.27.1 -> 7.29.7
node_modules/@babel/helper-string-parser 7.27.1 -> 7.29.7
node_modules/@babel/helper-validator-identifier 7.27.1 -> 7.29.7
node_modules/@babel/helper-validator-option 7.27.1 -> 7.29.7
node_modules/@babel/helpers 7.27.6 -> 7.29.7
node_modules/@babel/parser 7.28.0 -> 7.29.7
node_modules/@babel/plugin-syntax-import-attributes 7.27.1 -> 7.29.7
node_modules/@babel/plugin-syntax-jsx 7.27.1 -> 7.29.7
node_modules/@babel/plugin-syntax-typescript 7.27.1 -> 7.29.7
node_modules/@babel/template 7.27.2 -> 7.29.7
node_modules/@babel/traverse 7.28.0 -> 7.29.7
node_modules/@babel/types 7.28.0 -> 7.29.7
node_modules/@eslint-community/eslint-utils 4.7.0 -> 4.9.1
node_modules/@eslint-community/regexpp 4.12.1 -> 4.12.2
node_modules/@istanbuljs/load-nyc-config/node_modules/js-yaml 3.14.1 -> 3.15.0
node_modules/@istanbuljs/schema 0.1.3 -> 0.1.6
node_modules/@jridgewell/gen-mapping 0.3.12 -> 0.3.13
node_modules/@jridgewell/sourcemap-codec 1.5.4 -> 1.5.5
node_modules/@jridgewell/trace-mapping 0.3.29 -> 0.3.31
node_modules/@sinclair/typebox 0.27.8 -> 0.27.12
node_modules/@smithy/abort-controller removed
node_modules/@smithy/config-resolver removed
node_modules/@smithy/core 3.6.0 -> 3.29.5
node_modules/@smithy/credential-provider-imds 4.0.6 -> 4.4.10
node_modules/@smithy/fetch-http-handler 5.0.4 -> 5.6.7
node_modules/@smithy/hash-node removed
node_modules/@smithy/invalid-dependency removed
node_modules/@smithy/is-array-buffer removed
node_modules/@smithy/middleware-content-length removed
node_modules/@smithy/middleware-endpoint removed
node_modules/@smithy/middleware-retry removed
node_modules/@smithy/middleware-serde removed
node_modules/@smithy/middleware-stack removed
node_modules/@smithy/node-config-provider removed
node_modules/@smithy/node-http-handler 4.0.6 -> 4.9.7
node_modules/@smithy/property-provider removed
node_modules/@smithy/protocol-http removed
node_modules/@smithy/querystring-builder removed
node_modules/@smithy/querystring-parser removed
node_modules/@smithy/service-error-classification removed
node_modules/@smithy/shared-ini-file-loader removed
node_modules/@smithy/signature-v4 5.1.2 -> 5.6.6
node_modules/@smithy/smithy-client removed
node_modules/@smithy/types 4.3.1 -> 4.16.1
node_modules/@smithy/url-parser removed
node_modules/@smithy/util-base64 removed
node_modules/@smithy/util-body-length-browser removed
node_modules/@smithy/util-body-length-node removed
node_modules/@smithy/util-buffer-from removed
node_modules/@smithy/util-config-provider removed
node_modules/@smithy/util-defaults-mode-browser removed
node_modules/@smithy/util-defaults-mode-node removed
node_modules/@smithy/util-endpoints removed
node_modules/@smithy/util-hex-encoding removed
node_modules/@smithy/util-middleware removed
node_modules/@smithy/util-retry removed
node_modules/@smithy/util-stream removed
node_modules/@smithy/util-uri-escape removed
node_modules/@smithy/util-utf8 removed
node_modules/@tsconfig/node10 1.0.11 -> 1.0.12
node_modules/@types/babel__traverse 7.20.7 -> 7.28.0
node_modules/@types/node 18.19.117 -> 18.19.130
node_modules/@types/semver 7.7.0 -> 7.7.1
node_modules/@types/uuid removed
node_modules/@types/yargs 17.0.33 -> 17.0.35
node_modules/@ungap/structured-clone 1.3.0 -> 1.3.3
node_modules/acorn 8.15.0 -> 8.17.0
node_modules/acorn-walk 8.3.4 -> 8.3.5
node_modules/ajv 6.12.6 -> 6.15.0
node_modules/async removed
node_modules/aws-cdk-lib 2.204.0 -> 2.261.0
node_modules/aws-cdk-lib/node_modules/ajv removed
node_modules/aws-cdk-lib/node_modules/ansi-regex removed
node_modules/aws-cdk-lib/node_modules/ansi-styles removed
node_modules/aws-cdk-lib/node_modules/astral-regex removed
node_modules/aws-cdk-lib/node_modules/balanced-match 1.0.2 -> 4.0.4
node_modules/aws-cdk-lib/node_modules/brace-expansion 1.1.12 -> 5.0.6
node_modules/aws-cdk-lib/node_modules/color-convert removed
node_modules/aws-cdk-lib/node_modules/color-name removed
node_modules/aws-cdk-lib/node_modules/concat-map removed
node_modules/aws-cdk-lib/node_modules/emoji-regex removed
node_modules/aws-cdk-lib/node_modules/fast-deep-equal removed
node_modules/aws-cdk-lib/node_modules/fast-uri removed
node_modules/aws-cdk-lib/node_modules/fs-extra 11.3.0 -> 11.3.5
node_modules/aws-cdk-lib/node_modules/is-fullwidth-code-point removed
node_modules/aws-cdk-lib/node_modules/json-schema-traverse removed
node_modules/aws-cdk-lib/node_modules/jsonfile 6.1.0 -> 6.2.1
node_modules/aws-cdk-lib/node_modules/lodash.truncate removed
node_modules/aws-cdk-lib/node_modules/minimatch 3.1.2 -> 10.2.5
node_modules/aws-cdk-lib/node_modules/require-from-string removed
node_modules/aws-cdk-lib/node_modules/semver 7.7.2 -> 7.8.1
node_modules/aws-cdk-lib/node_modules/slice-ansi removed
node_modules/aws-cdk-lib/node_modules/string-width removed
node_modules/aws-cdk-lib/node_modules/strip-ansi removed
node_modules/aws-cdk-lib/node_modules/table removed
node_modules/aws-cdk-lib/node_modules/yaml 1.10.2 -> 1.10.3
node_modules/babel-preset-current-node-syntax 1.1.0 -> 1.2.0
node_modules/bowser 2.11.0 -> 2.14.1
node_modules/brace-expansion 1.1.12 -> 1.1.16
node_modules/browserslist 4.25.1 -> 4.28.6
node_modules/caniuse-lite 1.0.30001727 -> 1.0.30001806
node_modules/collect-v8-coverage 1.0.2 -> 1.0.3
node_modules/constructs 10.4.2 -> 10.7.0
node_modules/debug 4.4.1 -> 4.4.3
node_modules/dedent 1.6.0 -> 1.7.2
node_modules/diff 4.0.2 -> 4.0.4
node_modules/ejs removed
node_modules/electron-to-chromium 1.5.180 -> 1.5.393
node_modules/error-ex 1.3.2 -> 1.3.4
node_modules/eslint-config-prettier 8.10.0 -> 8.10.2
node_modules/eslint-plugin-prettier 4.2.1 -> 4.2.5
node_modules/esquery 1.6.0 -> 1.7.0
node_modules/fast-xml-parser removed
node_modules/fastq 1.19.1 -> 1.20.1
node_modules/filelist removed
node_modules/filelist/node_modules/brace-expansion removed
node_modules/filelist/node_modules/minimatch removed
node_modules/flatted 3.3.3 -> 3.4.2
node_modules/hasown 2.0.2 -> 2.0.4
node_modules/is-core-module 2.16.1 -> 2.16.2
node_modules/istanbul-reports 3.1.7 -> 3.2.0
node_modules/jake removed
node_modules/js-yaml 4.1.0 -> 4.3.0
node_modules/minimatch 3.1.2 -> 3.1.5
node_modules/node-releases 2.0.19 -> 2.0.51
node_modules/picomatch 2.3.1 -> 2.3.2
node_modules/prettier-linter-helpers 1.0.0 -> 1.0.1
node_modules/resolve 1.22.10 -> 1.22.12
node_modules/semver 7.7.2 -> 7.8.5
node_modules/strnum removed
node_modules/ts-jest 29.4.0 -> 29.4.11
node_modules/typescript 5.8.3 -> 5.9.3
node_modules/update-browserslist-db 1.1.3 -> 1.2.3
node_modules/uuid removed
node_modules/yargs 17.7.2 -> 17.7.3
node_modules/@aws-sdk/credential-provider-login added
node_modules/@aws-sdk/signature-v4-multi-region added
node_modules/@aws/lambda-invoke-store added
node_modules/@jridgewell/remapping added
node_modules/aws-cdk-lib/node_modules/@aws-cdk/cloud-assembly-api added
node_modules/baseline-browser-mapping added
node_modules/es-errors added
node_modules/handlebars added
node_modules/minimist added
node_modules/neo-async added
node_modules/uglify-js added
node_modules/wordwrap added

@aikido-autofix

Copy link
Copy Markdown
Author

Closed by Aikido: a new AutoFix has been created → #47

@aikido-autofix aikido-autofix Bot closed this Jul 21, 2026
@aikido-autofix
aikido-autofix Bot deleted the fix/aikido-security-update-packages-70602530-8n4q branch July 21, 2026 23:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

0 participants