Skip to content

Security Vulnerability in aws-cdk-lib v2.179.0 – Upgrade Required #61

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
hylickipiotr opened this issue Mar 25, 2025 · 7 comments
Open
Assignees

Comments

@hylickipiotr
Copy link

The project currently uses aws-cdk-lib v2.179.0, which is affected by a security vulnerability as per GHSA-5pq3-h73f-66hr. To mitigate this risk, the package must be upgraded to v2.184.0 or later.

@krmorse
Copy link

krmorse commented Mar 31, 2025

+1

1 similar comment
@teseo
Copy link

teseo commented Apr 2, 2025

+1

@krmorse
Copy link

krmorse commented Apr 3, 2025

I'm curious for this one how important it is that it's pinned to an exact version. I know currently that you get typescript errors if you're using a different cdk version in your project, but I doubt there is anything in SST that would break if we changed it to ^2.187.0 or similar...

Especially because this library releases multiple times per week, so it's immediately out of date

@revmischa
Copy link
Contributor

+1

@krmorse
Copy link

krmorse commented Apr 14, 2025

There is another vulnerability documented at GHSA-5pq3-h73f-66hr, so 2.189.0 is probably the minimum version now

@krmorse
Copy link

krmorse commented Apr 15, 2025

another vunlerabiliity, so minimum version should be 2.189.1 now...
GHSA-qc59-cxj2-c2w4

@krmorse
Copy link

krmorse commented Apr 16, 2025

i'm happy to take a crack at this but i wanted to do #69 first to make sure i understood the contrib process first

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants