Skip to content

chore(deps): update dependency aws-cdk-lib to v2.260.0 - #289

Closed
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/aws-cdk-lib-2.x-lockfile
Closed

chore(deps): update dependency aws-cdk-lib to v2.260.0#289
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/aws-cdk-lib-2.x-lockfile

chore(deps): update dependency aws-cdk-lib to v2.260.0

4ed720c
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Jul 27, 2026 in 2m 26s

Security Report

You have successfully remediated 8 vulnerabilities, but introduced 4 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-16221

Path to dependency file: /aws/cdk/package.json

Path to vulnerable library: /aws/cdk/package.json

Dependency Hierarchy:

-> aws-cdk-lib-2.260.0.tgz (Root Library)

   -> table-6.9.0.tgz

     -> ajv-8.20.0.tgz

       -> ❌ fast-uri-3.1.2.tgz (Vulnerable Library)

High 7.5 Transitive fast-uri-3.1.2.tgz aws-cdk-lib-2.260.0.tgz Transitive 3.1.4 None
CVE-2026-14257

Path to dependency file: /aws/cdk/package.json

Path to vulnerable library: /aws/cdk/package.json

Dependency Hierarchy:

-> aws-cdk-lib-2.260.0.tgz (Root Library)

   -> minimatch-10.2.5.tgz

     -> ❌ brace-expansion-5.0.6.tgz (Vulnerable Library)

High 7.5 Transitive brace-expansion-5.0.6.tgz aws-cdk-lib-2.260.0.tgz Transitive 5.0.8 None
CVE-2026-13676

Path to dependency file: /aws/cdk/package.json

Path to vulnerable library: /aws/cdk/package.json

Dependency Hierarchy:

-> aws-cdk-lib-2.260.0.tgz (Root Library)

   -> table-6.9.0.tgz

     -> ajv-8.20.0.tgz

       -> ❌ fast-uri-3.1.2.tgz (Vulnerable Library)

High 7.5 Transitive fast-uri-3.1.2.tgz aws-cdk-lib-2.260.0.tgz Transitive 3.1.3 None
CVE-2026-13149

Path to dependency file: /aws/cdk/package.json

Path to vulnerable library: /aws/cdk/package.json

Dependency Hierarchy:

-> aws-cdk-lib-2.260.0.tgz (Root Library)

   -> minimatch-10.2.5.tgz

     -> ❌ brace-expansion-5.0.6.tgz (Vulnerable Library)

High 7.5 Transitive brace-expansion-5.0.6.tgz aws-cdk-lib-2.260.0.tgz Transitive https://github.com/juliangruber/brace-expansion.git - v5.0.7 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-13149 brace-expansion-5.0.5.tgz
CVE-2026-16221 fast-uri-3.1.0.tgz
CVE-2026-14257 brace-expansion-5.0.5.tgz
CVE-2026-13676 fast-uri-3.1.0.tgz
CVE-2026-13760 aws-cdk-lib-2.251.0.tgz
CVE-2026-45149 brace-expansion-5.0.5.tgz
CVE-2026-6321 fast-uri-3.1.0.tgz
CVE-2026-6322 fast-uri-3.1.0.tgz

Base branch total remaining vulnerabilities: 44
Base branch commit: b48bb7d0f5ffb4d3caad8c7e021e6c0c94d54b74


Total libraries scanned: 966

Scan token: a912f85bbcbe40928d80a1b6cff0a3b5