Skip to content

chore(deps): clear 6 Dependabot alerts (aws/cdk brace-expansion, examples aiohttp/cryptography) - #402

Open
kylehounslow wants to merge 2 commits into
opensearch-project:mainfrom
kylehounslow:security-sweep-cdk-brace-expansion
Open

chore(deps): clear 6 Dependabot alerts (aws/cdk brace-expansion, examples aiohttp/cryptography)#402
kylehounslow wants to merge 2 commits into
opensearch-project:mainfrom
kylehounslow:security-sweep-cdk-brace-expansion

examples: bump aiohttp and cryptography for open CVEs

3726d30
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Aug 6, 2026 in 3m 14s

Security Report

You have successfully remediated 2 vulnerabilities, but introduced 1 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2026-69152

Path to dependency file: /aws/cdk/package.json

Path to vulnerable library: /aws/cdk/package.json

Dependency Hierarchy:

-> aws-cdk-lib-2.263.0.tgz (Root Library)

   -> minimatch-10.2.5.tgz

     -> ❌ brace-expansion-5.0.8.tgz (Vulnerable Library)

High 7.5 Transitive brace-expansion-5.0.8.tgz aws-cdk-lib-2.263.0.tgz Transitive https://github.com/juliangruber/brace-expansion.git - v2.1.4,https://github.com/juliangruber/brace-expansion.git - v5.0.9,https://github.com/juliangruber/brace-expansion.git - v1.1.18,https://github.com/juliangruber/brace-expansion.git - v3.0.6 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2026-14257 brace-expansion-5.0.7.tgz
CVE-2026-69152 brace-expansion-5.0.7.tgz

Base branch total remaining vulnerabilities: 7
Base branch commit: 7cb4d76757d918595ec3771c6fc26a67930b3627


Total libraries scanned: 1033

Scan token: 90636386d8fe43b687fff764b183c48f