Skip to content

Conversation

mend-for-github-com[bot]
Copy link
Contributor

@mend-for-github-com mend-for-github-com bot commented Aug 1, 2025

This PR contains the following updates:

Package Type Update Change
aws-cdk-lib (source) dependencies minor 2.88.0 -> 2.177.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
High High 8.1 CVE-2025-23206
Low Low 3.1 CVE-2025-5889

Release Notes

aws/aws-cdk (aws-cdk-lib)

v2.177.0

Compare Source

Features
Bug Fixes

Alpha modules (2.177.0-alpha.0)

⚠ BREAKING CHANGES TO EXPERIMENTAL FEATURES
  • glue-alpha: Developers must refactor their existing Job
    instantiation method calls to choose the right job type and language,
    and use the new constants static values to define the associated Job
    configuration settings. See the RFC and/or new README for examples.
Description of how you validated changes

Increased unit test coverage to > 90%, consulted with Glue service team
on best practices and sane defaults, updated integration tests.

Features
Bug Fixes
  • custom-resource-handlers: do not allow unauthorized connection for iam OIDC connection (under feature flag) (#​32921) (3e4f377), closes #​32920
Code Refactoring
  • glue-alpha: Refactored glue-alpha L2 CDK construct RFC 0497 (#​32521) (1a18dc9)

v2.176.0

Compare Source

Features
Bug Fixes
Reverts

Alpha modules (2.176.0-alpha.0)

Features
Bug Fixes

v2.175.1

Compare Source

Bug Fixes

Alpha modules (2.175.1-alpha.0)

v2.175.0

Compare Source

Features
Bug Fixes

Alpha modules (2.175.0-alpha.0)

Features
Bug Fixes

v2.174.1

Compare Source

Features

Alpha modules (2.174.1-alpha.0)

v2.174.0

Compare Source

Features
Bug Fixes
Reverts

Alpha modules (2.174.0-alpha.0)

Features
Bug Fixes

v2.173.4

Compare Source

Bug Fixes

Alpha modules (2.173.4-alpha.0)

v2.173.3

Compare Source

Bug Fixes

Alpha modules (2.173.3-alpha.0)

v2.173.2

Compare Source

Bug Fixes
  • cli: allow credential plugins to return null for expiration (#​32554) (e59b1db)
  • cli: doesn't support plugins that return initially empty credentials (#​32552) (7ee9b90)

Alpha modules (2.173.2-alpha.0)

v2.173.1

Compare Source

Bug Fixes
  • cli: getting credentials via SSO fails when the region is set in the profile (#​32520) (01fec04)

Alpha modules (2.173.1-alpha.0)

v2.173.0

Compare Source

Features
Bug Fixes

Alpha modules (2.173.0-alpha.0)

Features

v2.172.0

Compare Source

⚠ BREAKING CHANGES TO EXPERIMENTAL FEATURES
  • apigateway: We will be removing deprecated APIGatewayV2 constructs from aws-apigateway module.
Features
Bug Fixes

Alpha modules (2.172.0-alpha.0)

Features
Bug Fixes
  • scheduler-targets-alpha: incorrect validation of maximumEventAge (#​32284) (2eebc59)

v2.171.1

Compare Source

Bug Fixes

Alpha modules (2.171.1-alpha.0)

v2.171.0

Compare Source

Features
Bug Fixes

Alpha modules (2.171.0-alpha.0)

v2.170.0

Compare Source

Features
Bug Fixes
Reverts

Alpha modules (2.170.0-alpha.0)

v2.169.0

Compare Source

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Aug 1, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/aws-cdk-lib-2.x-lockfile branch 2 times, most recently from 3075377 to 84c3282 Compare August 12, 2025 05:05
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/aws-cdk-lib-2.x-lockfile branch from 84c3282 to fab678a Compare August 28, 2025 04:50
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/aws-cdk-lib-2.x-lockfile branch from fab678a to c417c58 Compare September 9, 2025 05:26
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/aws-cdk-lib-2.x-lockfile branch from c417c58 to 934c92c Compare September 16, 2025 07:52
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/aws-cdk-lib-2.x-lockfile branch 2 times, most recently from 33aa089 to 41acfaa Compare September 30, 2025 05:43
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/aws-cdk-lib-2.x-lockfile branch from 41acfaa to e77e2c0 Compare October 7, 2025 11:30
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/aws-cdk-lib-2.x-lockfile branch from e77e2c0 to 552cacf Compare October 13, 2025 17:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants