Skip to content

enterprise blueprint: resolve npm audit findings before deployment #30

Description

@dgallitelli

Summary

At main commit e6cf018, the enterprise-agentic-ai-platform-blueprint lockfile resolves aws-cdk-lib to 2.251.0, and a lockfile-only audit reports 7 vulnerable packages: 5 high, 1 moderate, and 1 low.

The highest-priority direct finding is GHSA-vcrf-j523-4mrf / CVE-2026-13760, an OS command-injection issue in NodejsFunction Docker bundling:

  • affected: aws-cdk-lib < 2.260.0
  • fixed: aws-cdk-lib 2.260.0
  • locked here: aws-cdk-lib 2.251.0
  • severity: high (CVSS 7.3)

This is a build/deployment-toolchain risk. Exploitation requires control of dependency version strings processed while Docker-based bundling is used with nodeModules; this finding alone is not evidence of remote exploitability in a deployed workload.

Audit findings

Package Severity Relationship
aws-cdk-lib High Direct dependency; also has a low-severity advisory
fast-uri High Transitive
brace-expansion High Transitive
browserslist High Transitive
js-yaml High Transitive
baseline-browser-mapping Moderate Transitive
@babel/core Low Transitive

Existing remediation PRs

Dependabot has already opened several relevant updates:

This issue is intended to track verification and closure across those PRs, rather than duplicate them.

Acceptance criteria

  • Merge or supersede chore(deps): bump aws-cdk-lib from 2.251.0 to 2.265.0 in /enterprise-agentic-ai-platform-blueprint #14 so aws-cdk-lib resolves to at least 2.260.0 (the current PR targets 2.265.0).
  • Merge or supersede the relevant transitive-dependency PRs and refresh the lockfile.
  • Run npm audit --package-lock-only and confirm there are no remaining high or critical findings.
  • Run the blueprint's build, lint, tests, and CDK synth after dependency updates.
  • Resolve the remaining low/moderate findings or document why they are accepted.

Verification performed

The finding was reproduced with a lockfile-only audit. No application code, tests, CDK synthesis, deployment, or AWS resources were run as part of this verification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions