chore(deps): clear 24 Dependabot alerts across aws/cdk, docs, examples - #370
Merged
joshuali925 merged 5 commits intoJul 29, 2026
Merged
Conversation
aws-cdk-lib ^2.262.1 drops the vulnerable fast-uri transitive out of the tree entirely (opensearch-project#319, opensearch-project#321). esbuild override ^0.28.1 clears GHSA-67mh-4wv8-2f99 (opensearch-project#180, range >=0.27.3 <0.28.1). tsc passes. brace-expansion (opensearch-project#278, opensearch-project#329) is bundled inside aws-cdk-lib and not reachable by an override; tracked as deferred. Signed-off-by: Kyle Hounslow <kylhouns@amazon.com>
sharp override ^0.35.0 (resolves 0.35.3) clears GHSA-f88m-g3jw-g9cj (opensearch-project#324, range <0.35.0). astro is already 7.x on main; docs deps otherwise unchanged. 557/557 vitest pass, 135-page build, links valid. Signed-off-by: Kyle Hounslow <kylhouns@amazon.com>
…ss/vite/esbuild to clear CVEs astro ^6.4.8 clears GHSA-2pvr-wf23-7pc7, GHSA-jrpj-wcv7-9fh9 (opensearch-project#207, opensearch-project#208, range <6.4.6). Overrides: sharp 0.35.3 (opensearch-project#327), svgo 4.0.2 (opensearch-project#326), postcss 8.5.24 (opensearch-project#332), vite 7.3.6 (opensearch-project#198, opensearch-project#199), esbuild 0.28.1 (opensearch-project#179). astro 7.x-only CVEs (opensearch-project#281, opensearch-project#293, opensearch-project#294) require a major upgrade, deferred. Signed-off-by: Kyle Hounslow <kylhouns@amazon.com>
starlette 1.3.1 clears GHSA advisories (opensearch-project#176, opensearch-project#222, opensearch-project#223, opensearch-project#228, opensearch-project#229, Signed-off-by: Kyle Hounslow <kylhouns@amazon.com> opensearch-project#231, opensearch-project#232, opensearch-project#233, opensearch-project#234). idna 3.18 clears GHSA-jjg7-2v4v-x38h (opensearch-project#164, opensearch-project#165, opensearch-project#169). All three uv locks pass uv lock --check.
…canary Unwatched manifests held open alerts with no bot PR; add them so Dependabot cuts PRs going forward. Signed-off-by: Kyle Hounslow <kylhouns@amazon.com>
kylehounslow
requested review from
anirudha,
goyamegh,
joshuali925,
ps48 and
vamsimanohar
as code owners
July 29, 2026 00:40
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #370 +/- ##
=======================================
Coverage 55.62% 55.62%
=======================================
Files 4 4
Lines 169 169
Branches 47 47
=======================================
Hits 94 94
Misses 74 74
Partials 1 1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
joshuali925
approved these changes
Jul 29, 2026
Member
|
@joshuali925-osdbot check if there's any unnecessary change in the CVE fix PR, if so send a revert PR |
Contributor
|
On it — reviewing the merged CVE fix PR for any unnecessary changes. Will report back and open a revert PR if I find any. |
Contributor
|
Reviewed all changes in #370 against the alerts it set out to clear. Found one unnecessary change, and opened a revert: #382. Unnecessary — reverted in #382
Checked and kept (necessary / intended)
Revert PR: #382 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Clears 24 open Dependabot alerts across four manifests, plus a Dependabot coverage-gap fix. One commit per manifest group, all DCO-signed.
Alerts cleared (24)
aws/cdk (
fix(aws/cdk))aws-cdk-lib-> ^2.262.1: drops the vulnerablefast-uritransitive out of the tree entirely (chore(deps): bump js-yaml from 4.1.1 to 4.3.0 in /docs/starlight-docs #319, chore(release): bump CLI to 0.2.0 for GA #321)esbuildoverride ^0.28.1: GHSA-67mh-4wv8-2f99 (Add Astronomy Shop dashboard to init flow #180, range >=0.27.3 <0.28.1)docs (
fix(docs))sharpoverride ^0.35.0 (resolves 0.35.3): GHSA-f88m-g3jw-g9cj (chore(deps): bump mcp from 1.26.0 to 1.28.1 in /examples/agent-evals/genai-sdk #324, range <0.35.0). astro is already 7.x on main; no other docs deps changed.docs/starlight-docs (
fix(docs/starlight-docs))astro^6.4.8: GHSA-2pvr-wf23-7pc7, GHSA-jrpj-wcv7-9fh9 (Add PPL for SPL Users guide #207, feat: add insecure option for Prometheus remote write #208)sharp0.35.3 (chore(deps): bump astro from 6.3.7 to 7.1.0 in /docs #327),svgo4.0.2 (chore(deps): update dependency astro to v6.4.6 - autoclosed #326),postcss8.5.24 ([FEATURE] Support Optimized Engine (AWS Deploy) #332),vite7.3.6 (Add PPL for DQL/Lucene Users guide and fix playground links #198, chore(deps): bump @astrojs/react in /docs #199),esbuild0.28.1 (Switch to prod docker images for OpenSearch, Dashboards, and Data Prepper #179)examples (
fix(examples), 3 sample apps)starlette>=1.3.1 (bump cli to v0.1.1 and fix npm #176, chore(deps): update dependency astro to v6 - autoclosed #222, docs: Update architecture diagram image #223, chore(deps): bump python-multipart from 0.0.22 to 0.0.27 in /examples/strands/code-assistant #228, chore(deps): bump python-multipart from 0.0.22 to 0.0.27 in /examples/agent-evals/genai-sdk #229, chore(deps): bump fast-xml-builder from 1.1.4 to 1.2.0 in /aws/cli-installer #231, Feat/splunk distribution poc #232, chore(deps): bump langchain-core from 1.2.28 to 1.3.3 in /examples/langchain/bedrock-financial-assistant #233, [deps] Upgrade Data Prepper version from 2.15.0-SNAPSHOT-rc2 to 2.15.1 #234)idna>=3.15 (resolves 3.18) (chore(deps): bump vite from 6.4.1 to 6.4.2 in /docs/starlight-docs #164, Add APM setup and telemetry ingestion docs #165, Fix spans-per-trace slider not affecting storage calculations #169)Coverage gap (
chore(deps)).github/dependabot.yml: addaws/cdk,aws/cli-installer,examples/agent-evals/genai-sdk,docker-compose/agent-eval-canary. These manifests held open alerts with no bot PR.Validation
tsc --noEmitclean;fast-uriabsent from lockfile; esbuild 0.28.1uv lock --checkpass; idna 3.18, starlette 1.3.1 in every lockVulnerable ranges confirmed absent from each regenerated lockfile, not from a green Dependabot check.
Deferred (5)
brace-expansionstarlight-0.38.5.tgz: 3 vulnerabilities (highest severity is: 7.5) #278, chore(deps): bump pillow from 12.2.0 to 12.3.0 in /examples/strands/code-assistant #329 (aws/cdk): bundled insideaws-cdk-lib, not reachable by an npm override. Clears when aws-cdk-lib ships a fixed bundle.astrochore(deps): update dependency aws-cdk-lib to v2.250.0 #281, aws-cdk-lib-2.251.0.tgz: 8 vulnerabilities (highest severity is: 7.5) #293, vite-4.3.0.tgz: 2 vulnerabilities (highest severity is: 8.3) - autoclosed #294 (docs/starlight-docs): 7.x-only fixes requiring a breaking major upgrade of the starlight docs; out of scope for a routine dependency sweep.