Skip to content

Commit 215ea05

Browse files
fix: resolve @smithy/config-resolver security vulnerabilities (#6801)
* fix: resolve @smithy/config-resolver security vulnerabilities - Update AWS SDK packages to latest versions (3.967.0) - Update aws-amplify to 6.15.9 - Add resolution for @smithy/config-resolver ^4.4.5 to ensure all transitive dependencies use safe version - Keep environment packages using 'latest' for automatic security updates All @smithy/config-resolver versions now >= 4.4.0 (safe) Resolves Dependabot alerts #284, #283, #280, #276, #275
1 parent 37aab10 commit 215ea05

File tree

11 files changed

+3364
-3311
lines changed

11 files changed

+3364
-3311
lines changed

environments/liveness/liveness-environment/amplify/backend/function/livenessenvironment09873267/src/package-lock.json

Lines changed: 586 additions & 593 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

environments/liveness/liveness-environment/amplify/backend/function/livenessenvironment09873267/src/package.json

Lines changed: 2 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

environments/liveness/liveness-environment/amplify/backend/function/livenessenvironment3477af97/src/yarn.lock

Lines changed: 649 additions & 644 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

environments/liveness/liveness-environment/amplify/backend/function/livenessenvironment6105cfac/src/package-lock.json

Lines changed: 576 additions & 584 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

environments/liveness/liveness-environment/amplify/backend/function/livenessenvironment6105cfac/src/package.json

Lines changed: 2 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

environments/liveness/liveness-environment/amplify/backend/function/livenessenvironmentb20a0fc6/src/yarn.lock

Lines changed: 649 additions & 644 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

examples/next/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@
1616
"@aws-amplify/ui-react-liveness": "^3.5.0",
1717
"@aws-amplify/ui-react-notifications": "^2.2.14",
1818
"@aws-amplify/ui-react-storage": "^3.14.0",
19-
"@aws-sdk/credential-providers": "^3.370.0",
19+
"@aws-sdk/credential-providers": "^3.967.0",
2020
"next": "~16.0.0",
2121
"next-global-css": "^1.3.1",
2222
"react": "^18.3.0",

package.json

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,6 +72,7 @@
7272
]
7373
},
7474
"resolutions": {
75+
"@smithy/config-resolver": "^4.4.5",
7576
"@react-native-community/cli": "^17.0.1",
7677
"**/@react-native-community/**/fast-xml-parser": "^4.4.1",
7778
"**/@aws-*/**/fast-xml-parser": "^4.4.1",
@@ -146,7 +147,7 @@
146147
"@types/react-dom": "^18.3.0",
147148
"@types/react-test-renderer": "^18.3.0",
148149
"@vitejs/plugin-vue": "^2.3.4",
149-
"aws-amplify": "6.14.2",
150+
"aws-amplify": "6.15.9",
150151
"esbuild-register": "^3.5.0",
151152
"eslint": "^8.44.0",
152153
"fs-extra": "^11.1.1",

packages/react-liveness/package.json

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -44,15 +44,15 @@
4444
},
4545
"peerDependencies": {
4646
"@aws-amplify/core": "*",
47-
"aws-amplify": "^6.14.3",
47+
"aws-amplify": "^6.15.9",
4848
"react": "^16.14 || ^17 || ^18 || ^19",
4949
"react-dom": "^16.14 || ^17 || ^18 || ^19"
5050
},
5151
"dependencies": {
5252
"@aws-amplify/ui": "6.13.0",
5353
"@aws-amplify/ui-react": "6.13.2",
54-
"@aws-sdk/client-rekognitionstreaming": "3.828.0",
55-
"@aws-sdk/util-format-url": "3.609.0",
54+
"@aws-sdk/client-rekognitionstreaming": "3.967.0",
55+
"@aws-sdk/util-format-url": "3.965.0",
5656
"@smithy/eventstream-serde-browser": "^4.0.4",
5757
"@smithy/fetch-http-handler": "^5.0.4",
5858
"@smithy/protocol-http": "^3.0.3",
@@ -83,7 +83,7 @@
8383
"name": "FaceLivenessDetector",
8484
"path": "dist/esm/index.mjs",
8585
"import": "{ FaceLivenessDetector }",
86-
"limit": "225 kB"
86+
"limit": "228 kB"
8787
}
8888
]
8989
}

packages/react-storage/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -75,7 +75,7 @@
7575
"name": "StorageBrowser",
7676
"path": "dist/esm/index.mjs",
7777
"import": "{ StorageBrowser }",
78-
"limit": "92 kB"
78+
"limit": "93 kB"
7979
},
8080
{
8181
"name": "FileUploader",

0 commit comments

Comments
 (0)