Skip to content

chore: override tar to ^7.5.19, shell-quote to ^1.9.0, axios to ^1.18.0, brace-expansion to ^5.0.8 - #285

Merged
sachinh-amazon merged 2 commits into
1.2from
fix/override-security-findings-1.2
Jul 27, 2026
Merged

chore: override tar to ^7.5.19, shell-quote to ^1.9.0, axios to ^1.18.0, brace-expansion to ^5.0.8#285
sachinh-amazon merged 2 commits into
1.2from
fix/override-security-findings-1.2

Conversation

@sachinh-amazon

Copy link
Copy Markdown
Contributor

Issue

Description of Changes

Bumps npm dependency override versions flagged by the nightly Security Scan (Amazon Inspector, code-editor-sagemaker-server target) and regenerates the affected package-lock overrides + OSS attribution.

  • tar: ^7.5.16^7.5.19
  • shell-quote: ^1.8.4^1.9.0
  • axios: ^1.15.2^1.18.0
  • brace-expansion (in build-tools/oss-attribution/oss-attribution-generator): ^5.0.6^5.0.8

The finding-override-ws.diff patch is refreshed only to update its context around the axios line (the ws override versions are unchanged: ws ^8.21.0, nested chrome-remote-interface ws ^7.5.11).

Testing

  • ./scripts/prepare-src.sh code-editor-sagemaker-server applies the full patch series cleanly.
  • ./scripts/update-package-locks.sh regenerates lockfiles + OSS attribution for all four targets with no errors.
  • Verified resolved versions in package-lock-overrides/sagemaker.series/package-lock.json (and remote/): tar 7.5.22, axios 1.18.1, shell-quote 1.10.0, top-level ws 8.21.0 — all at or above the required fixed versions. brace-expansion resolves to 5.0.8 in the build-tool lockfile.

Screenshots/Videos

N/A

Additional Notes

Override-only change; no source/behavior changes. Follows the established finding-override-*.diff pattern (e.g. the prior undici/ws/form-data override PR). Patch headers use the deterministic @generator metadata so they can be regenerated on upstream bumps.

Backporting

The same fix is being raised in parallel against main, 1.0, 1.1, and 1.2. The set of affected packages differs per branch (older branches were only flagged for tar and brace-expansion).


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@sachinh-amazon
sachinh-amazon requested a review from a team as a code owner July 27, 2026 13:14
@sachinh-amazon
sachinh-amazon added this pull request to the merge queue Jul 27, 2026
Merged via the queue into 1.2 with commit f80c7b3 Jul 27, 2026
1 check passed
@sachinh-amazon
sachinh-amazon deleted the fix/override-security-findings-1.2 branch July 27, 2026 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants