Skip to content

chore: fix fast-xml-parser and minimatch vulnerability#3138

Open
Simone319 wants to merge 6 commits intomainfrom
dependabot/minimatch
Open

chore: fix fast-xml-parser and minimatch vulnerability#3138
Simone319 wants to merge 6 commits intomainfrom
dependabot/minimatch

Conversation

@Simone319
Copy link
Copy Markdown
Contributor

Problem

Update fast-xml-parser version to fix vulnerability in >= 4.1.3, < 4.5.4 and >= 5.0.0, < 5.3.6

Update minimatch version to fix vulnerability in< 3.1.4, >= 9.0.0, < 9.0.7, >= 10.0.0, < 10.2.3,

Changes

Corresponding docs PR, if applicable:

Validation

Checklist

  • If this PR includes a functional change to the runtime behavior of the code, I have added or updated automated test coverage for this change.
  • If this PR requires a change to the Project Architecture README, I have included that update in this PR.
  • If this PR requires a docs update, I have linked to that docs PR above.
  • If this PR modifies E2E tests, makes changes to resource provisioning, or makes SDK calls, I have run the PR checks with the run-e2e label set.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@Simone319 Simone319 requested a review from a team as a code owner March 11, 2026 10:49
@Simone319 Simone319 added the run-e2e Label that will include e2e tests in PR checks workflow label Mar 11, 2026
@Simone319 Simone319 requested a review from a team as a code owner March 11, 2026 10:49
@changeset-bot
Copy link
Copy Markdown

changeset-bot bot commented Mar 11, 2026

🦋 Changeset detected

Latest commit: 2292cf4

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 4 packages
Name Type
@aws-amplify/backend-platform-test-stubs Minor
@aws-amplify/integration-tests Minor
@aws-amplify/schema-generator Minor
@aws-amplify/ai-constructs Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@Simone319 Simone319 changed the title Dependabot/minimatch chore: fix fast-xml-parser and minimatch vulnerability Mar 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

run-e2e Label that will include e2e tests in PR checks workflow

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant