pulumi / pulumi-policy-aws

A policy pack of rules to enforce AWS best practices for security, reliability, cost, and more!
https://www.pulumi.com
Apache License 2.0
35 stars 7 forks source link

Security vulnerability for cross-spawn #114

Open MitchellGerdisch opened 1 week ago

MitchellGerdisch commented 1 week ago

What happened?

Snyk scanning has found a security vulnerability. Introduced through @pulumi/awsguard@0.4.0 https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230

How to fix? Upgrade cross-spawn to version 6.0.6, 7.0.5 or higher.

Example

N/A

Output of pulumi about

N/A

Additional context

This was reported by a customer.

Contributing

Vote on this issue by adding a 👍 reaction. To contribute a fix for this issue, leave a comment (and link to your pull request, if you've opened one already).