Skip to content

Conversation

@sarayev
Copy link
Contributor

@sarayev sarayev commented Jan 14, 2026

Description of changes:

Resolves Dependabot security alert for @smithy/config-resolver (CVE CVSS 3.7 LOW - region validation vulnerability).

Changes:

  • Upgraded aws-amplify from ^6.0.9 to ^6.15.9 to get latest security updates
  • Added resolution for @smithy/config-resolver to ^4.4.5 to ensure all transitive dependencies use the patched version
  • All @smithy/config-resolver versions now >= 4.4.6 (safe)

Testing:

  • All 195 unit tests passing
  • Linter checks passing
  • No security vulnerabilities remaining for @smithy/config-resolver

This follows the same approach used in aws-amplify/amplify-ui PR #6801.

Related GitHub issue #, if available:

Fixes Dependabot security alert #117

Instructions

If this PR should not be merged upon approval for any reason, please submit as a DRAFT

Which product(s) are affected by this PR (if applicable)?

  • amplify-cli
  • amplify-ui
  • amplify-studio
  • amplify-hosting
  • amplify-libraries

Which platform(s) are affected by this PR (if applicable)?

  • JS
  • Swift
  • Android
  • Flutter
  • React Native

Please add the product(s)/platform(s) affected to the PR title

Checks

  • Does this PR conform to the styleguide?
  • Does this PR include filetypes other than markdown or images? Please add or update unit tests accordingly.
  • Are any files being deleted with this PR? If so, have the needed redirects been created?
  • Are all links in MDX files using the MDX link syntax rather than HTML link syntax?
    ref: MDX: [link](https://docs.amplify.aws/) HTML: <a href="https://docs.amplify.aws/">link</a>

When this PR is ready to merge, please check the box below

  • Ready to merge

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@sarayev sarayev merged commit 4f8080d into main Jan 15, 2026
12 of 13 checks passed
@sarayev sarayev deleted the dependabot/117 branch January 15, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants