fix: Security updates #467
Open
StepSecurity Actions Security / StepSecurity Required Checks
succeeded
Mar 2, 2026 in 11s
StepSecurity Required Checks
Finished StepSecurity Required Checks
- NPM Package Cooldown Check - Fails if any package version in the PR was released within the configured cooldown period, helping to avoid brand-new (and potentially unreviewed or malicious) releases
- Pwn Request Vulnerabilities Check - Checks for Pwn Request vulnerabilities in the PR via risky triggers
- Script Injection Check - Checks for script injection vulnerabilities in the PR
- NPM Compromised Packages Check - Checks for compromised npm package versions in the PR
Details
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
✅ NPM Package Cooldown Check
No npm package upgrades to recent releases found in current PR.
The following npm packages are inspected in current PR (showing first 50 of 66 packages)
| Package Name | Previous Version | Current Version | file | Current Version Release Date |
|---|---|---|---|---|
| strnum | 2.1.2 | 2.2.0 | package-lock.json | 2026-02-28T08:24:13Z |
| @aws-sdk/lib-dynamodb | 3.993.0 | 3.1000.0 | package-lock.json | 2026-02-27T20:07:13Z |
| @aws-sdk/client-dynamodb | 3.993.0 | 3.1000.0 | package-lock.json | 2026-02-27T20:01:31Z |
| @aws-sdk/util-user-agent-node | 3.972.9 | 3.973.0 | package-lock.json | 2026-02-26T20:06:01Z |
| @aws-sdk/xml-builder | 3.972.5 | 3.972.8 | package-lock.json | 2026-02-26T20:06:01Z |
| @aws-sdk/util-user-agent-browser | 3.972.3 | 3.972.6 | package-lock.json | 2026-02-26T20:06:01Z |
| @aws-sdk/util-endpoints | 3.993.0 | 3.996.3 | package-lock.json | 2026-02-26T20:06:00Z |
| @aws-sdk/nested-clients | 3.993.0 | 3.996.3 | package-lock.json | 2026-02-26T20:05:55Z |
| @aws-sdk/region-config-resolver | 3.972.3 | 3.972.6 | package-lock.json | 2026-02-26T20:05:54Z |
| @aws-sdk/middleware-user-agent | 3.972.11 | 3.972.15 | package-lock.json | 2026-02-26T20:05:54Z |
| @aws-sdk/types | 3.973.1 | 3.973.4 | package-lock.json | 2026-02-26T20:05:54Z |
| @aws-sdk/middleware-logger | 3.972.3 | 3.972.6 | package-lock.json | 2026-02-26T20:05:39Z |
| @aws-sdk/middleware-recursion-detection | 3.972.3 | 3.972.6 | package-lock.json | 2026-02-26T20:05:39Z |
| @aws-sdk/middleware-endpoint-discovery | 3.972.3 | 3.972.6 | package-lock.json | 2026-02-26T20:05:33Z |
| @aws-sdk/middleware-host-header | 3.972.3 | 3.972.6 | package-lock.json | 2026-02-26T20:05:32Z |
| @aws-sdk/credential-provider-sso | 3.972.9 | 3.972.13 | package-lock.json | 2026-02-26T20:05:26Z |
| @aws-sdk/credential-provider-login | 3.972.9 | 3.972.13 | package-lock.json | 2026-02-26T20:05:25Z |
| @aws-sdk/credential-provider-process | 3.972.9 | 3.972.13 | package-lock.json | 2026-02-26T20:05:25Z |
| @aws-sdk/credential-provider-web-identity | 3.972.9 | 3.972.13 | package-lock.json | 2026-02-26T20:05:25Z |
| @aws-sdk/endpoint-cache | 3.972.2 | 3.972.3 | package-lock.json | 2026-02-26T20:05:25Z |
| @aws-sdk/credential-provider-node | 3.972.10 | 3.972.14 | package-lock.json | 2026-02-26T20:05:25Z |
| @aws-sdk/dynamodb-codec | 3.972.12 | 3.972.16 | package-lock.json | 2026-02-26T20:05:25Z |
| @aws-sdk/core | 3.973.11 | 3.973.15 | package-lock.json | 2026-02-26T20:05:18Z |
| @aws-sdk/credential-provider-env | 3.972.9 | 3.972.13 | package-lock.json | 2026-02-26T20:05:18Z |
| @aws-sdk/credential-provider-ini | 3.972.9 | 3.972.13 | package-lock.json | 2026-02-26T20:05:18Z |
| @aws-sdk/token-providers | 3.993.0 | 3.999.0 | package-lock.json | 2026-02-26T20:04:54Z |
| minimatch | 3.1.3 | 3.1.5 | package-lock.json | 2026-02-25T17:17:15Z |
| @aws-sdk/util-dynamodb | 3.993.0 | 3.996.1 | package-lock.json | 2026-02-24T20:07:24Z |
| @smithy/util-retry | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:28Z |
| @smithy/util-stream | 4.5.12 | 4.5.15 | package-lock.json | 2026-02-24T20:04:28Z |
| @smithy/util-waiter | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:28Z |
| @smithy/util-middleware | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:27Z |
| @smithy/url-parser | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:27Z |
| @smithy/util-endpoints | 3.2.8 | 3.3.1 | package-lock.json | 2026-02-24T20:04:27Z |
| @smithy/util-defaults-mode-browser | 4.3.32 | 4.3.36 | package-lock.json | 2026-02-24T20:04:27Z |
| @smithy/types | 4.12.0 | 4.13.0 | package-lock.json | 2026-02-24T20:04:27Z |
| @smithy/util-defaults-mode-node | 4.2.35 | 4.2.39 | package-lock.json | 2026-02-24T20:04:27Z |
| @smithy/smithy-client | 4.11.5 | 4.12.0 | package-lock.json | 2026-02-24T20:04:26Z |
| @smithy/signature-v4 | 5.3.8 | 5.3.10 | package-lock.json | 2026-02-24T20:04:25Z |
| @smithy/shared-ini-file-loader | 4.4.3 | 4.4.5 | package-lock.json | 2026-02-24T20:04:25Z |
| @smithy/querystring-parser | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:25Z |
| @smithy/querystring-builder | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:24Z |
| @smithy/service-error-classification | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:24Z |
| @smithy/node-config-provider | 4.3.8 | 4.3.10 | package-lock.json | 2026-02-24T20:04:24Z |
| @smithy/property-provider | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:24Z |
| @smithy/middleware-serde | 4.2.9 | 4.2.11 | package-lock.json | 2026-02-24T20:04:23Z |
| @smithy/middleware-stack | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:23Z |
| @smithy/middleware-endpoint | 4.4.16 | 4.4.20 | package-lock.json | 2026-02-24T20:04:22Z |
| @smithy/middleware-content-length | 4.2.8 | 4.2.10 | package-lock.json | 2026-02-24T20:04:22Z |
| @smithy/middleware-retry | 4.4.33 | 4.4.37 | package-lock.json | 2026-02-24T20:04:22Z |
⏲️ History
Previous invocation results of same check:
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
❌ NPM Package Cooldown Check
⏲️ History
Previous invocation results of same check:
✅ Script Injection Vulnerabilities Check
No Script Injection vulnerabilities found in this PR.
✅ Pwn Request Vulnerabilities Check
No Pwn Request vulnerabilities found in this PR.
✅ NPM Compromised Packages Check
No Compromised npm packages are added in current PR.
❌ NPM Package Cooldown Check
⏲️ History
Previous invocation results of same check:
Loading