An open index of dependabot pull requests across open source projects.

aws-cdk-lib

Ecosystem:
npm
Package URL:
pkg:npm/aws-cdk-lib
Total PRs:
3,901 Dependabot PRs
Latest PR:
3 days ago
Unique Repositories:
716 repositories
Unique Repos (30 days):
26 repositories
Security Advisories
AWS Cloud Development Kit (AWS CDK) IAM OIDC custom resource allows connection to unauthorized OIDC provider
GHSA-v4mq-x674-ff73 CVE-2025-23206 LOW published over 1 year ago • updated 10 days ago
### Impact Users who use IAM OIDC custom resource provider package will download CA Thumbprints as part of the custom resource workflow, https://gi...
AWS CDK CodePipeline: trusted entities are too broad
GHSA-5pq3-h73f-66hr LOW published about 1 year ago • updated 3 months ago
### Summary The [AWS Cloud Development Kit (CDK)](https://aws.amazon.com/cdk/) is an open-source framework for defining cloud infrastructure using...
aws-cdk-lib: OS Command Injection in NodejsFunction Bundling
GHSA-999r-qq7v-r334 CVE-2026-11417 HIGH published 3 days ago • updated 3 days ago
### Summary AWS CDK (`aws-cdk-lib`) is an open-source framework for defining cloud infrastructure in code and provisioning it through AWS CloudForm...
aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role
GHSA-qc59-cxj2-c2w4 LOW published about 1 year ago • updated 3 months ago
### Summary The [AWS Cloud Development Kit (AWS CDK)](https://aws.amazon.com/cdk/) is an open-source software development framework for defining c...
aws-cdk-lib has Insertion of Sensitive Information into Log File vulnerability when using Cognito UserPoolClient Construct
GHSA-qq4x-c6h6-rfxh MODERATE published about 1 year ago • updated 3 months ago
### Summary The [AWS Cloud Development Kit (CDK)](https://aws.amazon.com/cdk/) is an open-source framework for defining cloud infrastructure using ...
Recent PRs (filtered by: Patch PRs )
Bump the miscs group with 3 updates

poad/aws-oidc-role #1763

2.203.0 → 2.203.1 Patch PR
Merged 12 months ago 1 comment
poad
Bump the miscs group with 5 updates

poad/aws-setup #1710

2.203.0 → 2.203.1 Patch PR
Merged 12 months ago 2 comments
poad
Package Details
Name: aws-cdk-lib
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/aws-cdk-lib
JSON API: View JSON
Security Advisories

6

Active advisories
HIGH 1
MODERATE 2
LOW 3
View All npm Advisories
Package Information
Description:

Version 2 of the AWS Cloud Development Kit library

Repository: https://github.com/aws/aws-cdk
Homepage: https://github.com/aws/aws-cdk
Latest Release: 2.200.0
about 1 year ago
Dependent Repos: 4,665
Dependent Packages: 2,095
Downloads: 7,689,082
Ranking: Top 0.3394% by dependent repos Top 0.1235% by downloads Top 0.0423% by dependent pkgs
PR Status
Open 1,549 (39.7%)
Merged 901 (23.1%)
Closed 1,083 (27.8%)
PR Types
Major 4 (0.1%)
Minor 3,341 (85.6%)
Patch 174 (4.5%)