Skip to content

Commit 9d5ad93

Browse files
authored
chore: remove patch-package from dependency (#32466)
### Reason for this change I don't see `patch-package` is used anywhere in the code and version is too old. Based on CVE-2024-21538 https://nvd.nist.gov/vuln/detail/CVE-2024-21538, it should be upgraded to at least 7.0.5. If it's not used anymore, we can remove it from the dependency. ### Description of changes Remove `patch-package` from dependency ### Description of how you validated changes ### Checklist - [ ] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
1 parent 0c2f98b commit 9d5ad93

File tree

2 files changed

+4
-111
lines changed

2 files changed

+4
-111
lines changed

package.json

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,6 @@
3030
"jsii-reflect": "1.104.0",
3131
"lerna": "^8.1.8",
3232
"nx": "^19.8.6",
33-
"patch-package": "^6.5.1",
3433
"semver": "^7.6.3",
3534
"standard-version": "^9.5.0",
3635
"ts-jest": "^29.2.5",

yarn.lock

Lines changed: 4 additions & 110 deletions
Original file line numberDiff line numberDiff line change
@@ -9527,11 +9527,6 @@ chownr@^2.0.0:
95279527
resolved "https://registry.npmjs.org/chownr/-/chownr-2.0.0.tgz#15bfbe53d2eab4cf70f18a8cd68ebe5b3cb1dece"
95289528
integrity sha512-bIomtDF5KGpdogkLd9VspvFzk9KfpyyGlS8YFVZl7TGPBHL5snIOnxeshwVgPteQ9b4Eydl+pVbIyE1DcvCWgQ==
95299529

9530-
ci-info@^2.0.0:
9531-
version "2.0.0"
9532-
resolved "https://registry.npmjs.org/ci-info/-/ci-info-2.0.0.tgz#67a9e964be31a51e15e5010d58e6f12834002f46"
9533-
integrity sha512-5tK7EtrZ0N+OLFMthtqOj4fI2Jeb88C4CAZPu25LDVUgXJ0A3Js4PMGqrn0JU1W0Mh1/Z8wZzYPxqUrXeBboCQ==
9534-
95359530
ci-info@^3.2.0:
95369531
version "3.9.0"
95379532
resolved "https://registry.npmjs.org/ci-info/-/ci-info-3.9.0.tgz#4279a62028a7b1f262f3473fc9605f5e218c59b4"
@@ -10271,17 +10266,6 @@ cross-fetch@^3.1.5:
1027110266
dependencies:
1027210267
node-fetch "^2.6.12"
1027310268

10274-
cross-spawn@^6.0.5:
10275-
version "6.0.5"
10276-
resolved "https://registry.npmjs.org/cross-spawn/-/cross-spawn-6.0.5.tgz#4a5ec7c64dfae22c3a14124dbacdee846d80cbc4"
10277-
integrity sha512-eTVLrBSt7fjbDygz805pMnstIs2VTBNkRm0qxZd+M7A5XDdxVRWO5MxGBXZhjY4cqLYLdtrGqRf8mBPmzwSpWQ==
10278-
dependencies:
10279-
nice-try "^1.0.4"
10280-
path-key "^2.0.1"
10281-
semver "^5.5.0"
10282-
shebang-command "^1.2.0"
10283-
which "^1.2.9"
10284-
1028510269
cross-spawn@^7.0.0, cross-spawn@^7.0.2, cross-spawn@^7.0.3:
1028610270
version "7.0.3"
1028710271
resolved "https://registry.npmjs.org/cross-spawn/-/cross-spawn-7.0.3.tgz#f73a85b9d5d41d045551c177e2882d4ac85728a6"
@@ -11718,13 +11702,6 @@ find-up@^4.0.0, find-up@^4.1.0:
1171811702
locate-path "^5.0.0"
1171911703
path-exists "^4.0.0"
1172011704

11721-
find-yarn-workspace-root@^2.0.0:
11722-
version "2.0.0"
11723-
resolved "https://registry.npmjs.org/find-yarn-workspace-root/-/find-yarn-workspace-root-2.0.0.tgz#f47fb8d239c900eb78179aa81b66673eac88f7bd"
11724-
integrity sha512-1IMnbjt4KzsQfnhnzNd8wUEgXZ44IzZaZmnLYx7D5FZlaHt2gW20Cri8Q+E/t5tIj4+epTBub+2Zxu/vNILzqQ==
11725-
dependencies:
11726-
micromatch "^4.0.2"
11727-
1172811705
flat-cache@^3.0.4:
1172911706
version "3.2.0"
1173011707
resolved "https://registry.npmjs.org/flat-cache/-/flat-cache-3.2.0.tgz#2c0c2d5040c99b1632771a9d105725c0115363ee"
@@ -11860,7 +11837,7 @@ fs-extra@^8.1.0:
1186011837
jsonfile "^4.0.0"
1186111838
universalify "^0.1.0"
1186211839

11863-
fs-extra@^9, fs-extra@^9.0.0, fs-extra@^9.1.0:
11840+
fs-extra@^9, fs-extra@^9.1.0:
1186411841
version "9.1.0"
1186511842
resolved "https://registry.npmjs.org/fs-extra/-/fs-extra-9.1.0.tgz#5954460c764a8da2094ba3554bf839e6b9a7c86d"
1186611843
integrity sha512-hcg3ZmepS30/7BSFqRvoo3DOMQu7IjqxO5nCDt+zM9XWjb33Wg7ziNT+Qvqbuc3+gWpzO02JubVyk2G4Zvo1OQ==
@@ -12782,13 +12759,6 @@ [email protected], is-ci@^3.0.1:
1278212759
dependencies:
1278312760
ci-info "^3.2.0"
1278412761

12785-
is-ci@^2.0.0:
12786-
version "2.0.0"
12787-
resolved "https://registry.npmjs.org/is-ci/-/is-ci-2.0.0.tgz#6bc6334181810e04b5c22b3d589fdca55026404c"
12788-
integrity sha512-YfJT7rkpQB0updsdHLGWrvhBJfcfzNNawYDNIyQXJz0IViGf75O8EBPKSdvw2rF+LGCsX4FZ8tcr3b19LcZq4w==
12789-
dependencies:
12790-
ci-info "^2.0.0"
12791-
1279212762
is-cidr@^4.0.2:
1279312763
version "4.0.2"
1279412764
resolved "https://registry.npmjs.org/is-cidr/-/is-cidr-4.0.2.tgz#94c7585e4c6c77ceabf920f8cde51b8c0fda8814"
@@ -13040,7 +13010,7 @@ is-windows@^1.0.2:
1304013010
resolved "https://registry.npmjs.org/is-windows/-/is-windows-1.0.2.tgz#d1850eb9791ecd18e6182ce12a30f396634bb19d"
1304113011
integrity sha512-eXK1UInq2bPmjyX6e3VHIzMLobc4J94i4AWn+Hpq3OU5KkrRC96OAcR3PRJ/pGu6m8TRnBHP9dkXQVsT/COVIA==
1304213012

13043-
is-wsl@^2.1.1, is-wsl@^2.2.0:
13013+
is-wsl@^2.2.0:
1304413014
version "2.2.0"
1304513015
resolved "https://registry.npmjs.org/is-wsl/-/is-wsl-2.2.0.tgz#74a4c76e77ca9fd3f932f290c17ea326cd157271"
1304613016
integrity sha512-fKzAra0rGJUUBwGBgNkHZuToZcn+TtXHpeCgmkMJMMYx1sQDYaCSyjJBSCa2nH1DGm7s3n1oBnohoVTBaN7Lww==
@@ -13908,13 +13878,6 @@ kind-of@^6.0.2, kind-of@^6.0.3:
1390813878
resolved "https://registry.npmjs.org/kind-of/-/kind-of-6.0.3.tgz#07c05034a6c349fa06e24fa35aa76db4580ce4dd"
1390913879
integrity sha512-dcS1ul+9tmeD95T+x28/ehLgd9mENa3LsvDTtzm3vyBEO7RPptvAD+t44WVXaUjTBRcrpFeFlC8WCruUR456hw==
1391013880

13911-
klaw-sync@^6.0.0:
13912-
version "6.0.0"
13913-
resolved "https://registry.npmjs.org/klaw-sync/-/klaw-sync-6.0.0.tgz#1fd2cfd56ebb6250181114f0a581167099c2b28c"
13914-
integrity sha512-nIeuVSzdCCs6TDPTqI8w1Yre34sSq7AkZ4B3sfOBbI2CgVSB4Du4aLQijFU2+lhAFCwt9+42Hel6lQNIv6AntQ==
13915-
dependencies:
13916-
graceful-fs "^4.1.11"
13917-
1391813881
kleur@^3.0.3:
1391913882
version "3.0.3"
1392013883
resolved "https://registry.npmjs.org/kleur/-/kleur-3.0.3.tgz#a79c9ecc86ee1ce3fa6206d1216c501f147fc07e"
@@ -14683,7 +14646,7 @@ methods@~1.1.2:
1468314646
resolved "https://registry.npmjs.org/methods/-/methods-1.1.2.tgz#5529a4d67654134edcc5266656835b0f851afcee"
1468414647
integrity sha512-iclAHeNqNm68zFtnZ0e+1L2yUIdvzNoauKU4WBA3VvH/vPFieF7qfRlwUZU+DA9P9bPXIS90ulxoUoCH23sV2w==
1468514648

14686-
micromatch@^4.0.2, micromatch@^4.0.4:
14649+
micromatch@^4.0.4:
1468714650
version "4.0.8"
1468814651
resolved "https://registry.npmjs.org/micromatch/-/micromatch-4.0.8.tgz#d66fa18f3a47076789320b9b1af32bd86d9fa202"
1468914652
integrity sha512-PXwfBhYu0hBCPw8Dn0E+WDYb7af3dSLVWKi3HGv84IdF4TyFoC0ysxFd0Goxw7nSv4T/PzEJQxsYsEiFCKo2BA==
@@ -15067,11 +15030,6 @@ next-tick@^1.1.0:
1506715030
resolved "https://registry.npmjs.org/next-tick/-/next-tick-1.1.0.tgz#1836ee30ad56d67ef281b22bd199f709449b35eb"
1506815031
integrity sha512-CXdUiJembsNjuToQvxayPZF9Vqht7hewsvy2sOWafLvi2awflj9mOC6bHIg50orX8IJvWKY9wYQ/zB2kogPslQ==
1506915032

15070-
nice-try@^1.0.4:
15071-
version "1.0.5"
15072-
resolved "https://registry.npmjs.org/nice-try/-/nice-try-1.0.5.tgz#a3378a7696ce7d223e88fc9b764bd7ef1089e366"
15073-
integrity sha512-1nh45deeb5olNY7eX82BkPO7SSxR5SSYJiPTrTdFUVYwAl8CKMA5N9PjTYkHiRjisVcxcQ1HXdLhx2qxxJzLNQ==
15074-
1507515033
nise@^4.0.4:
1507615034
version "4.1.0"
1507715035
resolved "https://registry.npmjs.org/nise/-/nise-4.1.0.tgz#8fb75a26e90b99202fa1e63f448f58efbcdedaf6"
@@ -15820,14 +15778,6 @@ oo-ascii-tree@^1.104.0:
1582015778
resolved "https://registry.npmjs.org/oo-ascii-tree/-/oo-ascii-tree-1.104.0.tgz#f17857f84f25b0b9d0879bbea2f04caf15a72384"
1582115779
integrity sha512-2cScXtwxt5WVIi3+vdkbKoHSeRepRcibnFhdV2ojGxVvj1KU0m0EHfBCsal6XEg1vBkMgTIxnxVd+E/l/Fam3w==
1582215780

15823-
open@^7.4.2:
15824-
version "7.4.2"
15825-
resolved "https://registry.npmjs.org/open/-/open-7.4.2.tgz#b8147e26dcf3e426316c730089fd71edd29c2321"
15826-
integrity sha512-MVHddDVweXZF3awtlAS+6pgKLlm/JgxZ90+/NBurBoQctVOOB/zDdVjcyPzQ+0laDGbsWgrRkflI65sQeOgT9Q==
15827-
dependencies:
15828-
is-docker "^2.0.0"
15829-
is-wsl "^2.1.1"
15830-
1583115781
open@^8.4.0:
1583215782
version "8.4.2"
1583315783
resolved "https://registry.npmjs.org/open/-/open-8.4.2.tgz#5b5ffe2a8f793dcd2aad73e550cb87b59cb084f9"
@@ -16235,26 +16185,6 @@ pascal-case@^3.1.2:
1623516185
no-case "^3.0.4"
1623616186
tslib "^2.0.3"
1623716187

16238-
patch-package@^6.5.1:
16239-
version "6.5.1"
16240-
resolved "https://registry.npmjs.org/patch-package/-/patch-package-6.5.1.tgz#3e5d00c16997e6160291fee06a521c42ac99b621"
16241-
integrity sha512-I/4Zsalfhc6bphmJTlrLoOcAF87jcxko4q0qsv4bGcurbr8IskEOtdnt9iCmsQVGL1B+iUhSQqweyTLJfCF9rA==
16242-
dependencies:
16243-
"@yarnpkg/lockfile" "^1.1.0"
16244-
chalk "^4.1.2"
16245-
cross-spawn "^6.0.5"
16246-
find-yarn-workspace-root "^2.0.0"
16247-
fs-extra "^9.0.0"
16248-
is-ci "^2.0.0"
16249-
klaw-sync "^6.0.0"
16250-
minimist "^1.2.6"
16251-
open "^7.4.2"
16252-
rimraf "^2.6.3"
16253-
semver "^5.6.0"
16254-
slash "^2.0.0"
16255-
tmp "^0.0.33"
16256-
yaml "^1.10.2"
16257-
1625816188
path-browserify@^1.0.1:
1625916189
version "1.0.1"
1626016190
resolved "https://registry.npmjs.org/path-browserify/-/path-browserify-1.0.1.tgz#d98454a9c3753d5790860f16f68867b9e46be1fd"
@@ -16288,11 +16218,6 @@ path-is-absolute@^1.0.0:
1628816218
resolved "https://registry.npmjs.org/path-is-absolute/-/path-is-absolute-1.0.1.tgz#174b9268735534ffbc7ace6bf53a5a9e1b5c5f5f"
1628916219
integrity sha512-AVbw3UJ2e9bq64vSaS9Am0fje1Pa8pbGqTTsmXfaIiMpnr5DlDhfJOuLj9Sf95ZPVDAUerDfEk88MPmPe7UCQg==
1629016220

16291-
path-key@^2.0.1:
16292-
version "2.0.1"
16293-
resolved "https://registry.npmjs.org/path-key/-/path-key-2.0.1.tgz#411cadb574c5a140d3a4b1910d40d80cc9f40b40"
16294-
integrity sha512-fEHGKCSmUSDPv4uoj8AlD+joPlq3peND+HRYyxFz4KPw4z926S/b8rIuFs2FYJg3BwsxJf6A9/3eIdLaYC+9Dw==
16295-
1629616221
path-key@^3.0.0, path-key@^3.1.0:
1629716222
version "3.1.1"
1629816223
resolved "https://registry.npmjs.org/path-key/-/path-key-3.1.1.tgz#581f6ade658cbba65a0d3380de7753295054f375"
@@ -17119,13 +17044,6 @@ rfdc@^1.3.0:
1711917044
resolved "https://registry.npmjs.org/rfdc/-/rfdc-1.4.1.tgz#778f76c4fb731d93414e8f925fbecf64cce7f6ca"
1712017045
integrity sha512-q1b3N5QkRUWUl7iyylaaj3kOpIT0N2i9MqIEQXP73GVsN9cw3fdx8X63cEmWhJGi2PPCF23Ijp7ktmd39rawIA==
1712117046

17122-
rimraf@^2.6.3:
17123-
version "2.7.1"
17124-
resolved "https://registry.npmjs.org/rimraf/-/rimraf-2.7.1.tgz#35797f13a7fdadc566142c29d4f07ccad483e3ec"
17125-
integrity sha512-uWjbaKIK3T1OSVptzX7Nl6PvQ3qAGtKEtVRjRuazjfL3Bx5eI409VZSqgND+4UNnmzLVdPj9FqFJNPqBZFve4w==
17126-
dependencies:
17127-
glob "^7.1.3"
17128-
1712917047
rimraf@^3.0.0, rimraf@^3.0.2:
1713017048
version "3.0.2"
1713117049
resolved "https://registry.npmjs.org/rimraf/-/rimraf-3.0.2.tgz#f1a5402ba6220ad52cc1282bac1ae3aa49fd061a"
@@ -17355,25 +17273,13 @@ shallow-clone@^3.0.0:
1735517273
dependencies:
1735617274
kind-of "^6.0.2"
1735717275

17358-
shebang-command@^1.2.0:
17359-
version "1.2.0"
17360-
resolved "https://registry.npmjs.org/shebang-command/-/shebang-command-1.2.0.tgz#44aac65b695b03398968c39f363fee5deafdf1ea"
17361-
integrity sha512-EV3L1+UQWGor21OmnvojK36mhg+TyIKDh3iFBKBohr5xeXIhNBcx8oWdgkTEEQ+BEFFYdLRuqMfd5L84N1V5Vg==
17362-
dependencies:
17363-
shebang-regex "^1.0.0"
17364-
1736517276
shebang-command@^2.0.0:
1736617277
version "2.0.0"
1736717278
resolved "https://registry.npmjs.org/shebang-command/-/shebang-command-2.0.0.tgz#ccd0af4f8835fbdc265b82461aaf0c36663f34ea"
1736817279
integrity sha512-kHxr2zZpYtdmrN1qDjrrX/Z1rR1kG8Dx+gkpK1G4eXmvXswmcE1hTWBWYUzlraYw1/yZp6YuDY77YtvbN0dmDA==
1736917280
dependencies:
1737017281
shebang-regex "^3.0.0"
1737117282

17372-
shebang-regex@^1.0.0:
17373-
version "1.0.0"
17374-
resolved "https://registry.npmjs.org/shebang-regex/-/shebang-regex-1.0.0.tgz#da42f49740c0b42db2ca9728571cb190c98efea3"
17375-
integrity sha512-wpoSFAxys6b2a2wHZ1XpDSgD7N9iVjg29Ph9uV/uaP9Ex/KXlkTZTeddxDPSYQpgvzKLGJke2UU0AzoGCjNIvQ==
17376-
1737717283
shebang-regex@^3.0.0:
1737817284
version "3.0.0"
1737917285
resolved "https://registry.npmjs.org/shebang-regex/-/shebang-regex-3.0.0.tgz#ae16f1644d873ecad843b0307b143362d4c42172"
@@ -17477,11 +17383,6 @@ [email protected], slash@^3.0.0:
1747717383
resolved "https://registry.npmjs.org/slash/-/slash-3.0.0.tgz#6539be870c165adbd5240220dbe361f1bc4d4634"
1747817384
integrity sha512-g9Q1haeby36OSStwb4ntCGGGaKsaVSjQ68fBxoQcutl5fS1vuY18H3wSt3jFyFtrkx+Kz0V1G85A4MyAdDMi2Q==
1747917385

17480-
slash@^2.0.0:
17481-
version "2.0.0"
17482-
resolved "https://registry.npmjs.org/slash/-/slash-2.0.0.tgz#de552851a1759df3a8f206535442f5ec4ddeab44"
17483-
integrity sha512-ZYKh3Wh2z1PpEXWr0MpSBZ0V6mZHAQfYevttO11c51CaWjGTaadiKZ+wVt1PbMlDV5qhMFslpZCemhwOK7C89A==
17484-
1748517386
slice-ansi@^4.0.0:
1748617387
version "4.0.0"
1748717388
resolved "https://registry.npmjs.org/slice-ansi/-/slice-ansi-4.0.0.tgz#500e8dd0fd55b05815086255b3195adf2a45fe6b"
@@ -18852,13 +18753,6 @@ which-typed-array@^1.1.2:
1885218753
gopd "^1.0.1"
1885318754
has-tostringtag "^1.0.2"
1885418755

18855-
which@^1.2.9:
18856-
version "1.3.1"
18857-
resolved "https://registry.npmjs.org/which/-/which-1.3.1.tgz#a45043d54f5805316da8d62f9f50918d3da70b0a"
18858-
integrity sha512-HxJdYWq1MTIQbJ3nw0cqssHoTNU267KlrDuGZ1WYlxDStUtKUhOaJmh112/TZmHxxUfuJqPXSOm7tDyas0OSIQ==
18859-
dependencies:
18860-
isexe "^2.0.0"
18861-
1886218756
which@^2.0.1, which@^2.0.2:
1886318757
version "2.0.2"
1886418758
resolved "https://registry.npmjs.org/which/-/which-2.0.2.tgz#7c6a8dd0a636a0327e10b59c9286eee93f3f51b1"
@@ -19109,7 +19003,7 @@ yallist@^4.0.0:
1910919003
resolved "https://registry.npmjs.org/yallist/-/yallist-4.0.0.tgz#9bb92790d9c0effec63be73519e11a35019a3a72"
1911019004
integrity sha512-3wdGidZyq5PB084XLES5TpOSRA3wjXAlIWMhum2kRcv/41Sn2emQ0dycQW4uZXLejwKvg6EsvbdlVL+FYEct7A==
1911119005

19112-
[email protected], yaml@^1.10.0, yaml@^1.10.2:
19006+
[email protected], yaml@^1.10.0:
1911319007
version "1.10.2"
1911419008
resolved "https://registry.npmjs.org/yaml/-/yaml-1.10.2.tgz#2301c5ffbf12b467de8da2333a459e29e7920e4b"
1911519009
integrity sha512-r3vXyErRCYJ7wg28yvBY5VSoAF8ZvlcW9/BwUzEtUsjvX/DKs24dIkuwjtuprwJJHsbyUbLApepYTR1BN4uHrg==

0 commit comments

Comments
 (0)