Skip to content

fix(examples): remediate SQS and EC2 dependency advisories - #428

Merged
ulises-jeremias merged 2 commits into
mainfrom
fix/devops-reference-medium-low-security
Oct 5, 2026
Merged

ulises-jeremias merged 2 commits into
mainfrom
fix/devops-reference-medium-low-security

Conversation

@ulises-jeremias

@ulises-jeremias ulises-jeremias commented Oct 5, 2026 •

Copy link
Copy Markdown
Member

Description

  • Replace the unmaintained serverless-offline-sqs-external plugin with serverless-offline-sqs v9, align the sample with Serverless Framework v4, and move the CLI-only plugin to devDependencies.
  • Move the SQS example to Python 3.12, pin the local Python/Node tool versions, and update boto3 to 1.43.108 to remove vulnerable urllib3 1.26.20.
  • Migrate the scheduled EC2 example from AWS SDK v2 to @aws-sdk/client-ec2 v3, use Framework v4 native TypeScript support, and update its Node runtime to 24.
  • Track the remaining upstream-blocked LocalStack and NestJS advisories in security: replace legacy Serverless LocalStack dependency chain #426 and security: track js-yaml advisory in NestJS example #427.

Refs #426, #427

Type of Change

  • Bugfix (non-breaking change which fixes an issue)
  • Breaking change (runtime/toolchain requirements move to Node 24, Python 3.12 and Serverless Framework v4)
  • Documentation update

How Has This Been Tested?

  • npm ci and npm audit --audit-level=low passed in both examples under Node 24.21.0; each reports 0 vulnerabilities.
  • npx tsc --noEmit passed for the EC2 handlers under Node 24.21.0.
  • pip-audit -r app/send_to_queue/requirements.txt passed under Python 3.12.14; both Python handlers import successfully with the example's local SQS endpoint and region configured.
  • Parsed both changed serverless.yml files to validate YAML syntax.
  • Framework packaging was attempted for both services but requires a Serverless Framework v4 access or license key, which is not configured in this environment.

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have checked my code and corrected any misspellings

Guides and Examples

Only applies when this PR adds, renames, or moves a guide under examples/.

  • Back-reference exists.
  • Registered in examples.json.
  • Links resolve.
  • Sanitized.
  • No unsafe examples.

Summary by CodeRabbit

  • Updates
    • The SQS example now uses the Serverless Offline SQS plugin for LocalStack setup, with updated local development requirements for Node.js and Python.
    • The EC2 start/stop example now runs on Node.js 24 and uses the current AWS SDK for EC2 operations.
    • Both examples have updated Serverless Framework versions and setup guidance.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f95fd977-af9b-4fbb-a278-3558e52a4cd6
📥 Commits

Reviewing files that changed from the base of the PR and between ba0c012 and a09f75f.

⛔ Files ignored due to path filters (2)
  • examples/serverless-sqs-python/package-lock.json is excluded by !**/package-lock.json
  • examples/serverless-start-stop-ec2-instance/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (11)
  • examples/serverless-sqs-python/.node-version
  • examples/serverless-sqs-python/README.md
  • examples/serverless-sqs-python/app/send_to_queue/requirements.txt
  • examples/serverless-sqs-python/package.json
  • examples/serverless-sqs-python/serverless.yml
  • examples/serverless-start-stop-ec2-instance/.node-version
  • examples/serverless-start-stop-ec2-instance/README.md
  • examples/serverless-start-stop-ec2-instance/package.json
  • examples/serverless-start-stop-ec2-instance/serverless.yml
  • examples/serverless-start-stop-ec2-instance/src/handlers/start.ts
  • examples/serverless-start-stop-ec2-instance/src/handlers/stop.ts
 __________________________________________
< The GIL can't stop these rabbit threads. >
 ------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Warnings
⚠️ This PR is changing more than 10 files.
Messages
📖 Thanks for updating docs! We ❤️ documentation!
📖 Thanks! We ❤️ removing more lines than added!

Generated by 🚫 dangerJS against 558f596

@ulises-jeremias
ulises-jeremias merged commit 4f4b054 into main Oct 5, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant