Skip to content

fix(lambda): bump @middy/core from 6.4.5 to 7.7.0 in /lambdas - #4999

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/lambdas/middy/core-7.0.2
Closed

fix(lambda): bump @middy/core from 6.4.5 to 7.7.0 in /lambdas#4999
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/lambdas/middy/core-7.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 16, 2026

Copy link
Copy Markdown
Contributor

Bumps @middy/core from 6.4.5 to 7.7.0.

Release notes

Sourced from @​middy/core's releases.

7.7.0

What's Changed

  • Update @aws/durable-execution-sdk-js to v2 - May cause Type breaking change
  • Update core to use new SDK for improved executionMode detection

Security hardening

  • http-response-serializer — caps media-type length at 128 chars and validates against a media-type grammar before reflecting into Content-Type. Stops ReDoS via attacker-supplied media types and prevents echoing untrusted input.

Bug fixes / edge cases

  • Added missing defaults, plus small fixes across http-header-normalizer, http-multipart-body-parser, glue-schema-registry, validator, http-content-negotiation, event-batch-response, http-x402.

Performance

  • core/index.js reworked across standard/durable/streamify execution modes.

Tooling / CI (not user-facing)

  • Biome → 2.5.0 + config migration; fuzz-test fixes (event-normalizer); mutation-coverage improvements; provenance-attestation source fix.

Docs

  • WAF alternative note; typo fixes.
  • Deps: bump github/codeql-action 4.35.5 → 4.36.0 (#1656)

Full Changelog: middyjs/middy@7.6.8...7.7.0

7.6.8

What's Changed

Security hardening

  • http-response-serializer — caps media-type length at 128 chars and validates against a media-type grammar before reflecting into Content-Type. Stops ReDoS via attacker-supplied media types and prevents echoing

Bug fixes / edge cases

  • fix: add in missing defaults, plus small fixes across http-header-normalizer, http-multipart-body-parser, glue-schema-registry, validator, http-content-negotiation, event-batch-response, http-x402.

Performance

  • core/index.js reworked (~73 lines) across the standard/durable/streamify execution modes, plus two perf commits (fix: perf optimization, fix: small perf boost).

Tooling / CI (not user-facing)

  • Biome bumped to 2.5.0 + config migration (the lint fix from earlier in our session — preset: "recommended", SVG/proto/test overrides).
  • Fuzz-test fixes (event-normalizer), mutation-coverage improvements, provenance-attestation source fix.

Docs

  • Added a WAF alternative note; typo fixes.

Full Changelog: middyjs/middy@7.6.7...7.6.8

7.6.7

What's Changed

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​middy/core since your current version.


Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jan 16, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner January 16, 2026 19:48
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jan 16, 2026
@github-actions

github-actions Bot commented Jan 16, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 4 package(s) with unknown licenses.
See the Details below.

License Issues

lambdas/functions/control-plane/package.json

PackageVersionLicenseIssue Type
@middy/core^7.7.0NullUnknown License

lambdas/functions/gh-agent-syncer/package.json

PackageVersionLicenseIssue Type
@middy/core^7.7.0NullUnknown License

lambdas/functions/termination-watcher/package.json

PackageVersionLicenseIssue Type
@middy/core^7.7.0NullUnknown License

lambdas/functions/webhook/package.json

PackageVersionLicenseIssue Type
@middy/core^7.7.0NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
npm/@middy/core ^7.7.0 UnknownUnknown
npm/@middy/core ^7.7.0 UnknownUnknown
npm/@middy/core ^7.7.0 UnknownUnknown
npm/@middy/core ^7.7.0 UnknownUnknown
npm/@middy/core 7.7.0 🟢 10
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Dependency-Update-Tool🟢 10update tool detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices🟢 10badge detected: Gold
Signed-Releases⚠️ -1no releases found
Packaging🟢 10packaging workflow detected
License🟢 10license file detected
SAST🟢 10SAST tool is run on all commits
Vulnerabilities🟢 100 existing vulnerabilities detected
Fuzzing🟢 10project is fuzzed
Branch-Protection🟢 10branch protection is fully enabled on development and all release branches
CI-Tests🟢 104 out of 4 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 31 contributing companies or organizations
npm/@middy/util 7.7.0 🟢 10
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 1030 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Dependency-Update-Tool🟢 10update tool detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices🟢 10badge detected: Gold
Signed-Releases⚠️ -1no releases found
Packaging🟢 10packaging workflow detected
License🟢 10license file detected
SAST🟢 10SAST tool is run on all commits
Vulnerabilities🟢 100 existing vulnerabilities detected
Fuzzing🟢 10project is fuzzed
Branch-Protection🟢 10branch protection is fully enabled on development and all release branches
CI-Tests🟢 104 out of 4 merged PRs checked by a CI test -- score normalized to 10
Contributors🟢 10project has 31 contributing companies or organizations

Scanned Files

  • lambdas/functions/control-plane/package.json
  • lambdas/functions/gh-agent-syncer/package.json
  • lambdas/functions/termination-watcher/package.json
  • lambdas/functions/webhook/package.json
  • lambdas/yarn.lock

@npalm

npalm commented Jan 30, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lambdas/middy/core-7.0.2 branch from f66d804 to f209721 Compare January 30, 2026 20:11
@npalm

npalm commented Jan 30, 2026

Copy link
Copy Markdown
Member

Would be better to test this pr on a deployment due to major bump.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lambdas/middy/core-7.0.2 branch 4 times, most recently from abdba02 to 826f39b Compare February 13, 2026 21:03
@npalm

npalm commented Mar 9, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lambdas/middy/core-7.0.2 branch 2 times, most recently from 62154c0 to ede1c40 Compare March 9, 2026 21:12
@npalm
npalm marked this pull request as draft March 10, 2026 18:04
@npalm

npalm commented Mar 10, 2026

Copy link
Copy Markdown
Member

@Brend-Smits @edersonbrilhante I have upgraded manual to Middy 7 with thanks to copilot. Tested (multi-runner) the changes including X-Ray. It looks working smooth. But the middy layer is crucial in Lambda. So would great if one of you can run a double check.

@npalm
npalm marked this pull request as ready for review March 10, 2026 18:22
@dependabot @github

dependabot Bot commented on behalf of github Mar 13, 2026

Copy link
Copy Markdown
Contributor Author

A newer version of @​middy/core exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@npalm

npalm commented Jun 10, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jun 10, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@npalm

npalm commented Jun 10, 2026

Copy link
Copy Markdown
Member

@copilot can you fix this pr?

Copilot AI commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

@copilot can you fix this pr?

Fixed in 8b38581. I updated the webhook test to match the current combined matcher-config error output and re-ran the affected lambda tests.

Copilot AI changed the title fix(lambda): bump @middy/core from 6.4.5 to 7.0.2 in /lambdas fix(lambda): bump @middy/core from 6.4.5 to 7.1.2 in /lambdas Jun 10, 2026
Copilot finished work on behalf of npalm June 10, 2026 06:33
Copilot AI requested a review from npalm June 10, 2026 06:33
@edersonbrilhante

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jul 3, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@edersonbrilhante

Copy link
Copy Markdown
Contributor

@dependabot recreate

Bumps [@middy/core](https://github.com/middyjs/middy/tree/HEAD/packages/core) from 6.4.5 to 7.7.0.
- [Release notes](https://github.com/middyjs/middy/releases)
- [Changelog](https://github.com/middyjs/middy/blob/main/docs/RELEASE.md)
- [Commits](https://github.com/middyjs/middy/commits/7.7.0/packages/core)

---
updated-dependencies:
- dependency-name: "@middy/core"
  dependency-version: 7.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title fix(lambda): bump @middy/core from 6.4.5 to 7.1.2 in /lambdas fix(lambda): bump @middy/core from 6.4.5 to 7.7.0 in /lambdas Jul 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/lambdas/middy/core-7.0.2 branch from 8b38581 to eda240d Compare July 3, 2026 14:35
@dependabot @github

dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #5333.

@dependabot dependabot Bot closed this Sep 2, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/lambdas/middy/core-7.0.2 branch September 2, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants