Skip to content

Copilot CLI binary contains vulnerable version of adm-zip package #4442

Description

@aleksey-hariton

Describe the bug

My org uses XRay for scanning Docker image we built and I have a problem with building such an image with latest version of Copilot CLI 1.0.79 - it contains adm-zip v0.5.17 which have High severity CVE - CVE-2026-39244, is it possible to fix it somehow? (update adm-zip to v0.6.0)

Why even fresh Coplot CLI binary includes vulnerable package version, when fix was released in the end of June?
You dont have security assets scans at all?

Thanks.

Affected version

1.0.79

Steps to reproduce the behavior

No response

Expected behavior

No response

Additional context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions