Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Security issue with the latest available AWS SAM pipe available

Stuart Smiley July 30, 2021

Recently we received a message from AWS to "Update all existing SAM CLI installations to version 1.25 or later." as soon as possible. So I went to https://bitbucket.org/atlassian/aws-sam-deploy to see what version was available in the latest pipe for use in our bitbucket pipeline. Looking at the was-sam-deploy/Dockerfile for master, it appears the version available is v1.18.0, which is well below the 1.25 or later recommended by AWS. 

I am using version 1.26 of the SAM CLI  when I work locally, but our test and production deployments use a bitbucket pipeline which appears to be using a less secure version of the SAM CLI

What is involved in getting an update to the Docker file to bump up the version of the aws SAM CLI in master. 

1 answer

0 votes
Oleksandr Kyrdan
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 2, 2021

Hi @Stuart Smiley

Thank you for your question!

We're investigating it and notify you.

 

Best regards,
Oleksandr Kyrdan

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events