Skip to content

Remove jsonpath (by upgrading bfj) to resolve CVE-2026-1615#237

Merged
cigamit merged 1 commit intomainfrom
CVE-2026-1615
Feb 24, 2026
Merged

Remove jsonpath (by upgrading bfj) to resolve CVE-2026-1615#237
cigamit merged 1 commit intomainfrom
CVE-2026-1615

Conversation

@cigamit
Copy link
Copy Markdown
Contributor

@cigamit cigamit commented Feb 21, 2026

No description provided.

@cigamit cigamit requested a review from TheWitness February 21, 2026 00:51
@cigamit cigamit self-assigned this Feb 21, 2026
Copilot AI review requested due to automatic review settings February 21, 2026 00:51
@cigamit cigamit added dependencies Pull requests that update a dependency file SECURITY A security related issue like a CVE specifically labels Feb 21, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR upgrades the bfj package from version ^7.0.2 to ^9.1.3 to address CVE-2026-1615, which affects the transitive dependency jsonpath.

Changes:

  • Updated bfj dependency to version ^9.1.3 in package.json
Files not reviewed (1)
  • awx/ui/package-lock.json: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@cigamit cigamit merged commit 5c5dfec into main Feb 24, 2026
4 checks passed
@cigamit cigamit deleted the CVE-2026-1615 branch February 24, 2026 01:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file SECURITY A security related issue like a CVE specifically

Development

Successfully merging this pull request may close these issues.

3 participants