Skip to content

Upgrade dompurify to resolve CVE-2025-15599#258

Merged
cigamit merged 1 commit intomainfrom
CVE-2025-15599
Mar 4, 2026
Merged

Upgrade dompurify to resolve CVE-2025-15599#258
cigamit merged 1 commit intomainfrom
CVE-2025-15599

Conversation

@cigamit
Copy link
Copy Markdown
Contributor

@cigamit cigamit commented Mar 4, 2026

Still waiting on a new version of dompurify to resolve another CVE

@cigamit cigamit requested a review from TheWitness March 4, 2026 22:31
@cigamit cigamit self-assigned this Mar 4, 2026
@cigamit cigamit added the dependencies Pull requests that update a dependency file label Mar 4, 2026
Copilot AI review requested due to automatic review settings March 4, 2026 22:31
@cigamit cigamit added the SECURITY A security related issue like a CVE specifically label Mar 4, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the AWX UI’s DOMPurify dependency to a newer patched version to address the CVE referenced in the PR title.

Changes:

  • Bump dompurify from 3.2.6 to 3.3.1 in UI dependencies.
  • Regenerate/update package-lock.json entries for DOMPurify to match the new version.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
awx/ui/package.json Updates the pinned DOMPurify dependency version to 3.3.1.
awx/ui/package-lock.json Updates the lockfile to resolve DOMPurify 3.3.1 (including updated tarball URL/integrity metadata).
Files not reviewed (1)
  • awx/ui/package-lock.json: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread awx/ui/package.json
@cigamit cigamit merged commit 11178d0 into main Mar 4, 2026
4 checks passed
@cigamit cigamit deleted the CVE-2025-15599 branch March 4, 2026 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file SECURITY A security related issue like a CVE specifically

Development

Successfully merging this pull request may close these issues.

3 participants