Skip to content

Upgrade dompurify to resolve GHSA-cmwh-pvxp-8882 - #499

Merged
cigamit merged 1 commit into
mainfrom
GHSA-cmwh-pvxp-8882
Jun 22, 2026
Merged

Upgrade dompurify to resolve GHSA-cmwh-pvxp-8882#499
cigamit merged 1 commit into
mainfrom
GHSA-cmwh-pvxp-8882

Conversation

@cigamit

@cigamit cigamit commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@cigamit cigamit self-assigned this Jun 22, 2026
@cigamit cigamit added the dependencies Pull requests that update a dependency file label Jun 22, 2026
Copilot AI review requested due to automatic review settings June 22, 2026 03:37
@cigamit cigamit added SECURITY A security related issue like a CVE specifically javascript Pull requests that update javascript code labels Jun 22, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the AWX UI’s DOMPurify dependency to a patched version to address GitHub Security Advisory GHSA-cmwh-pvxp-8882.

Changes:

  • Bumps dompurify dependency from ^3.4.9 to ^3.4.11 in the UI package.json.
  • Regenerates package-lock.json entries to lock DOMPurify to 3.4.11 (updated resolved URL + integrity).

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated no comments.

File Description
awx/ui/package.json Updates the declared DOMPurify dependency range to ^3.4.11.
awx/ui/package-lock.json Locks DOMPurify to 3.4.11 and updates the tarball metadata accordingly.
Files not reviewed (1)
  • awx/ui/package-lock.json: Generated file

@cigamit
cigamit merged commit 461fbc0 into main Jun 22, 2026
1 check passed
@cigamit
cigamit deleted the GHSA-cmwh-pvxp-8882 branch June 22, 2026 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code SECURITY A security related issue like a CVE specifically

Development

Successfully merging this pull request may close these issues.

3 participants