Skip to content

Upgrade js-yaml to resolve GHSA-pm4m-ph32-ghv5 - #602

Merged
cigamit merged 1 commit into
mainfrom
GHSA-pm4m-ph32-ghv5
Jul 28, 2026
Merged

Upgrade js-yaml to resolve GHSA-pm4m-ph32-ghv5#602
cigamit merged 1 commit into
mainfrom
GHSA-pm4m-ph32-ghv5

Conversation

@cigamit

@cigamit cigamit commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@cigamit cigamit self-assigned this Jul 28, 2026
Copilot AI review requested due to automatic review settings July 28, 2026 08:40
@cigamit cigamit added dependencies Pull requests that update a dependency file SECURITY A security related issue like a CVE specifically javascript Pull requests that update javascript code labels Jul 28, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the AWX UI’s JavaScript dependencies to address the js-yaml security advisory (GHSA-pm4m-ph32-ghv5) by bumping the pinned version used by the frontend build.

Changes:

  • Bump js-yaml from 5.2.1 to 5.2.2 in the UI dependency set.
  • Refresh package-lock.json to reflect the updated resolved dependency graph (including a dompurify range update captured in the lockfile).

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
awx/ui/package.json Updates the direct js-yaml dependency version used by the UI.
awx/ui/package-lock.json Updates lockfile entries to match the new resolved versions (including js-yaml 5.2.2).
Files not reviewed (1)
  • awx/ui/package-lock.json: Generated file

Comment thread awx/ui/package-lock.json
@cigamit
cigamit merged commit cbc6e9f into main Jul 28, 2026
1 check passed
@cigamit
cigamit deleted the GHSA-pm4m-ph32-ghv5 branch July 28, 2026 18:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code SECURITY A security related issue like a CVE specifically

Development

Successfully merging this pull request may close these issues.

3 participants