Skip to content

Upgrade postcss to resolve GHSA-r28c-9q8g-f849 - #604

Merged
cigamit merged 2 commits into
mainfrom
GHSA-r28c-9q8g-f849
Jul 28, 2026
Merged

Upgrade postcss to resolve GHSA-r28c-9q8g-f849#604
cigamit merged 2 commits into
mainfrom
GHSA-r28c-9q8g-f849

Conversation

@cigamit

@cigamit cigamit commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@cigamit cigamit self-assigned this Jul 28, 2026
Copilot AI review requested due to automatic review settings July 28, 2026 08:45
@cigamit cigamit added dependencies Pull requests that update a dependency file SECURITY A security related issue like a CVE specifically javascript Pull requests that update javascript code labels Jul 28, 2026
@cigamit
cigamit requested a review from TheWitness July 28, 2026 08:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the AWX UI’s Node dependency lockfile to pull in a patched PostCSS release intended to address the GHSA-r28c-9q8g-f849 security advisory.

Changes:

  • Bumps postcss in awx/ui/package-lock.json from 8.5.16 to 8.5.23.
  • Bumps transitive nanoid dependency from 3.3.15 to 3.3.16 (as required by updated PostCSS).
Files not reviewed (1)
  • awx/ui/package-lock.json: Generated file

Comment thread awx/ui/package-lock.json
Comment thread awx/ui/package-lock.json
Copilot AI review requested due to automatic review settings July 28, 2026 08:47

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 2 changed files in this pull request and generated no new comments.

Files not reviewed (1)
  • awx/ui/package-lock.json: Generated file
Comments suppressed due to low confidence (1)

awx/ui/package-lock.json:21769

  • This change updates package-lock.json (npm lockfile). Repository guidelines require using pnpm for Node projects; please migrate this dependency update to pnpm (generate/commit pnpm-lock.yaml) and remove/stop updating package-lock.json so installs are reproducible with the expected package manager.

@cigamit
cigamit merged commit 5fe408b into main Jul 28, 2026
1 check passed
@cigamit
cigamit deleted the GHSA-r28c-9q8g-f849 branch July 28, 2026 18:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code SECURITY A security related issue like a CVE specifically

Development

Successfully merging this pull request may close these issues.

3 participants