Skip to content

Update antchfx/xpath to v1.3.6 - #172

Open
nishant111 wants to merge 1 commit into
sonic-net:masterfrom
nishant111:fix-cve-2026-32287-xpath
Open

nishant111 wants to merge 1 commit into
sonic-net:masterfrom
nishant111:fix-cve-2026-32287-xpath

Conversation

@nishant111

Copy link
Copy Markdown

Update antchfx/xpath to v1.3.6 for CVE-2026-32287

Use the first release containing the logicalQuery loop fix while retaining the SONiC XPath extensions through the rebased management-common patch.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 877ef55e-5d69-4ebd-87c3-a5b5a94f3498
Signed-off-by: Nishant Sharma <nshntsharma86@gmail.com>
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@mssonicbld

Copy link
Copy Markdown

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).

@nishant111

Copy link
Copy Markdown
Author

This PR is blocked by sonic-net/sonic-mgmt-common#256.

The current CI run checked out sonic-mgmt-common commit 43e679c, which
contains the XPath patch for v1.1.10. This PR vendors XPath v1.3.6, so
the old patch fails to apply.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants