Commit 23f789e
committed
fix(security): resolve fast-xml-parser DoS vulnerability (CVE-2026-26278) (#326)
Add pnpm override to force fast-xml-parser >=5.3.6, fixing Dependabot
alert #114 (GHSA-jmr7-xgp7-cmfj, CVSS 7.5). Resolves two vulnerable
transitive instances: 4.5.3 via @loaders.gl/xml and 5.3.4 via
@aws-sdk/xml-builder.1 parent 100306c commit 23f789e
2 files changed
Lines changed: 16 additions & 23 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
178 | 178 | | |
179 | 179 | | |
180 | 180 | | |
181 | | - | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
182 | 185 | | |
183 | 186 | | |
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments