Skip to content

chore: upgrade fast-xml-parser to 5.3.6#14721

Draft
ahmedhamouda78 wants to merge 1 commit intov4-stablefrom
fix/bump-fast-xml-parser-version
Draft

chore: upgrade fast-xml-parser to 5.3.6#14721
ahmedhamouda78 wants to merge 1 commit intov4-stablefrom
fix/bump-fast-xml-parser-version

Conversation

@ahmedhamouda78
Copy link
Member

@ahmedhamouda78 ahmedhamouda78 commented Feb 17, 2026

Description of changes

Bump fast-xml-parser to ^5.3.6 to fix the "DoS through entity expansion in DOCTYPE" vulnerability (GHSA affecting >= 4.1.3, <= 5.3.5). No safe 4.x version exists.

Issue #, if available

N/A

Description of how you validated changes

  • Verified the build and test processes pass

Checklist

  • PR description included
  • yarn test passes
  • Unit Tests are changed or added
  • Relevant documentation is changed or added (and PR referenced)

Checklist for repo maintainers

  • Verify E2E tests for existing workflows are working as expected or add E2E tests for newly added workflows
  • New source file paths included in this PR have been added to CODEOWNERS, if appropriate

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@changeset-bot
Copy link

changeset-bot bot commented Feb 17, 2026

⚠️ No Changeset found

Latest commit: 9de8ce0

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@ahmedhamouda78 ahmedhamouda78 marked this pull request as ready for review February 17, 2026 19:49
@ahmedhamouda78 ahmedhamouda78 requested review from a team as code owners February 17, 2026 19:49
@ahmedhamouda78 ahmedhamouda78 marked this pull request as draft February 19, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments