Skip to content

MLE-26949 Bumping fast-xml-parser to address CVE#316

Merged
rjrudin merged 1 commit intodevelopfrom
feature/xml-parser
Feb 2, 2026
Merged

MLE-26949 Bumping fast-xml-parser to address CVE#316
rjrudin merged 1 commit intodevelopfrom
feature/xml-parser

Conversation

@rjrudin
Copy link
Contributor

@rjrudin rjrudin commented Feb 2, 2026

Also removed the caret from mocha, as "npm ls diff" resulted in npm complaining about the use of the caret.

Also removed the caret from mocha, as "npm ls diff" resulted in npm complaining about the use of the caret.
@rjrudin rjrudin requested a review from BillFarber as a code owner February 2, 2026 14:51
Copilot AI review requested due to automatic review settings February 2, 2026 14:51
@rjrudin rjrudin requested a review from stevebio as a code owner February 2, 2026 14:51
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates package dependencies to address a security vulnerability (CVE) in fast-xml-parser by upgrading it from version 4.5.3 to 5.3.4. Additionally, it removes the caret (^) version prefix from mocha to use an exact version specification.

Changes:

  • Upgraded fast-xml-parser from 4.5.3 to 5.3.4 to address CVE
  • Changed mocha version specifier from ^11.7.5 to 11.7.5 (exact version)

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

"await-notify": "1.0.1",
"esprima": "4.0.1",
"fast-xml-parser": "4.5.3",
"fast-xml-parser": "5.3.4",
Copy link

Copilot AI Feb 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Upgrading fast-xml-parser from version 4.5.3 to 5.3.4 is a major version change that may introduce breaking API changes. Review the migration guide and ensure all usages of fast-xml-parser in the codebase are compatible with the v5 API, as major version updates typically include breaking changes.

Suggested change
"fast-xml-parser": "5.3.4",
"fast-xml-parser": "4.5.3",

Copilot uses AI. Check for mistakes.
@rjrudin rjrudin merged commit b7b34b3 into develop Feb 2, 2026
1 check passed
@rjrudin rjrudin deleted the feature/xml-parser branch February 2, 2026 15:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants