build(deps): bump fast-xml-parser from 5.9.3 to 5.11.0 - #5328
Closed
dependabot[bot] wants to merge 1 commit into
Closed
build(deps): bump fast-xml-parser from 5.9.3 to 5.11.0#5328dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.9.3 to 5.11.0. - [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases) - [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md) - [Commits](NaturalIntelligence/fast-xml-parser@v5.9.3...v5.11.0) --- updated-dependencies: - dependency-name: fast-xml-parser dependency-version: 5.11.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
These do not block merging, but we recommend reviewing and resolving them:
Show 36 more issues
| Vulnerability ID | Issue | Affected version | Remediation |
|---|---|---|---|
fast-uri - Fast-uri: Security policy bypass due to URL parsing inconsistency |
fast-uri@3.1.2 |
Upgrade to 2.4.3, 3.1.4, 4.1.1 or higher |
|
fast-uri - fast-uri: Host confusion vulnerability via backslash in URI authority |
fast-uri@3.1.2 |
Upgrade to 2.4.4, 3.1.5, 4.1.2 or higher |
|
extract-zip - github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass |
extract-zip@2.0.1 |
Upgrade to null or higher |
|
js-yaml - js-yaml: Denial of Service via crafted YAML documents |
js-yaml@4.2.0 |
Upgrade to 3.15.0, 4.3.0 or higher |
|
tar - node-tar: Denial of Service due to incorrect PAX path handling |
tar@7.5.16 |
Upgrade to 7.5.18 or higher |
|
tar - node-tar: Denial of Service via crafted gzip bomb |
tar@7.5.16 |
Upgrade to 7.5.19 or higher |
|
tar - Node-tar: Denial of Service via malformed tar archive header |
tar@7.5.16 |
Upgrade to 7.5.18 or higher |
|
immutable - Immutable.js provides many Persistent Immutable data structures. Prior ... |
immutable@5.1.6 |
Upgrade to 4.3.9, 5.1.8 or higher |
|
immutable - Immutable.js provides many Persistent Immutable data structures. Prior ... |
immutable@5.1.6 |
Upgrade to 4.3.9, 5.1.8 or higher |
|
nanoid - nanoid: Denial of Service via infinite loop in random ID generation |
nanoid@3.3.15 |
Upgrade to 3.3.18, 5.1.6 or higher |
|
nanoid - nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ... |
nanoid@3.3.15 |
Upgrade to 3.3.16, 5.1.16 or higher |
|
brace-expansion - DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
brace-expansion@5.0.6 |
Upgrade to 1.1.18, 2.1.4, 3.0.6, 5.0.9 or higher |
|
postcss - Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure |
postcss@8.5.15 |
Upgrade to 8.5.18 or higher |
|
svgo - SVGO removeScripts plugin leaves some executable scripts intact |
svgo@3.3.3 |
Upgrade to 2.8.3, 3.3.4, 4.0.2 or higher |
|
svgo - SVGO removeScripts plugin leaves some executable scripts intact |
svgo@4.0.1 |
Upgrade to 2.8.3, 3.3.4, 4.0.2 or higher |
|
js-yaml - Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported |
js-yaml@4.2.0 |
Upgrade to 4.3.1, 3.15.1 or higher |
|
sharp - CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 |
sharp@0.34.5 |
Upgrade to 0.35.0 or higher |
|
undici - undici: HTTP header injection via unvalidated blob-like body type property |
undici@7.28.0 |
Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher |
|
undici - undici: Response desynchronization via retry interceptor with mismatched Content-Length |
undici@7.28.0 |
Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher |
|
undici - Undici: Cookie attribute injection allows bypassing security protections |
undici@7.28.0 |
Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher |
|
yaml - yaml: Denial of Service via deeply nested YAML document parsing |
yaml@2.7.1 |
Upgrade to 2.8.3, 1.10.3 or higher |
|
mermaid - Mermaid: CSS injection allows altering page elements via diagram input |
mermaid@11.15.0 |
Upgrade to 11.16.1, 10.9.8 or higher |
|
@astrojs/rss - XML Injection via Unescaped RSS Feed Fields |
@astrojs/rss@4.0.18 |
Upgrade to 4.0.19 or higher |
|
astro - XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) |
astro@7.0.0 |
Upgrade to 7.0.6 or higher |
|
tar - node-tar: Denial of Service via crafted archive with NUL bytes in metadata |
tar@7.5.16 |
Upgrade to 7.5.17 or higher |
|
postcss - PostCSS: Information disclosure via crafted sourceMappingURL |
postcss@8.5.15 |
Upgrade to 8.5.23 or higher |
|
mermaid - Mermaid XY Charts: Denial of Service via invalid X-Axis parameters |
mermaid@11.15.0 |
Upgrade to 10.9.8, 11.16.1 or higher |
|
mermaid - Mermaid: Prototype pollution vulnerability allows potential arbitrary code execution |
mermaid@11.15.0 |
Upgrade to 11.16.1 or higher |
|
mermaid - Mermaid: Denial of Service via Radar Diagrams 'ticks' parameter |
mermaid@11.15.0 |
Upgrade to 11.16.1 or higher |
|
astro - Reflected XSS via unescaped View Transition animation properties |
astro@7.0.0 |
Upgrade to 7.1.0 or higher |
|
astro - composable astro/hono pipeline bypasses security.checkOrigin when middleware() is absent or misordered |
astro@7.0.0 |
Upgrade to 7.0.6 or higher |
|
dompurify - IN_PLACE hook removal leaves a detached subtree executable, causing XSS |
dompurify@3.4.11 |
Upgrade to 3.4.13 or higher |
|
tar - Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection |
tar@7.5.16 |
Upgrade to 7.5.21 or higher |
|
astro - Cross-site scripting via unescaped transition:* directive values on hydrated islands |
astro@7.0.0 |
Upgrade to 7.0.4 or higher |
|
mermaid - Mermaid: Prototype pollution vulnerability via configuration APIs |
mermaid@11.15.0 |
Upgrade to 11.16.1, 10.9.8 or higher |
|
dompurify - CUSTOM_ELEMENT_HANDLING bypasses afterSanitizeElements for allowed custom elements. |
dompurify@3.4.11 |
Upgrade to 3.4.12 or higher |
Contributor
🔦 Lighthouse Benchmark
Scores (0–100, higher is better)
Core Web Vitals (lower is better)
Legend🟢 improved · 🔻 regressed · (blank) no significant change View full Lighthouse HTML report for a pageFull per-page Lighthouse Results (LHR) are attached as the |
Contributor
Author
|
Superseded by #5478. |
dependabot
Bot
deleted the
dependabot/npm_and_yarn/fast-xml-parser-5.11.0
branch
September 2, 2026 22:37
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps fast-xml-parser from 5.9.3 to 5.11.0.
Release notes
Sourced from fast-xml-parser's releases.
Changelog
Sourced from fast-xml-parser's changelog.
... (truncated)
Commits
f3c69ae5.11.0fdbd072update for releasec5fcb5bupdate lock files549452aupdate gitignore3ed7b03depsfee9b15update README57ad0d3fix DOCTYPE to read SYSTEM/PUBLICc8e2f28fix: don't crash on a closing tag with no matching opening tag (#861)4652011add support for endIndex in node metadata (#850)2ce71915.10.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.