Skip to content

build(deps): bump fast-xml-parser from 5.9.3 to 5.11.0 - #5328

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-xml-parser-5.11.0
Closed

build(deps): bump fast-xml-parser from 5.9.3 to 5.11.0#5328
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-xml-parser-5.11.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-xml-parser from 5.9.3 to 5.11.0.

Release notes

Sourced from fast-xml-parser's releases.

v5.11.0

What's Changed

New Contributors

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.10.1...v5.11.0

v5.10.1

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.10.0...v5.10.1

v5.10.0

What's Changed

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.9.3...v5.10.0

Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion

5.11.0 / 2026-08-16

  • feat: support for endIndex in node metadata (#850) [By Pavel Dranichnikov]
  • fix: don't crash on a closing tag with no matching opening tag (#861) [By Haïm Dimer]
  • fix: DOCTYPE to read SYSTEM/PUBLIC
  • deps: strnum v2.4.2

5.10.1 / 2026-07-17

  • fix: multiple DOCTYPE declarations.
  • deps: @nodable/entities for treeshaking

5.10.0 / 2026-07-11

  • upgrade:
    • xml-naming v0.3.0: cache support
    • PEM v1.6.2: sibling bug fix
    • is-unsafe v2.0.0: tree shaking

*5.9.3 / 2026-06-19

  • update strnum

*5.9.2 / 2026-06-17

  • dummy release to test changes in github action

*5.9.1 / 2026-06-17

  • dummy release to test release from github action

*5.9.0 / 2026-06-15

  • update strnum to 2.3.0
    • you can set hex, binary, enotation, infinity, unicode
  • validate unsafe HTML or XML data in doctype entities unsing 'is-unsafe' library. User can override rules by overriding EntityDecoder.

*5.8.0 / 2026-05-12

  • integrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)
    • This will consider xml-version as well. '1.0' is default
  • update strnum to 2.3.0
    • You can set octal and binary parsing which is bydeault off
  • update fast-xml-builder to 1.2.0
    • can sanitize tag names if found invalid
    • fix format output

5.7.3 / 2006-05-05

  • fix: alwaysCreateTextNode should create text node when attributes are present for self closing node
  • fix stop node expression when ns prefix is removed (found by iruizsalinas)

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.9.3 to 5.11.0.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.9.3...v5.11.0)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.11.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added area/frontend Needs frontend code changes dependency-upgrade Dependency upgrade is needed labels Aug 17, 2026
Comment thread package-lock.json

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Plerion found 41 security issues.

These do not block merging, but we recommend reviewing and resolving them:

Vulnerability ID Issue Affected version Remediation
Severity: Critical undici - undici: Information disclosure and Denial of Service via malformed Cache-Control directives undici@7.28.0 Upgrade to 7.29.0, 8.9.0 or higher
Severity: High brace-expansion - Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion@5.0.6 Upgrade to 5.0.7, 1.1.16, 2.1.2 or higher
Severity: High fast-uri - fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri@3.1.2 Upgrade to 4.0.1, 3.1.3, 2.4.2 or higher
Severity: High brace-expansion - Brace-expansion: Denial of Service via memory exhaustion in expand() function brace-expansion@5.0.6 Upgrade to 5.0.8, 3.0.3, 2.1.3, 1.1.17 or higher
Severity: High undici - undici: Cross-user information disclosure due to improper Cache-Control directive parsing undici@7.28.0 Upgrade to 7.29.0, 8.9.0 or higher
Show 36 more issues
Vulnerability ID Issue Affected version Remediation
Severity: High fast-uri - Fast-uri: Security policy bypass due to URL parsing inconsistency fast-uri@3.1.2 Upgrade to 2.4.3, 3.1.4, 4.1.1 or higher
Severity: High fast-uri - fast-uri: Host confusion vulnerability via backslash in URI authority fast-uri@3.1.2 Upgrade to 2.4.4, 3.1.5, 4.1.2 or higher
Severity: High extract-zip - github.com/maxogden/extract-zip: extract-zip: Arbitrary file write and information disclosure via symlink validation bypass extract-zip@2.0.1 Upgrade to null or higher
Severity: High js-yaml - js-yaml: Denial of Service via crafted YAML documents js-yaml@4.2.0 Upgrade to 3.15.0, 4.3.0 or higher
Severity: High tar - node-tar: Denial of Service due to incorrect PAX path handling tar@7.5.16 Upgrade to 7.5.18 or higher
Severity: High tar - node-tar: Denial of Service via crafted gzip bomb tar@7.5.16 Upgrade to 7.5.19 or higher
Severity: High tar - Node-tar: Denial of Service via malformed tar archive header tar@7.5.16 Upgrade to 7.5.18 or higher
Severity: High immutable - Immutable.js provides many Persistent Immutable data structures. Prior ... immutable@5.1.6 Upgrade to 4.3.9, 5.1.8 or higher
Severity: High immutable - Immutable.js provides many Persistent Immutable data structures. Prior ... immutable@5.1.6 Upgrade to 4.3.9, 5.1.8 or higher
Severity: High nanoid - nanoid: Denial of Service via infinite loop in random ID generation nanoid@3.3.15 Upgrade to 3.3.18, 5.1.6 or higher
Severity: High nanoid - nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ... nanoid@3.3.15 Upgrade to 3.3.16, 5.1.16 or higher
Severity: High brace-expansion - DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation brace-expansion@5.0.6 Upgrade to 1.1.18, 2.1.4, 3.0.6, 5.0.9 or higher
Severity: High postcss - Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure postcss@8.5.15 Upgrade to 8.5.18 or higher
Severity: High svgo - SVGO removeScripts plugin leaves some executable scripts intact svgo@3.3.3 Upgrade to 2.8.3, 3.3.4, 4.0.2 or higher
Severity: High svgo - SVGO removeScripts plugin leaves some executable scripts intact svgo@4.0.1 Upgrade to 2.8.3, 3.3.4, 4.0.2 or higher
Severity: High js-yaml - Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported js-yaml@4.2.0 Upgrade to 4.3.1, 3.15.1 or higher
Severity: High sharp - CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591 sharp@0.34.5 Upgrade to 0.35.0 or higher
Severity: Medium undici - undici: HTTP header injection via unvalidated blob-like body type property undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium undici - undici: Response desynchronization via retry interceptor with mismatched Content-Length undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium undici - Undici: Cookie attribute injection allows bypassing security protections undici@7.28.0 Upgrade to 6.28.0, 7.29.0, 8.9.0 or higher
Severity: Medium yaml - yaml: Denial of Service via deeply nested YAML document parsing yaml@2.7.1 Upgrade to 2.8.3, 1.10.3 or higher
Severity: Medium mermaid - Mermaid: CSS injection allows altering page elements via diagram input mermaid@11.15.0 Upgrade to 11.16.1, 10.9.8 or higher
Severity: Medium @astrojs/rss - XML Injection via Unescaped RSS Feed Fields @astrojs/rss@4.0.18 Upgrade to 4.0.19 or higher
Severity: Medium astro - XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) astro@7.0.0 Upgrade to 7.0.6 or higher
Severity: Medium tar - node-tar: Denial of Service via crafted archive with NUL bytes in metadata tar@7.5.16 Upgrade to 7.5.17 or higher
Severity: Medium postcss - PostCSS: Information disclosure via crafted sourceMappingURL postcss@8.5.15 Upgrade to 8.5.23 or higher
Severity: Medium mermaid - Mermaid XY Charts: Denial of Service via invalid X-Axis parameters mermaid@11.15.0 Upgrade to 10.9.8, 11.16.1 or higher
Severity: Medium mermaid - Mermaid: Prototype pollution vulnerability allows potential arbitrary code execution mermaid@11.15.0 Upgrade to 11.16.1 or higher
Severity: Medium mermaid - Mermaid: Denial of Service via Radar Diagrams 'ticks' parameter mermaid@11.15.0 Upgrade to 11.16.1 or higher
Severity: Medium astro - Reflected XSS via unescaped View Transition animation properties astro@7.0.0 Upgrade to 7.1.0 or higher
Severity: Medium astro - composable astro/hono pipeline bypasses security.checkOrigin when middleware() is absent or misordered astro@7.0.0 Upgrade to 7.0.6 or higher
Severity: Medium dompurify - IN_PLACE hook removal leaves a detached subtree executable, causing XSS dompurify@3.4.11 Upgrade to 3.4.13 or higher
Severity: Medium tar - Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection tar@7.5.16 Upgrade to 7.5.21 or higher
Severity: Low astro - Cross-site scripting via unescaped transition:* directive values on hydrated islands astro@7.0.0 Upgrade to 7.0.4 or higher
Severity: Low mermaid - Mermaid: Prototype pollution vulnerability via configuration APIs mermaid@11.15.0 Upgrade to 11.16.1, 10.9.8 or higher
Severity: Low dompurify - CUSTOM_ELEMENT_HANDLING bypasses afterSanitizeElements for allowed custom elements. dompurify@3.4.11 Upgrade to 3.4.12 or higher

View in Plerion

@github-actions

Copy link
Copy Markdown
Contributor

🔦 Lighthouse Benchmark

Tested: http://localhost:8787 on 2026-08-17 02:43 UTC
Compared against main baseline from 2026-08-14

Scores (0–100, higher is better)

Page Performance Accessibility Best Practices SEO
Home 66 84 54 92
Get Started 63 83 54 100
Pricing 98 92 54 100
Enterprise 95 83 54 100
Cloud 91 80 54 100
About Us 85 91 54 100
Docs Landing 97 🟢 +14 88 54 92
Contribute to Kestra (simple docs) 98 88 54 92
Flow (full featured docs) 95 90 54 92
Blog Index 75 91 54 100
Blog Post (sample) 92 88 54 100
VS Page (sample) 97 88 54 100
Plugins Landing 94 81 54 92
Plugin Page (sample) 90 88 54 100
Plugin Debug Page (sample) 96 88 54 100
Plugin Debug Return Page (sample) 93 88 58 100
Blueprints Landing 77 91 54 100
Blueprint Audit Logs CSV Export 0 🔻 -82 92 54 100

Core Web Vitals (lower is better)

Page LCP FCP TBT CLS Speed Index
Home 1.29 s 0.67 s 906 ms 🟢 0.000 1.83 s 🟢
Get Started 2.03 s 0.63 s 870 ms 0.000 0.97 s
Pricing 1.03 s 0.54 s 49 ms 🟢 0.000 0.79 s
Enterprise 1.44 s 0.59 s 17 ms 0.000 🟢 0.85 s
Cloud 1.95 s 0.58 s 37 ms 0.027 🔻 0.86 s
About Us 2.61 s 0.64 s 21 ms 0.000 0.76 s
Docs Landing 0.96 s 🟢 0.70 s 106 ms 0.000 1.00 s
Contribute to Kestra (simple docs) 0.95 s 0.57 s 88 ms 0.000 🟢 0.76 s
Flow (full featured docs) 1.25 s 0.57 s 115 ms 0.000 1.18 s
Blog Index 9.55 s 0.54 s 25 ms 🟢 0.001 0.82 s
Blog Post (sample) 1.84 s 0.60 s 24 ms 0.000 0.75 s
VS Page (sample) 1.08 s 0.61 s 30 ms 🟢 0.064 0.70 s
Plugins Landing 0.84 s 0.50 s 20 ms 🟢 0.000 2.28 s
Plugin Page (sample) 1.02 s 0.66 s 28 ms 0.000 3.63 s 🔻
Plugin Debug Page (sample) 0.92 s 0.52 s 103 ms 🔻 0.000 1.65 s
Plugin Debug Return Page (sample) 0.98 s 0.61 s 138 ms 🔻 0.000 1.95 s
Blueprints Landing 2.47 s 1.01 s 73 ms 🔻 0.000 3.23 s
Blueprint Audit Logs CSV Export 0.00 s 🟢 0.00 s 🟢 0 ms 🟢 0.000 0.00 s 🟢
Legend

🟢 improved  ·  🔻 regressed  ·  (blank) no significant change
Score threshold: ±10 pts  ·  Metric threshold: ±30% of baseline

View full Lighthouse HTML report for a page

Full per-page Lighthouse Results (LHR) are attached as the lhr-reports artifact on this run. Download and unzip it, then open https://googlechrome.github.io/lighthouse/viewer/ and drop the <page>-lhr.json file into the page to see every audit, opportunity, and diagnostic.

@dependabot @github

dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #5478.

@dependabot dependabot Bot closed this Sep 2, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/fast-xml-parser-5.11.0 branch September 2, 2026 22:37
@kestrabot kestrabot Bot added this to Pull Requests Sep 2, 2026
@github-project-automation github-project-automation Bot moved this to To review in Pull Requests Sep 2, 2026
@github-project-automation github-project-automation Bot moved this from To review to Done in Pull Requests Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/frontend Needs frontend code changes dependency-upgrade Dependency upgrade is needed

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

0 participants