Skip to content

[release-1.9] chore(deps): update fast-xml-parser#4482

Merged
openshift-merge-bot[bot] merged 2 commits intoredhat-developer:release-1.9from
JessicaJHee:cve-1.9-fast-xml-parser
Mar 30, 2026
Merged

[release-1.9] chore(deps): update fast-xml-parser#4482
openshift-merge-bot[bot] merged 2 commits intoredhat-developer:release-1.9from
JessicaJHee:cve-1.9-fast-xml-parser

Conversation

@JessicaJHee
Copy link
Copy Markdown
Member

Description

Bumps fast-xml-parser to 4.5.5, 5.5.8, or 5.5.9 where the linked CVEs have been patched

In root:

├─┬ @internal/plugin-dynamic-plugins-info-backend@0.1.0 -> ./plugins/dynamic-plugins-info-backend
│ └─┬ @backstage/backend-defaults@0.13.1
│   ├─┬ @aws-sdk/client-codecommit@3.1018.0
│   │ └─┬ @aws-sdk/core@3.973.25
│   │   └─┬ @aws-sdk/xml-builder@3.972.16
│   │     └── fast-xml-parser@5.5.8
│   └─┬ @google-cloud/storage@7.7.0
│     └── fast-xml-parser@4.5.5
└─┬ app@1.0.1 -> ./packages/app
  └─┬ @backstage/plugin-api-docs@0.13.1
    └─┬ @asyncapi/react-component@2.6.3
      └─┬ openapi-sampler@1.6.1
        └── fast-xml-parser@4.5.5 deduped

In dynamic-plugins/:

dynamic-plugins-root@1.9.3 /Users/jhe/git/rhdh-repos/rhdh/dynamic-plugins
├─┬ @backstage/cli@0.34.5
│ └─┬ @backstage/integration@1.19.1
│   └─┬ @azure/storage-blob@12.30.0
│     └─┬ @azure/core-xml@1.5.0
│       └── fast-xml-parser@5.5.9
├─┬ backstage-community-plugin-ocm-backend@5.12.2 -> ./wrappers/backstage-community-plugin-ocm-backend-dynamic
│ └─┬ @backstage-community/plugin-ocm-backend@5.12.2
│   └─┬ @backstage/backend-defaults@0.13.1
│     └─┬ @google-cloud/storage@7.18.0
│       └── fast-xml-parser@4.5.5
└─┬ backstage-plugin-kubernetes-backend@0.20.4 -> ./wrappers/backstage-plugin-kubernetes-backend-dynamic
  └─┬ @backstage/plugin-kubernetes-backend@0.20.4
    └─┬ @aws-sdk/credential-providers@3.1018.0
      └─┬ @aws-sdk/core@3.973.25
        └─┬ @aws-sdk/xml-builder@3.972.16
          └── fast-xml-parser@5.5.8

Which issue(s) does this PR fix

PR acceptance criteria

Please make sure that the following steps are complete:

  • GitHub Actions are completed and successful
  • Unit Tests are updated and passing
  • E2E Tests are updated and passing
  • Documentation is updated if necessary (requirement for new features)
  • Add a screenshot if the change is UX/UI related

How to test changes / Special notes to the reviewer

Signed-off-by: Jessica He <jhe@redhat.com>
@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

@JessicaJHee
Copy link
Copy Markdown
Member Author

/retest

Copy link
Copy Markdown
Member

@alizard0 alizard0 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@JessicaJHee
Copy link
Copy Markdown
Member Author

/retest

@openshift-ci openshift-ci Bot removed the lgtm label Mar 30, 2026
@sonarqubecloud
Copy link
Copy Markdown

@github-actions
Copy link
Copy Markdown
Contributor

Image was built and published successfully. It is available at:

Copy link
Copy Markdown
Member

@alizard0 alizard0 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci Bot added the lgtm label Mar 30, 2026
@openshift-merge-bot openshift-merge-bot Bot merged commit cd6fcd8 into redhat-developer:release-1.9 Mar 30, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants