Skip to content

build(deps): bump fast-xml-parser from 5.7.0 to 5.7.1#10

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-xml-parser-5.7.1
Closed

build(deps): bump fast-xml-parser from 5.7.0 to 5.7.1#10
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-xml-parser-5.7.1

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Apr 22, 2026

Bumps fast-xml-parser from 5.7.0 to 5.7.1.

Release notes

Sourced from fast-xml-parser's releases.

upgrade @​nodable/entities and FXB

  • Use @nodable/entities v2.1.0
    • breaking changes
      • single entity scan. You're not allowed to use entity value to form another entity name.
      • you cant add numeric external entity
      • entity error message when expantion limit is crossed might change
    • typings are updated for new options related to process entity
    • please follow documentation of @nodable/entities for more detail.
    • performance
      • if processEntities is false, then there should not be impact on performance.
      • if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
      • if processEntities is true, and you pass entity decoder separately
        • if no entity then performance should be same as before
        • if there are entities then performance should be increased from past versions
    • ignoreAttributes is not required to be set to set xml version for NCR entity value
  • update 'fast-xml-builder' to sanitize malicious CDATA and comment's content
Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion

5.7.1 / 2026-04-20

  • fix #705: attributesGroupName working with preserveOrder
  • fix #817: stackoverflow when tag expression is very long

5.7.0 / 2026-04-17

  • Use @nodable/entities v2.1.0
    • breaking changes
      • single entity scan. You're not allowed to user entity value to form another entity name.
      • you cant add numeric external entity
      • entity error message when expantion limit is crossed might change
    • typings are updated for new options related to process entity
    • please follow documentation of @nodable/entities for more detail.
    • performance
      • if processEntities is false, then there should not be impact on performance.
      • if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
      • if processEntities is true, and you pass entity decoder separately
        • if no entity then performance should be same as before
        • if there are entities then performance should be increased from past versions
    • ignoreAttributes is not required to be set to set xml version for NCR entity value
  • update 'fast-xml-builder' to sanitize malicious CDATA and comment's content

5.6.0 / 2026-04-15

  • fix: entity replacement for numeric entities
  • use @​nodable/entities to replace entities
    • this may change some error messages related to entities expansion limit or inavlid use
    • post check would be exposed in future version

5.5.12 / 2026-04-13

  • Performance Improvement: update path-expression-matcher
    • use proxy pattern than Proxy class

5.5.11 / 2026-04-08

  • Performance Improvement
    • integrate ExpressionSet for stopNodes

5.5.10 / 2026-04-03

  • increase default entity explansion limit as many projects demand for that
  • performance improvement
    • reduce calls to toString
    • early return when entities are not present
    • prepare rawAttrsForMatcher only if user sets jPath: false

5.5.9 / 2026-03-23

  • combine typing files

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 22, 2026
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.7.0 to 5.7.1.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.7.0...v5.7.1)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.7.1 branch from 4eaa5ea to af4bfff Compare April 23, 2026 00:07
@theagenticguy
Copy link
Copy Markdown
Owner

Superseded by #18 (bulk dep bump).

@theagenticguy theagenticguy deleted the dependabot/npm_and_yarn/fast-xml-parser-5.7.1 branch April 23, 2026 00:10
@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Apr 23, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

theagenticguy added a commit that referenced this pull request Apr 23, 2026
## Summary

Sweep of every outdated direct dependency in the workspace, bringing
each one to its latest version — except for two intentional holds
(TypeScript 6, Zod 4) that need their own migration PRs.

## What's bumped

**Safe minors + patches** (no behavior changes on our surface):

| Package | From | To |
|---|---|---|
| `@biomejs/biome` | 2.4.0 | 2.4.12 |
| `fast-xml-parser` | 5.7.0 | 5.7.1 |
| `piscina` | 5.1.3 | 5.1.4 |
| `envinfo` | 7.14.0 | 7.21.0 |
| `lru-cache` | 11.2.2 | 11.3.5 |

**Safe majors** (no source-level breakage; verified via full build +
test matrix):

| Package | From | To |
|---|---|---|
| `@apidevtools/swagger-parser` | 10.1.1 | 12.1.0 |
| `@commitlint/cli` | 19.6.1 | 20.5.0 |
| `@commitlint/config-conventional` | 19.6.0 | 20.5.0 |
| `@types/node` | 20.14.0 | 22.19.17 (Node 22 LTS) |
| `commander` | 13.1.0 | 14.0.3 |
| `listr2` | 9.0.4 | 10.2.1 |
| `write-file-atomic` | 6.0.0 | 7.0.1 |

**Deliberately deferred** (need real migration work; track in follow-up
PRs):

- `typescript` 5.9.3 → 6.x — many workspace deps peer-declare
`typescript@^5`; the jump needs a compatibility sweep first.
- `zod` 3 → 4 — breaking changes (`.merge()` → `.extend()`, stricter
coercion, different result shape) that touch the MCP + SARIF schema
layers.

## License allowlist update

`lru-cache` switched its declared license from `ISC` → `BlueOak-1.0.0`
at 11.3.x. BlueOak-1.0.0 is an OSI-approved permissive license
(explicitly designed as an MIT/ISC-class modernization with no
ShareAlike / attribution friction).

Added `BlueOak-1.0.0` and `0BSD` to the CI license allowlist
(`.github/workflows/ci.yml`, `mise.toml`) to match what's actually in
the SBOM today. `SECURITY.md` + `CONTRIBUTING.md` updated to mirror.

## Supply chain

- `osv-scanner` — 0 issues on the refreshed 705-package lockfile.
- `SBOM.cdx.json` regenerated from the new lockfile.
- `THIRD_PARTY_LICENSES.md` regenerated (705 components).

## Drive-by fix

`packages/cli/src/commands/setup.test.ts` asserted the bundled plugin
manifest version was `2.0.0` (stale from the pre-launch internal
versioning). Updated to `0.1.0` to match the launch version and unblock
`pnpm -r test`.

## Closes

Should supersede these open Dependabot PRs (will auto-close on next
scan): #6, #7, #8, #9, #10, #11, #12, #13, #14, #15.

## Test plan

- [x] `pnpm install` resolves cleanly
- [x] `pnpm -r build` — all workspaces green
- [x] `pnpm -r exec tsc --noEmit` — 0 type errors
- [x] `pnpm -r test` — 1 stale-assertion fixed, remainder green
- [x] `bash scripts/check-banned-strings.sh` — PASS
- [x] `osv-scanner scan source --lockfile=pnpm-lock.yaml` — 0 issues
- [x] `license-checker-rseidelsohn --onlyAllow '...'` — 0 violations
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant