Skip to content

Bump the npm_and_yarn group across 1 directory with 2 updates#69

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/npm_and_yarn-3070030e16
Open

Bump the npm_and_yarn group across 1 directory with 2 updates#69
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/npm_and_yarn-3070030e16

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github May 4, 2026

Bumps the npm_and_yarn group with 2 updates in the / directory: fast-xml-parser and uuid.

Updates fast-xml-parser from 5.5.8 to 5.7.2

Release notes

Sourced from fast-xml-parser's releases.

backward compatibility for numerical external entity, fix #705, #817

  • allow numerical external entity for backward compatibility
  • fix #705: attributesGroupName working with preserveOrder
  • fix #817: stackoverflow when tag expression is very long

upgrade @​nodable/entities and FXB

  • Use @nodable/entities v2.1.0
    • breaking changes
      • single entity scan. You're not allowed to use entity value to form another entity name.
      • you cant add numeric external entity
      • entity error message when expantion limit is crossed might change
    • typings are updated for new options related to process entity
    • please follow documentation of @nodable/entities for more detail.
    • performance
      • if processEntities is false, then there should not be impact on performance.
      • if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
      • if processEntities is true, and you pass entity decoder separately
        • if no entity then performance should be same as before
        • if there are entities then performance should be increased from past versions
    • ignoreAttributes is not required to be set to set xml version for NCR entity value
  • update 'fast-xml-builder' to sanitize malicious CDATA and comment's content

use @​nodable/entities to replace entities

  • No API change
  • No change in performance for basic usage
  • No typing change
  • No config change
  • new dependency
  • breaking: error messages for entities might have been changed.

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.12...v5.6.0

performance improvment, increase entity expansion default limit

  • increase default entity explansion limit as many projects demand for that
maxEntitySize: 10000,
maxExpansionDepth: 10000,
maxTotalExpansions: Infinity,
maxExpandedLength: 100000,
maxEntityCount: 1000,
  • performance improvement
    • reduce calls to toString
    • early return when entities are not present
    • prepare rawAttrsForMatcher only if user sets jPath: false

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.9...v5.5.10

fix typins and matcher instance in callbacks

combine typings file to avoid configuration changes

... (truncated)

Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion

5.7.3

  • fix: alwaysCreateTextNode should create text node when attributes are present for self closing node
  • fix stop node expression when ns prefix is removed (found by iruizsalinas)
  • update XML Builder to 1.1.7
  • mark addEntity deprecated

5.7.2 / 2026-04-25

  • allow numerical external entity for backward compatibility
  • fix #705: attributesGroupName working with preserveOrder
  • fix #817: stackoverflow when tag expression is very long

5.7.1 / 2026-04-20

  • fix typo in CJS typing file

5.7.0 / 2026-04-17

  • Use @nodable/entities v2.1.0
    • breaking changes
      • single entity scan. You're not allowed to user entity value to form another entity name.
      • you cant add numeric external entity
      • entity error message when expantion limit is crossed might change
    • typings are updated for new options related to process entity
    • please follow documentation of @nodable/entities for more detail.
    • performance
      • if processEntities is false, then there should not be impact on performance.
      • if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
      • if processEntities is true, and you pass entity decoder separately
        • if no entity then performance should be same as before
        • if there are entities then performance should be increased from past versions
    • ignoreAttributes is not required to be set to set xml version for NCR entity value
  • update 'fast-xml-builder' to sanitize malicious CDATA and comment's content

5.6.0 / 2026-04-15

  • fix: entity replacement for numeric entities
  • use @​nodable/entities to replace entities
    • this may change some error messages related to entities expansion limit or inavlid use
    • post check would be exposed in future version

5.5.12 / 2026-04-13

  • Performance Improvement: update path-expression-matcher
    • use proxy pattern than Proxy class

5.5.11 / 2026-04-08

  • Performance Improvement
    • integrate ExpressionSet for stopNodes

... (truncated)

Commits
  • b1d5b90 update releas info
  • 78571ae tests for long tag expression
  • ebaedc0 allow numerical external entities for backward compatibility
  • 91245eb update changelog
  • 79dd40d fix #705: don not group and nest attributes when both preserveOrder and attri...
  • d6bce3b allow long attribute expressions
  • 9a2561b remove unnecessary
  • 0f08303 fix typo
  • f529642 update to release v5.7.0
  • 52a8583 Revert "improve performance of attributes reading"
  • Additional commits viewable in compare view

Removes uuid

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 2 updates in the / directory: [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) and [uuid](https://github.com/uuidjs/uuid).


Updates `fast-xml-parser` from 5.5.8 to 5.7.2
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.5.8...v5.7.2)

Removes `uuid`

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.7.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: uuid
  dependency-version: 
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 4, 2026
MansiVisuals added a commit that referenced this pull request May 5, 2026
…loop (#68)

Features
- Custom favicon upload (#66): accepts SVG/PNG/ICO up to 100 KB; SVG sanitized via DOMPurify, PNG/ICO magic-byte verified. Served from /api/branding/favicon and overrides the default browser-tab icons.
- Loop playback toggle on the video player (#68).

Upload/download performance
- Worker-side S3 multipart upload now parallel (env S3_SERVER_MULTIPART_CONCURRENCY, default 4).
- s3UploadFile streams chunk-by-chunk; no longer buffers whole transcoded outputs in heap.
- Browser S3 multipart now uses a worker pool instead of Promise.all batches; parts sorted on completion (fixes "Failed to complete upload" for the new pool).
- XMLHttpRequest per-part upload: byte-level onProgress, no more 25 MiB-jump progress bars.
- Per-part retry with 0.5 s / 1.5 s / 4.5 s exponential backoff.
- Presigned part-URL TTL raised from 1 h to 6 h.
- TUS finish uses fs.rename instead of pipeline-copy in FS mode (with EXDEV fallback).
- Backpressure-aware FS download stream (manual pause/resume on desiredSize).
- Range-bounded downloads honor open-ended ranges as "rest of file" instead of capping at 16 MiB.
- ZIP bundles use store: true (no compression on already-compressed video bytes).
- Fire-and-forget download analytics so the browser save dialog opens immediately on click.
- Token-based download for admin Project Uploads (no fetch-into-Blob detour).
- TRANSFER_STREAM_HWM_MB default raised from 4 to 16 MiB.

Security audit fixes
- Cross-project IDOR on recipient PATCH/DELETE: lookup now scoped by projectId.
- Race conditions on default-row creation in 5 endpoints converted to upsert / unique-constraint catch.
- Video approval wrapped in prisma.$transaction.
- Share-page guest auth no longer recurses with stale closure shareToken.
- OTP verify timing oracle removed (no email enumeration via timing).
- Push subscription list survives malformed stored endpoint URLs.
- Cloud-metadata SSRF deny-list on outbound notification URLs (Gotify baseUrl, NTFY serverUrl).
- Missing rate limits added on 6 admin routes (blocklist domains/ips, test-email, logo, security/events DELETE, share/send-otp per-IP).
- crypto.randomUUID for client-side upload IDs.

Dependencies
- Bumped @aws-sdk/client-s3, @aws-sdk/s3-request-presigner, @tus/file-store, bullmq, isomorphic-dompurify, next-intl, nodemailer, postcss within their semver ranges. Satisfies Dependabot PR #69 transitively. @tus/server stays pinned to 2.0.0 (transitive srvx vulnerability not yet patched upstream).

Other
- Removed scripts/ folder (PWA-icon bootstrap was one-shot; icons already committed).
- Wiki docs added for the transfer-tuning env vars (TRANSFER_STREAM_HWM_MB, TRANSFER_STREAM_CHUNK_MB, S3_SERVER_MULTIPART_CONCURRENCY).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants