Skip to content

chore(deps): bump fast-xml-parser from 5.4.1 to 5.5.7#7374

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/fast-xml-parser-5.5.7
Open

chore(deps): bump fast-xml-parser from 5.4.1 to 5.5.7#7374
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/fast-xml-parser-5.5.7

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 20, 2026

Bumps fast-xml-parser from 5.4.1 to 5.5.7.

Release notes

Sourced from fast-xml-parser's releases.

fix bugs of entity parsing and value parsing

fix: entity expansion limits update strnum package to 2.2.0

fix entity expansion and incorrect replacement and performance

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.5...v5.5.6

support onDangerousProperty

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.3...v5.5.5

update dependecies to fix typings

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.1...v5.5.2

integrate path-expression-matcher

  • support path-expression-matcher
  • fix: stopNode should not be parsed
  • performance improvement for stopNode checking
Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion

5.5.10 / 2026-04-03

  • increase default entity explansion limit as many projects demand for that
  • performance improvement
    • reduce calls to toString
    • early return when entities are not present
    • prepare rawAttrsForMatcher only if user sets jPath: false

5.5.9 / 2026-03-23

  • combine typing files

4.5.5 / 2026-03-22

apply fixes from v5 (legacy maintenance branch v4-maintenance)

  • support maxEntityCount
  • support onDangerousProperty
  • support maxNestedTags
  • handle prototype pollution
  • fix incorrect entity name replacement
  • fix incorrect condition for entity expansion

5.5.8 / 2026-03-20

  • pass read only matcher in callback

5.5.7 / 2026-03-19

  • fix: entity expansion limits
  • update strnum package to 2.2.0

5.5.6 / 2026-03-16

  • update builder dependency
  • fix incorrect regex to replace . in entity name
  • fix check for entitiy expansion for lastEntities and html entities too

5.5.5 / 2026-03-13

  • sanitize dangerous tag or attribute name
  • error on critical property name
  • support onDangerousProperty option

5.5.4 / 2026-03-13

  • declare Matcher & Expression as unknown so user is not forced to install path-expression-matcher

5.5.3 / 2026-03-11

... (truncated)

Commits
  • a21c441 update package detail
  • 239b64a check for min value for entity exapantion options
  • 61cb666 restrict more properties to be unsafe
  • 41abd66 performance improvement of reading DOCTYPE
  • 3dfcd20 refactor: performance improvement
  • 870043e update release info
  • 6df401e update builder dependency
  • bd26122 check for entitiy expansion for lastEntities and html entities too
  • 7e70dd8 fix incorrect regex to replace . in entity name
  • e54155f update package info
  • Additional commits viewable in compare view

@dependabot dependabot bot added dependencies javascript Pull requests that update javascript code labels Mar 20, 2026
Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0750080b4f

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment on lines 526 to 528
"@app/address-service@workspace:apps/address-service":
version: 0.0.0-use.local
resolution: "@app/address-service@workspace:apps/address-service"
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Restore submodule workspace entries in yarn.lock

This lockfile hunk prunes the @app/* workspace stanzas for initialized submodule apps (for example accruals-gateway, billing-connector, resident-app, etc.), even though those paths are still declared in .gitmodules. I checked .github/workflows/nodejs.condo.ci.yml:144-149,278-281 and packages.release.yml:22-36: those jobs explicitly check out submodules recursively and then run yarn install --immutable. On those checkouts Yarn will re-add the missing workspace entries and fail the immutable install, so this dependency bump becomes CI-breaking for any workflow that includes submodules.

Useful? React with 👍 / 👎.

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from 0750080 to c8e2956 Compare March 20, 2026 15:57
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from c8e2956 to 383c2f6 Compare March 20, 2026 17:52
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from 383c2f6 to e889f14 Compare March 23, 2026 18:54
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from e889f14 to 2209859 Compare March 29, 2026 08:01
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from 2209859 to b3156af Compare March 29, 2026 18:09
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from b3156af to 70037dd Compare March 30, 2026 06:11
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from 70037dd to f7bfedf Compare March 30, 2026 07:00
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from f7bfedf to 10fd849 Compare April 2, 2026 14:02
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.4.1 to 5.5.7.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.4.1...v5.5.7)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.5.7
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.5.7 branch from 10fd849 to b57de76 Compare April 8, 2026 13:07
@sonarqubecloud
Copy link
Copy Markdown

sonarqubecloud bot commented Apr 8, 2026

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

0 participants