Skip to content

fix: update fast-xml-parser to 5.4.1#1667

Merged
jennifer-shehane merged 2 commits intocypress-io:masterfrom
MikeMcC399:update/fast-xml-parser
Feb 27, 2026
Merged

fix: update fast-xml-parser to 5.4.1#1667
jennifer-shehane merged 2 commits intocypress-io:masterfrom
MikeMcC399:update/fast-xml-parser

Conversation

@MikeMcC399
Copy link
Collaborator

Situation

npm audit shows a vulnerability GHSA-fj3w-jwp8-x2g3 in dependencies

$ npm audit --omit=dev
# npm audit report

fast-xml-parser  <5.3.8
fast-xml-parser has stack overflow in XMLBuilder with preserveOrder - https://github.com/advisories/GHSA-fj3w-jwp8-x2g3
fix available via `npm audit fix`
node_modules/fast-xml-parser

1 low severity vulnerability

To address all issues, run:
  npm audit fix

Change

Use npm audit fix to update fast-xml-parser to 5.4.1

@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 added bug Something isn't working type: dependencies labels Feb 27, 2026
@MikeMcC399 MikeMcC399 self-assigned this Feb 27, 2026
@MikeMcC399 MikeMcC399 changed the title fix: update fast-yml-parser to 5.4.1 fix: update fast-xml-parser to 5.4.1 Feb 27, 2026
Update also
minimatch to 10.2.4
@MikeMcC399 MikeMcC399 force-pushed the update/fast-xml-parser branch from bff1667 to be45836 Compare February 27, 2026 08:56
@MikeMcC399 MikeMcC399 marked this pull request as ready for review February 27, 2026 09:17
@jennifer-shehane jennifer-shehane merged commit bc22e01 into cypress-io:master Feb 27, 2026
84 checks passed
@github-actions
Copy link

🎉 This PR is included in version 7.1.5 🎉

The release is available on:

Your semantic-release bot 📦🚀

@MikeMcC399 MikeMcC399 deleted the update/fast-xml-parser branch February 27, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants