Skip to content

fix(deps): update fast-xml-parser to 5.6.0 (CVE-2026-33349)#232

Merged
kherembourg merged 1 commit into
mainfrom
fix/fast-xml-parser-cve-2026-33349
Apr 16, 2026
Merged

fix(deps): update fast-xml-parser to 5.6.0 (CVE-2026-33349)#232
kherembourg merged 1 commit into
mainfrom
fix/fast-xml-parser-cve-2026-33349

Conversation

@kherembourg
Copy link
Copy Markdown
Contributor

Summary

  • Updates fast-xml-parser from 5.5.6 to 5.6.0
  • Resolves Dependabot alert #649CVE-2026-33349 (medium severity): entity expansion limits bypassed when set to zero due to JavaScript falsy evaluation
  • This is the last remaining open Dependabot alert on this repo

Test plan

  • yarn test — 139/139 tests pass
  • yarn lint — 0 errors
  • yarn typecheck — passes
  • CI passes (lint, test, build-android, build-ios)

🤖 Generated with Claude Code

Resolves Dependabot alert #649 — entity expansion limits bypassed
when set to zero due to JavaScript falsy evaluation.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@greptile-apps
Copy link
Copy Markdown

greptile-apps Bot commented Apr 16, 2026

No reviewable files after applying ignore patterns.

@kherembourg kherembourg requested a review from chouaibMo April 16, 2026 09:04
@kherembourg kherembourg merged commit 87f4bfd into main Apr 16, 2026
4 checks passed
@kherembourg kherembourg deleted the fix/fast-xml-parser-cve-2026-33349 branch April 16, 2026 09:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants