Skip to content

Bump @xmldom/xmldom, @sap-ux/axios-extension and @sap-ux/system-access#124

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/multi-826d193e4d
Closed

Bump @xmldom/xmldom, @sap-ux/axios-extension and @sap-ux/system-access#124
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/multi-826d193e4d

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Apr 10, 2026

Bumps @xmldom/xmldom to 0.8.12 and updates ancestor dependencies @xmldom/xmldom, @sap-ux/axios-extension and @sap-ux/system-access. These dependencies need to be updated together.

Updates @xmldom/xmldom from 0.8.10 to 0.8.12

Release notes

Sourced from @​xmldom/xmldom's releases.

0.8.12

Commits

Fixed

Code that passes a string containing "]]>" to createCDATASection and relied on the previously unsafe behavior will now receive InvalidCharacterError. Use a mutation method such as appendData if you intentionally need "]]>" in a CDATASection node's data.

Thank you, @​thesmartshadow, @​stevenobiajulu, for your contributions

xmldom/xmldom#357

0.8.11

0.8.11

Fixed

Thank you, @​shunkica, for your contributions

Changelog

Sourced from @​xmldom/xmldom's changelog.

0.8.12

Fixed

Code that passes a string containing "]]>" to createCDATASection and relied on the previously unsafe behavior will now receive InvalidCharacterError. Use a mutation method such as appendData if you intentionally need "]]>" in a CDATASection node's data.

Thank you, @​thesmartshadow, @​stevenobiajulu, for your contributions

0.8.11

Fixed

Thank you, @​shunkica, for your contributions

0.9.8

Fixed

Chore

Thank you, @​kboshold, @​Ponynjaa, for your contributions.

0.9.7

Added

Fixed

... (truncated)

Commits
  • 189cb78 0.8.12
  • ed08df7 fix: XML injection via unsafe CDATA serialization (GHSA-wh4c-j3r5-mjhp) (#968)
  • a5b929b chore: clean up generated test artefacts before running ci-local
  • 4e37a20 ci: run format:check in lint job
  • ac0ac77 chore: ignore generated files when checking formatting
  • 968c893 chore: add local CI script and format:check script
  • ac40424 fix: preserve trailing whitespace in ProcessingInstruction data (#962)
  • cece752 chore: add .nvmrc pointing to node version 18
  • cbf44d9 docs: improve links to changes in most recent release
  • c0f1401 0.8.11
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by karfau, a new releaser for @​xmldom/xmldom since your current version.


Updates @sap-ux/axios-extension from 1.25.24 to 1.25.29

Release notes

Sourced from @​sap-ux/axios-extension's releases.

@​sap-ux/axios-extension@​1.25.29

Patch Changes

  • f1e4481: chore: upgrade lodash 4.17.23 → 4.18.1 (CVE security fix, vulnerable range <=4.17.23)
  • f1e4481: chore(axios-extension): upgrade @​xmldom/xmldom 0.8.11 → 0.8.12 (security fix)
  • Updated dependencies [f1e4481]
    • @​sap-ux/logger@​0.8.5
    • @​sap-ux/btp-utils@​1.1.12
Changelog

Sourced from @​sap-ux/axios-extension's changelog.

1.25.29

Patch Changes

  • f1e4481: chore: upgrade lodash 4.17.23 → 4.18.1 (CVE security fix, vulnerable range <=4.17.23)
  • f1e4481: chore(axios-extension): upgrade @​xmldom/xmldom 0.8.11 → 0.8.12 (security fix)
  • Updated dependencies [f1e4481]
    • @​sap-ux/logger@​0.8.5
    • @​sap-ux/btp-utils@​1.1.12

1.25.28

Patch Changes

  • c53a4ba: chore(axios-extension): upgrade shared devDependencies (jest 30, axios 1.13.6, ws 8.20.0)
  • Updated dependencies [c53a4ba]
  • Updated dependencies [c53a4ba]
    • @​sap-ux/feature-toggle@​0.3.8
    • @​sap-ux/logger@​0.8.4
    • @​sap-ux/btp-utils@​1.1.12

1.25.27

Patch Changes

  • Updated dependencies [2e17a6b]
    • @​sap-ux/btp-utils@​1.1.12

1.25.26

Patch Changes

  • a41533f: chore(axios-extension): upgrade runtime dependencies (axios 1.13.6, fast-xml-parser 5.5.9, qs 6.15.0, xpath 0.0.34, @​xmldom/xmldom 0.8.11)
  • Updated dependencies [a41533f]
  • Updated dependencies [a41533f]
    • @​sap-ux/btp-utils@​1.1.11
    • @​sap-ux/logger@​0.8.3

1.25.25

Patch Changes

  • c0e05ab: Updates catalog services dedup logic to include url
Commits

Updates @sap-ux/system-access from 0.6.66 to 0.7.5

Release notes

Sourced from @​sap-ux/system-access's releases.

@​sap-ux/system-access@​0.7.5

Patch Changes

  • Updated dependencies [f1e4481]
  • Updated dependencies [f1e4481]
    • @​sap-ux/axios-extension@​1.25.29
    • @​sap-ux/logger@​0.8.5
    • @​sap-ux/btp-utils@​1.1.12
    • @​sap-ux/store@​1.5.13
Changelog

Sourced from @​sap-ux/system-access's changelog.

0.7.5

Patch Changes

  • Updated dependencies [f1e4481]
  • Updated dependencies [f1e4481]
    • @​sap-ux/axios-extension@​1.25.29
    • @​sap-ux/logger@​0.8.5
    • @​sap-ux/btp-utils@​1.1.12
    • @​sap-ux/store@​1.5.13

0.7.4

Patch Changes

  • Updated dependencies [c53a4ba]
  • Updated dependencies [c53a4ba]
  • Updated dependencies [c53a4ba]
    • @​sap-ux/axios-extension@​1.25.28
    • @​sap-ux/logger@​0.8.4
    • @​sap-ux/store@​1.5.12
    • @​sap-ux/btp-utils@​1.1.12

0.7.3

Patch Changes

  • Updated dependencies [2e17a6b]
    • @​sap-ux/btp-utils@​1.1.12
    • @​sap-ux/axios-extension@​1.25.27

0.7.2

Patch Changes

  • Updated dependencies [a41533f]
  • Updated dependencies [a41533f]
  • Updated dependencies [a41533f]
  • Updated dependencies [a41533f]
    • @​sap-ux/axios-extension@​1.25.26
    • @​sap-ux/btp-utils@​1.1.11
    • @​sap-ux/logger@​0.8.3
    • @​sap-ux/store@​1.5.11

0.7.1

Patch Changes

  • Updated dependencies [c0e05ab]
    • @​sap-ux/axios-extension@​1.25.25

... (truncated)

Commits
  • 7ac1410 chore: apply latest changesets
  • ea3e098 chore: apply latest changesets
  • c3a95a9 chore: apply latest changesets
  • ab0348b chore: apply latest changesets
  • a41533f chore(dependencies) - Upgrade devDependencies (#4451)
  • 649613c chore: apply latest changesets
  • ac44a88 chore: apply latest changesets
  • 25e5177 feat: support for full service url systems in the generator (#4392)
  • 84bc17f chore: apply latest changesets
  • 3619b8a chore: apply latest changesets
  • Additional commits viewable in compare view

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 10, 2026
Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) to 0.8.12 and updates ancestor dependencies [@xmldom/xmldom](https://github.com/xmldom/xmldom), [@sap-ux/axios-extension](https://github.com/SAP/open-ux-tools/tree/HEAD/packages/axios-extension) and [@sap-ux/system-access](https://github.com/SAP/open-ux-tools/tree/HEAD/packages/system-access). These dependencies need to be updated together.


Updates `@xmldom/xmldom` from 0.8.10 to 0.8.12
- [Release notes](https://github.com/xmldom/xmldom/releases)
- [Changelog](https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md)
- [Commits](xmldom/xmldom@0.8.10...0.8.12)

Updates `@sap-ux/axios-extension` from 1.25.24 to 1.25.29
- [Release notes](https://github.com/SAP/open-ux-tools/releases)
- [Changelog](https://github.com/SAP/open-ux-tools/blob/main/packages/axios-extension/CHANGELOG.md)
- [Commits](https://github.com/SAP/open-ux-tools/commits/@sap-ux/axios-extension@1.25.29/packages/axios-extension)

Updates `@sap-ux/system-access` from 0.6.66 to 0.7.5
- [Release notes](https://github.com/SAP/open-ux-tools/releases)
- [Changelog](https://github.com/SAP/open-ux-tools/blob/main/packages/system-access/CHANGELOG.md)
- [Commits](https://github.com/SAP/open-ux-tools/commits/@sap-ux/system-access@0.7.5/packages/system-access)

---
updated-dependencies:
- dependency-name: "@xmldom/xmldom"
  dependency-version: 0.8.12
  dependency-type: indirect
- dependency-name: "@sap-ux/axios-extension"
  dependency-version: 1.25.29
  dependency-type: direct:production
- dependency-name: "@sap-ux/system-access"
  dependency-version: 0.7.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/multi-826d193e4d branch from 59ba435 to 3b3c30e Compare April 14, 2026 08:29
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Apr 14, 2026

Looks like these dependencies are up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Apr 14, 2026
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/multi-826d193e4d branch April 14, 2026 08:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants