Bump fast-xml-parser and @aws-sdk/xml-builder in /aws/offsite/aurora-snapshots-fargate by dependabot[bot] · Pull Request #71536 · code-dot-org/code-dot-org
Bumps fast-xml-parser and @aws-sdk/xml-builder. These dependencies needed to be updated together.
Updates fast-xml-parser from 5.4.1 to 5.5.8
Release notes
Sourced from fast-xml-parser's releases.
fix entity expansion and incorrect replacement and performance
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.5...v5.5.6
support onDangerousProperty
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.3...v5.5.5
update dependecies to fix typings
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.1...v5.5.2
integrate path-expression-matcher
- support path-expression-matcher
- fix: stopNode should not be parsed
- performance improvement for stopNode checking
Changelog
Sourced from fast-xml-parser's changelog.
Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.
Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion
5.5.8 / 2026-03-20
- pass read only matcher in callback
5.5.7 / 2026-03-19
- fix: entity expansion limits
- update strnum package to 2.2.0
5.5.6 / 2026-03-16
- update builder dependency
- fix incorrect regex to replace . in entity name
- fix check for entitiy expansion for lastEntities and html entities too
5.5.5 / 2026-03-13
- sanitize dangerous tag or attribute name
- error on critical property name
- support onDangerousProperty option
5.5.4 / 2026-03-13
- declare Matcher & Expression as unknown so user is not forced to install path-expression-matcher
5.5.3 / 2026-03-11
- upgrade builder
5.5.2 / 2026-03-11
- update dependency to fix typings
5.5.1 / 2026-03-10
- fix dependency
5.5.0 / 2026-03-10
- support path-expression-matcher
- fix: stopNode should not be parsed
- performance improvement for stopNode checking
5.4.2 / 2026-03-03
- support maxEntityCount option
5.4.1 / 2026-02-25
- fix (#785) unpairedTag node should not have tag content
5.4.0 / 2026-02-25
- migrate to fast-xml-builder
5.3.9 / 2026-02-25
- support strictReservedNames
... (truncated)
Commits
a92a665pass read only matcher in call backa21c441update package detail239b64acheck for min value for entity exapantion options61cb666restrict more properties to be unsafe41abd66performance improvement of reading DOCTYPE3dfcd20refactor: performance improvement870043eupdate release info6df401eupdate builder dependencybd26122check for entitiy expansion for lastEntities and html entities too7e70dd8fix incorrect regex to replace . in entity name- Additional commits viewable in compare view
Updates @aws-sdk/xml-builder from 3.972.9 to 3.972.15
Changelog
Sourced from @aws-sdk/xml-builder's changelog.
3.972.15 (2026-03-20)
Chores
3.972.14 (2026-03-18)
Bug Fixes
Chores
3.972.12 (2026-03-18)
Chores
3.972.11 (2026-03-13)
Chores
3.972.10 (2026-03-04)
Chores
Commits
- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.