Bump fast-xml-parser and @opennextjs/cloudflare in /with-nextjs-better-auth-cloudflare-workers by dependabot[bot] · Pull Request #211 · polarsource/examples
Bumps fast-xml-parser to 5.5.8 and updates ancestor dependency @opennextjs/cloudflare. These dependencies need to be updated together.
Updates fast-xml-parser from 5.2.5 to 5.5.8
Release notes
Sourced from fast-xml-parser's releases.
fix entity expansion and incorrect replacement and performance
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.5...v5.5.6
support onDangerousProperty
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.3...v5.5.5
update dependecies to fix typings
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.1...v5.5.2
integrate path-expression-matcher
- support path-expression-matcher
- fix: stopNode should not be parsed
- performance improvement for stopNode checking
Separate Builder
XML Builder was the part of fast-xml-parser for years. But considering that any bug in builder may false-alarm the users who are only using parser and vice-versa, we have decided to split it into a separate package.
Migration
To migrate to fast-xml-builder;
From
import { XMLBuilder } from "fast-xml-parser";To
import XMLBuilder from "fast-xml-builder";XMLBuilder will be removed from current package in any next major version of this library. So better to migrate.
support strictReservedNames
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.3.9...v5.3.9
handle non-array input for XML builder && support maxNestedTags
- support maxNestedTags
- handle non-array input for XML builder when preserveOrder is true (By Angelo Coetzee)
- save use of js properies Full Changelog: NaturalIntelligence/fast-xml-parser@v5.3.7...v5.3.8
CJS typing fix
What's Changed
- Unexport
X2jOptionsat declaration site by@Drarig29in NaturalIntelligence/fast-xml-parser#787New Contributors
@Drarig29made their first contribution in NaturalIntelligence/fast-xml-parser#787
... (truncated)
Changelog
Sourced from fast-xml-parser's changelog.
Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.
Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion
4.5.5 / 2026-03-22
apply fixes from v5 (legacy maintenance branch v4-maintenance)
- support maxEntityCount
- support onDangerousProperty
- support maxNestedTags
- handle prototype pollution
- fix incorrect entity name replacement
- fix incorrect condition for entity expansion
5.5.8 / 2026-03-20
- pass read only matcher in callback
5.5.7 / 2026-03-19
- fix: entity expansion limits
- update strnum package to 2.2.0
5.5.6 / 2026-03-16
- update builder dependency
- fix incorrect regex to replace . in entity name
- fix check for entitiy expansion for lastEntities and html entities too
5.5.5 / 2026-03-13
- sanitize dangerous tag or attribute name
- error on critical property name
- support onDangerousProperty option
5.5.4 / 2026-03-13
- declare Matcher & Expression as unknown so user is not forced to install path-expression-matcher
5.5.3 / 2026-03-11
- upgrade builder
5.5.2 / 2026-03-11
- update dependency to fix typings
5.5.1 / 2026-03-10
- fix dependency
5.5.0 / 2026-03-10
- support path-expression-matcher
- fix: stopNode should not be parsed
- performance improvement for stopNode checking
... (truncated)
Commits
a92a665pass read only matcher in call backa21c441update package detail239b64acheck for min value for entity exapantion options61cb666restrict more properties to be unsafe41abd66performance improvement of reading DOCTYPE3dfcd20refactor: performance improvement870043eupdate release info6df401eupdate builder dependencybd26122check for entitiy expansion for lastEntities and html entities too7e70dd8fix incorrect regex to replace . in entity name- Additional commits viewable in compare view
Updates @opennextjs/cloudflare from 1.13.0 to 1.17.3
Release notes
Sourced from @opennextjs/cloudflare's releases.
@opennextjs/cloudflare@1.17.3Patch Changes
#1160
161e726Thanks@matthewvolk! - fix(patches): includeprefetch-hints.jsonin loadManifest build-time inliningNext.js 16.2.0 introduced
prefetch-hints.jsonas a new server manifest loaded unconditionally byNextNodeServer.getPrefetchHints(). The file exists in the build output but wasn't matched by the glob pattern*-manifest.json, causing the patchedloadManifest()to throw at runtime.
@opennextjs/cloudflare@1.17.2Patch Changes
#1151
a143282Thanks@nathanschram! - fix: handle known optional manifests gracefully in loadManifest/evalManifest patchesNext.js loads certain manifests with
handleMissing: true(returning{}when the file doesn't exist). The adapter's build-time glob scan doesn't find these files when they're conditionally generated, so the patched function threw at runtime, crashing dynamic routes with 500.Instead of a blanket catch-all, handle only the specific optional manifests from Next.js
route-module.ts:
react-loadable-manifest(Turbopack per-route, not all routes have dynamic imports)subresource-integrity-manifest(only whenexperimental.sriconfigured)server-reference-manifest(App Router only)dynamic-css-manifest(Pages Router + Webpack only)fallback-build-manifest(only for/_errorpage)prefetch-hints(new in Next.js 16.2)_client-reference-manifest.js(optional for static metadata routes, evalManifest)Manifest matching strips
.jsonbefore comparison since some Next.js constants omit the extension (SUBRESOURCE_INTEGRITY_MANIFEST,DYNAMIC_CSS_MANIFEST, etc.).Unknown manifests still throw to surface genuine errors.
Fixes #1141.
@opennextjs/cloudflare@1.17.1Patch Changes
@opennextjs/cloudflare@1.17.0Minor Changes
- #1133
25d5835Thanks@dario-piotrowicz! - Update themigratecommand to attempt to create an R2 bucket for caching, if that is not possible an application without caching enabled will be generated instead.
@opennextjs/cloudflare@1.16.6Patch Changes
- #1138
4487f1fThanks@james-elicx! - Fix the CLI potentially setting a future compatibility date in the wrangler config when workerd has published a version matching a future date, by capping to the current date.
... (truncated)
Changelog
Sourced from @opennextjs/cloudflare's changelog.
1.17.3
Patch Changes
#1160
161e726Thanks@matthewvolk! - fix(patches): includeprefetch-hints.jsonin loadManifest build-time inliningNext.js 16.2.0 introduced
prefetch-hints.jsonas a new server manifest loaded unconditionally byNextNodeServer.getPrefetchHints(). The file exists in the build output but wasn't matched by the glob pattern*-manifest.json, causing the patchedloadManifest()to throw at runtime.1.17.2
Patch Changes
#1151
a143282Thanks@nathanschram! - fix: handle known optional manifests gracefully in loadManifest/evalManifest patchesNext.js loads certain manifests with
handleMissing: true(returning{}when the file doesn't exist). The adapter's build-time glob scan doesn't find these files when they're conditionally generated, so the patched function threw at runtime, crashing dynamic routes with 500.Instead of a blanket catch-all, handle only the specific optional manifests from Next.js
route-module.ts:
react-loadable-manifest(Turbopack per-route, not all routes have dynamic imports)subresource-integrity-manifest(only whenexperimental.sriconfigured)server-reference-manifest(App Router only)dynamic-css-manifest(Pages Router + Webpack only)fallback-build-manifest(only for/_errorpage)prefetch-hints(new in Next.js 16.2)_client-reference-manifest.js(optional for static metadata routes, evalManifest)Manifest matching strips
.jsonbefore comparison since some Next.js constants omit the extension (SUBRESOURCE_INTEGRITY_MANIFEST,DYNAMIC_CSS_MANIFEST, etc.).Unknown manifests still throw to surface genuine errors.
Fixes #1141.
1.17.1
Patch Changes
1.17.0
Minor Changes
- #1133
25d5835Thanks@dario-piotrowicz! - Update themigratecommand to attempt to create an R2 bucket for caching, if that is not possible an application without caching enabled will be generated instead.
... (truncated)
Commits
6fdc1e2Version Packages (#1162)161e726fix(patches): include prefetch-hints.json in loadManifest glob for Next.js 16...7ccf5eaVersion Packages (#1161)a143282fix(patches): return empty object for unhandled manifests in loadManifest (#1...206794fVersion Packages (#1149)f5bd138make dev /cdn-cgi/image behaves like prod for consistency (#1147)e965e4drefactor: creation of config files (#1146)7d86f42Version Packages (#1143)25d5835Update themigratecommand to attempt to create an R2 bucket for caching as...2e4e595Version Packages (#1140)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.