fix(deps): bump fast-xml-parser, @aws-sdk/client-cloudfront and @aws-sdk/client-s3 by dependabot[bot] · Pull Request #416 · oracle/create-database-app
Bumps fast-xml-parser, @aws-sdk/client-cloudfront and @aws-sdk/client-s3. These dependencies needed to be updated together.
Updates fast-xml-parser from 4.4.1 to 5.5.8
Release notes
Sourced from fast-xml-parser's releases.
fix entity expansion and incorrect replacement and performance
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.5...v5.5.6
support onDangerousProperty
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.3...v5.5.5
update dependecies to fix typings
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.1...v5.5.2
integrate path-expression-matcher
- support path-expression-matcher
- fix: stopNode should not be parsed
- performance improvement for stopNode checking
Separate Builder
XML Builder was the part of fast-xml-parser for years. But considering that any bug in builder may false-alarm the users who are only using parser and vice-versa, we have decided to split it into a separate package.
Migration
To migrate to fast-xml-builder;
From
import { XMLBuilder } from "fast-xml-parser";To
import XMLBuilder from "fast-xml-builder";XMLBuilder will be removed from current package in any next major version of this library. So better to migrate.
support strictReservedNames
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.3.9...v5.3.9
handle non-array input for XML builder && support maxNestedTags
- support maxNestedTags
- handle non-array input for XML builder when preserveOrder is true (By Angelo Coetzee)
- save use of js properies Full Changelog: NaturalIntelligence/fast-xml-parser@v5.3.7...v5.3.8
CJS typing fix
What's Changed
- Unexport
X2jOptionsat declaration site by@Drarig29in NaturalIntelligence/fast-xml-parser#787New Contributors
@Drarig29made their first contribution in NaturalIntelligence/fast-xml-parser#787
... (truncated)
Changelog
Sourced from fast-xml-parser's changelog.
Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.
Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion
4.5.5 / 2026-03-22
apply fixes from v5 (legacy maintenance branch v4-maintenance)
- support maxEntityCount
- support onDangerousProperty
- support maxNestedTags
- handle prototype pollution
- fix incorrect entity name replacement
- fix incorrect condition for entity expansion
5.5.8 / 2026-03-20
- pass read only matcher in callback
5.5.7 / 2026-03-19
- fix: entity expansion limits
- update strnum package to 2.2.0
5.5.6 / 2026-03-16
- update builder dependency
- fix incorrect regex to replace . in entity name
- fix check for entitiy expansion for lastEntities and html entities too
5.5.5 / 2026-03-13
- sanitize dangerous tag or attribute name
- error on critical property name
- support onDangerousProperty option
5.5.4 / 2026-03-13
- declare Matcher & Expression as unknown so user is not forced to install path-expression-matcher
5.5.3 / 2026-03-11
- upgrade builder
5.5.2 / 2026-03-11
- update dependency to fix typings
5.5.1 / 2026-03-10
- fix dependency
5.5.0 / 2026-03-10
- support path-expression-matcher
- fix: stopNode should not be parsed
- performance improvement for stopNode checking
... (truncated)
Commits
a92a665pass read only matcher in call backa21c441update package detail239b64acheck for min value for entity exapantion options61cb666restrict more properties to be unsafe41abd66performance improvement of reading DOCTYPE3dfcd20refactor: performance improvement870043eupdate release info6df401eupdate builder dependencybd26122check for entitiy expansion for lastEntities and html entities too7e70dd8fix incorrect regex to replace . in entity name- Additional commits viewable in compare view
Updates @aws-sdk/client-cloudfront from 3.787.0 to 3.1016.0
Release notes
Sourced from @aws-sdk/client-cloudfront's releases.
v3.1016.0
3.1016.0(2026-03-24)
Documentation Changes
- client-gamelift: Amazon GameLift Servers launches UDP ping beacons in the Beijing and Ningxia (China) Regions to help measure real-time network latency for multiplayer games. The ListLocations API is now available in these regions to provide endpoint domain and port information as part of the locations list. (83fcd2fd)
New Features
- client-pcs: This release adds support for custom slurmdbd and cgroup configuration in AWS PCS. Customers can now specify slurmdbd and cgroup settings to configure database accounting and reporting for their HPC workloads, and control resource allocation and limits for compute jobs. (e95c8062)
- client-bedrock-agentcore-control: Adds SDK support for 1) Persist session state in AgentCore Runtime via filesystemConfigurations in CreateAgentRuntime, UpdateAgentRuntime, and GetAgentRuntime APIs, 2) Optional name-based filtering on AgentCore ListBrowserProfiles API. (72c67eb2)
- client-opensearchserverless: Adds support for updating the vector options field for existing collections. (e2ec053d)
- client-mediapackagev2: Reduces the minimum allowed value for startOverWindowSeconds from 60 to 0, allowing customers to effectively disable the start-over window. (7f932107)
- client-rds: Adds support in Aurora PostgreSQL serverless databases for express configuration based creation through WithExpressConfiguration in CreateDbCluster API, and for restoring clusters using RestoreDBClusterToPointInTime and RestoreDBClusterFromSnapshot APIs. (d1038f0f)
For list of updated packages, view updated-packages.md in assets-3.1016.0.zip
v3.1015.0
3.1015.0(2026-03-23)
Chores
New Features
- client-lightsail: Add support for tagging of ContactMethod resource type (9e5c87c6)
- client-batch: AWS Batch AMI Visibility feature support. Adds read-only batchImageStatus to Ec2Configuration to provide visibility on the status of Batch-vended AMIs used by Compute Environments. (a1eace0c)
- client-connectcases: You can now use the UpdateRelatedItem API to update the content of comments and custom related items associated with a case. (ca3fcd61)
- client-omics: Adds support for batch workflow runs in Amazon Omics, enabling users to submit, manage, and monitor multiple runs as a single batch. Includes APIs to create, cancel, and delete batches, track submission statuses and counts, list runs within a batch, and configure default settings. (5dd6fe2f)
Bug Fixes
- core/protocols: use composite error registry for error handling, revert default error message to "UnknownError" (#7877) (55f77269)
For list of updated packages, view updated-packages.md in assets-3.1015.0.zip
v3.1014.0
3.1014.0(2026-03-20)
Chores
... (truncated)
Changelog
Sourced from @aws-sdk/client-cloudfront's changelog.
3.1016.0 (2026-03-24)
Note: Version bump only for package
@aws-sdk/client-cloudfront3.1015.0 (2026-03-23)
Note: Version bump only for package
@aws-sdk/client-cloudfront3.1014.0 (2026-03-20)
Note: Version bump only for package
@aws-sdk/client-cloudfront3.1013.0 (2026-03-19)
Note: Version bump only for package
@aws-sdk/client-cloudfront3.1012.0 (2026-03-18)
Note: Version bump only for package
@aws-sdk/client-cloudfront3.1011.0 (2026-03-17)
Note: Version bump only for package
@aws-sdk/client-cloudfront3.1010.0 (2026-03-16)
... (truncated)
Commits
7ca64d5Publish v3.1016.009b1455Publish v3.1015.0577a874Publish v3.1014.0414aa0dchore: bump smithy versions19ca473Publish v3.1013.07f54759Publish v3.1012.0950b0c2chore(codegen): smithy-aws-typescript-codegen 0.47.0 (#7854)e171694Publish v3.1011.02aa1e6cPublish v3.1010.07888030Publish v3.1009.0- Additional commits viewable in compare view
Updates @aws-sdk/client-s3 from 3.787.0 to 3.1016.0
Release notes
Sourced from @aws-sdk/client-s3's releases.
v3.1016.0
3.1016.0(2026-03-24)
Documentation Changes
- client-gamelift: Amazon GameLift Servers launches UDP ping beacons in the Beijing and Ningxia (China) Regions to help measure real-time network latency for multiplayer games. The ListLocations API is now available in these regions to provide endpoint domain and port information as part of the locations list. (83fcd2fd)
New Features
- client-pcs: This release adds support for custom slurmdbd and cgroup configuration in AWS PCS. Customers can now specify slurmdbd and cgroup settings to configure database accounting and reporting for their HPC workloads, and control resource allocation and limits for compute jobs. (e95c8062)
- client-bedrock-agentcore-control: Adds SDK support for 1) Persist session state in AgentCore Runtime via filesystemConfigurations in CreateAgentRuntime, UpdateAgentRuntime, and GetAgentRuntime APIs, 2) Optional name-based filtering on AgentCore ListBrowserProfiles API. (72c67eb2)
- client-opensearchserverless: Adds support for updating the vector options field for existing collections. (e2ec053d)
- client-mediapackagev2: Reduces the minimum allowed value for startOverWindowSeconds from 60 to 0, allowing customers to effectively disable the start-over window. (7f932107)
- client-rds: Adds support in Aurora PostgreSQL serverless databases for express configuration based creation through WithExpressConfiguration in CreateDbCluster API, and for restoring clusters using RestoreDBClusterToPointInTime and RestoreDBClusterFromSnapshot APIs. (d1038f0f)
For list of updated packages, view updated-packages.md in assets-3.1016.0.zip
v3.1015.0
3.1015.0(2026-03-23)
Chores
New Features
- client-lightsail: Add support for tagging of ContactMethod resource type (9e5c87c6)
- client-batch: AWS Batch AMI Visibility feature support. Adds read-only batchImageStatus to Ec2Configuration to provide visibility on the status of Batch-vended AMIs used by Compute Environments. (a1eace0c)
- client-connectcases: You can now use the UpdateRelatedItem API to update the content of comments and custom related items associated with a case. (ca3fcd61)
- client-omics: Adds support for batch workflow runs in Amazon Omics, enabling users to submit, manage, and monitor multiple runs as a single batch. Includes APIs to create, cancel, and delete batches, track submission statuses and counts, list runs within a batch, and configure default settings. (5dd6fe2f)
Bug Fixes
- core/protocols: use composite error registry for error handling, revert default error message to "UnknownError" (#7877) (55f77269)
For list of updated packages, view updated-packages.md in assets-3.1015.0.zip
v3.1014.0
3.1014.0(2026-03-20)
Chores
... (truncated)
Changelog
Sourced from @aws-sdk/client-s3's changelog.
3.1016.0 (2026-03-24)
Note: Version bump only for package
@aws-sdk/client-s33.1015.0 (2026-03-23)
Note: Version bump only for package
@aws-sdk/client-s33.1014.0 (2026-03-20)
Note: Version bump only for package
@aws-sdk/client-s33.1013.0 (2026-03-19)
Note: Version bump only for package
@aws-sdk/client-s33.1012.0 (2026-03-18)
Note: Version bump only for package
@aws-sdk/client-s33.1011.0 (2026-03-17)
Note: Version bump only for package
@aws-sdk/client-s33.1010.0 (2026-03-16)
... (truncated)
Commits
7ca64d5Publish v3.1016.009b1455Publish v3.1015.0577a874Publish v3.1014.0414aa0dchore: bump smithy versions19ca473Publish v3.1013.07f54759Publish v3.1012.0950b0c2chore(codegen): smithy-aws-typescript-codegen 0.47.0 (#7854)e171694Publish v3.1011.02aa1e6cPublish v3.1010.07888030Publish v3.1009.0- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.