Summary
Dependabot flagged fast-xml-parser (currently ^4.5.1). The advisory is resolved in 4.5.3, which is within the existing ^4 range, so this is a low-risk, non-breaking lockfile refresh with no expected API changes.
Status
This is the lowest-risk item from the Wk 2 sweep. There is no minimumReleaseAge / version-cooldown guard configured in any repo (checked package.json, pnpm-workspace.yaml, .npmrc, dependabot.yml, and renovate configs), so it can proceed on normal review. No open Dependabot PR exists for it yet.
Proposed work
Notes
Surfaced during the weekly PMDS dependency + security sweep (Wk 2). Good candidate to action first.
Summary
Dependabot flagged
fast-xml-parser(currently^4.5.1). The advisory is resolved in 4.5.3, which is within the existing^4range, so this is a low-risk, non-breaking lockfile refresh with no expected API changes.Status
This is the lowest-risk item from the Wk 2 sweep. There is no
minimumReleaseAge/ version-cooldown guard configured in any repo (checked package.json, pnpm-workspace.yaml, .npmrc, dependabot.yml, and renovate configs), so it can proceed on normal review. No open Dependabot PR exists for it yet.Proposed work
fix(deps): bump fast-xml-parser to 4.5.3).Notes
Surfaced during the weekly PMDS dependency + security sweep (Wk 2). Good candidate to action first.