Skip to content

[Security] Bump fast-xml-parser ^4.5.1 → 4.5.3 (in-range, safe lockfile refresh) #108

Description

@PAMulligan

Summary

Dependabot flagged fast-xml-parser (currently ^4.5.1). The advisory is resolved in 4.5.3, which is within the existing ^4 range, so this is a low-risk, non-breaking lockfile refresh with no expected API changes.

Status

This is the lowest-risk item from the Wk 2 sweep. There is no minimumReleaseAge / version-cooldown guard configured in any repo (checked package.json, pnpm-workspace.yaml, .npmrc, dependabot.yml, and renovate configs), so it can proceed on normal review. No open Dependabot PR exists for it yet.

Proposed work

  • Bump fast-xml-parser to 4.5.3 via pnpm and refresh the lockfile.
  • - [ ] Run Vitest + Stryker mutation gate; confirm CI green.
  • - [ ] Open PR with a Conventional Commits message (e.g. fix(deps): bump fast-xml-parser to 4.5.3).

Notes

Surfaced during the weekly PMDS dependency + security sweep (Wk 2). Good candidate to action first.

Metadata

Metadata

Assignees

Labels

dependenciesPull requests that update a dependency filesecuritySecurity hardening and auditing

Type

No type

Projects

Status
Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions