Skip to content

chore(deps): bump fast-xml-parser to ^5.5.7#5854

Open
antonis wants to merge 1 commit intomainfrom
antonis/bump-fast-xml-parser
Open

chore(deps): bump fast-xml-parser to ^5.5.7#5854
antonis wants to merge 1 commit intomainfrom
antonis/bump-fast-xml-parser

Conversation

@antonis
Copy link
Contributor

@antonis antonis commented Mar 20, 2026

Bumps the existing fast-xml-parser resolution from ^5.3.6 to ^5.5.7 to fix entity expansion bypass vulnerabilities.

Dev-only dependency.

https://github.com/getsentry/sentry-react-native/security/dependabot/454
https://github.com/getsentry/sentry-react-native/security/dependabot/456

Fixes Dependabot alerts for entity expansion bypass vulnerabilities.

https://github.com/getsentry/sentry-react-native/security/dependabot/454
https://github.com/getsentry/sentry-react-native/security/dependabot/456

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions
Copy link
Contributor

Semver Impact of This PR

None (no version bump detected)

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


  • chore(deps): bump fast-xml-parser to ^5.5.7 by antonis in #5854
  • chore(deps): update JavaScript SDK to v10.45.0 by github-actions in #5848
  • chore(deps): bump flatted from 3.4.1 to 3.4.2 by dependabot in #5853
  • chore(deps): update Cocoa SDK to v9.8.0 by github-actions in #5847
  • fix(tracing): Guard getNewScreenTimeToDisplay behind enableTimeToInitialDisplay by antonis in #5849
  • chore(deps): bump json from 2.16.0 to 2.17.1.2 in /performance-tests by dependabot in #5844
  • chore(docs): Add changelog entry for duplicated breadcrumbs fix by antonis in #5851
  • fix(tracing): Unsubscribe spanEnd listeners after they fire to prevent accumulation by antonis in #5840
  • fix(android): Properly remove duplicated breadcrumbs by vovkasm in #5841
  • fix(tracing): Skip native frames and stall tracking for unsampled spans by antonis in #5842

🤖 This preview updates automatically when you update the PR.

@github-actions
Copy link
Contributor

Fails
🚫 Pull request is not ready for merge, please add the "ready-to-merge" label to the pull request

Generated by 🚫 dangerJS against ce49dfa

@antonis antonis marked this pull request as ready for review March 20, 2026 12:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant