Skip to content

Conversation

@cjnoname
Copy link
Contributor

@cjnoname cjnoname commented Feb 3, 2026

Summary

Upgrade fast-xml-parser from v4 to v5.3.4 to fix XML parsing security vulnerability.

Changes

  • Bumped fast-xml-parser dependency from ^4.2.5 to ^5.3.4

Testing

  • All unit tests pass, including XML parser configuration tests

@cjnoname cjnoname requested a review from a team as a code owner February 3, 2026 01:27
@betsy
Copy link

betsy commented Feb 3, 2026

unsure why the dayjs stuff changed, but would love the fast-xml-parser upgrade to fix the vuln, thank you for this and hoping it can get reviewed quickly!

@cjnoname
Copy link
Contributor Author

cjnoname commented Feb 3, 2026

unsure why the dayjs stuff changed, but would love the fast-xml-parser upgrade to fix the vuln, thank you for this and hoping it can get reviewed quickly!

My bad, it has been cleaned up.

Fixes XML parsing security vulnerability by upgrading fast-xml-parser from v4 to v5.3.4.
@sfc-gh-dszmolka sfc-gh-dszmolka changed the title deps: upgrade fast-xml-parser to 5.3.4 SNOW-3043109: deps: upgrade fast-xml-parser to 5.3.4 Feb 4, 2026
@sfc-gh-rsavenok sfc-gh-rsavenok merged commit faac062 into snowflakedb:master Feb 4, 2026
64 of 70 checks passed
@github-actions github-actions bot locked and limited conversation to collaborators Feb 4, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants