Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): add fast-xml-parser resolution to v5 #13663

Merged
merged 1 commit into from
Jul 30, 2024

Conversation

israx
Copy link
Member

@israx israx commented Jul 30, 2024

Description of changes

This PR adds the fast-xml-parser dep as a resolution to fix the ongoing depandabot alert

Issue #, if available

Description of how you validated changes

Checklist

  • PR description included
  • yarn test passes
  • Unit Tests are changed or added
  • Relevant documentation is changed or added (and PR referenced)

Checklist for repo maintainers

  • Verify E2E tests for existing workflows are working as expected or add E2E tests for newly added workflows
  • New source file paths included in this PR have been added to CODEOWNERS, if appropriate

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@israx israx requested a review from a team as a code owner July 30, 2024 17:08
@israx israx merged commit eb21a88 into aws-amplify:v5-stable Jul 30, 2024
28 checks passed
@mcintoac-aws
Copy link

Left a similar comment on another PR, but wondering if/when this will be published to npm? And if we will get an updated version for both v5 and v6, since there seem to have been PRs to address the issue in both versions. Thanks.

@mcintoac-aws
Copy link

I believe this will also require further updates to change the dependency versions for the @AWS-SDK packages to 3.621.0, since the older versions have a forced dependency on the vulnerable fast-xml-parser version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants