Skip to content

refactor: Bump fast-xml-parser from 5.5.9 to 5.8.0 - #10447

Merged
mtrezza merged 1 commit into
alphafrom
dependabot/npm_and_yarn/fast-xml-parser-5.7.1
Jul 13, 2026
Merged

refactor: Bump fast-xml-parser from 5.5.9 to 5.8.0#10447
mtrezza merged 1 commit into
alphafrom
dependabot/npm_and_yarn/fast-xml-parser-5.7.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Apr 23, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-xml-parser from 5.5.9 to 5.8.0.

Release notes

Sourced from fast-xml-parser's releases.

update strnum, FXB. Use xml-naming for DOCTYPE

  • integrate xml-naming to validate DOCTYPE entity name and notation name (using qname because of backward compatibility)
    • This will consider xml-version as well. '1.0' is default
  • update strnum to 2.3.0
    • You can set octal and binary parsing which is by deault off
  • update fast-xml-builder to 1.2.0
    • can sanitize tag names if found invalid
    • fix format output

fix minor old bugs and update builder

  • fix: alwaysCreateTextNode should create text node when attributes are present for self closing node
  • fix stop node expression when ns prefix is removed (found by iruizsalinas)
  • update XML Builder to 1.1.7
  • mark addEntity deprecated

backward compatibility for numerical external entity, fix #705, #817

  • allow numerical external entity for backward compatibility
  • fix #705: attributesGroupName working with preserveOrder
  • fix #817: stackoverflow when tag expression is very long

upgrade @​nodable/entities and FXB

  • Use @nodable/entities v2.1.0
    • breaking changes
      • single entity scan. You're not allowed to use entity value to form another entity name.
      • you cant add numeric external entity
      • entity error message when expantion limit is crossed might change
    • typings are updated for new options related to process entity
    • please follow documentation of @nodable/entities for more detail.
    • performance
      • if processEntities is false, then there should not be impact on performance.
      • if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
      • if processEntities is true, and you pass entity decoder separately
        • if no entity then performance should be same as before
        • if there are entities then performance should be increased from past versions
    • ignoreAttributes is not required to be set to set xml version for NCR entity value
  • update 'fast-xml-builder' to sanitize malicious CDATA and comment's content

use @​nodable/entities to replace entities

  • No API change
  • No change in performance for basic usage
  • No typing change
  • No config change
  • new dependency
  • breaking: error messages for entities might have been changed.

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.12...v5.6.0

performance improvment, increase entity expansion default limit

  • increase default entity explansion limit as many projects demand for that
</tr></table> 

... (truncated)

Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion

*5.8.0 / 2026-05-12

  • integrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)
    • This will consider xml-version as well. '1.0' is default
  • update strnum to 2.3.0
    • You can set octal and binary parsing which is bydeault off
  • update fast-xml-builder to 1.2.0
    • can sanitize tag names if found invalid
    • fix format output

5.7.3 / 2006-05-05

  • fix: alwaysCreateTextNode should create text node when attributes are present for self closing node
  • fix stop node expression when ns prefix is removed (found by iruizsalinas)
  • update XML Builder to 1.1.7
  • mark addEntity deprecated

5.7.2 / 2026-04-25

  • allow numerical external entity for backward compatibility
  • fix #705: attributesGroupName working with preserveOrder
  • fix #817: stackoverflow when tag expression is very long

5.7.1 / 2026-04-20

  • fix typo in CJS typing file

5.7.0 / 2026-04-17

  • Use @nodable/entities v2.1.0
    • breaking changes
      • single entity scan. You're not allowed to user entity value to form another entity name.
      • you cant add numeric external entity
      • entity error message when expantion limit is crossed might change
    • typings are updated for new options related to process entity
    • please follow documentation of @nodable/entities for more detail.
    • performance
      • if processEntities is false, then there should not be impact on performance.
      • if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
      • if processEntities is true, and you pass entity decoder separately
        • if no entity then performance should be same as before
        • if there are entities then performance should be increased from past versions
    • ignoreAttributes is not required to be set to set xml version for NCR entity value
  • update 'fast-xml-builder' to sanitize malicious CDATA and comment's content

5.6.0 / 2026-04-15

  • fix: entity replacement for numeric entities
  • use @​nodable/entities to replace entities
    • this may change some error messages related to entities expansion limit or inavlid use
    • post check would be exposed in future version

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Summary by CodeRabbit

  • Chores
    • Updated XML parsing dependencies and related package metadata.
    • Refreshed supporting libraries for improved compatibility and maintenance.

@dependabot dependabot Bot added dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code labels Apr 23, 2026
@parse-github-assistant

Copy link
Copy Markdown

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant Bot changed the title refactor: bump fast-xml-parser from 5.5.9 to 5.7.1 refactor: Bump fast-xml-parser from 5.5.9 to 5.7.1 Apr 23, 2026
@dependabot dependabot Bot changed the title refactor: Bump fast-xml-parser from 5.5.9 to 5.7.1 refactor: bump fast-xml-parser from 5.5.9 to 5.7.2 Apr 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.7.1 branch from 497626a to 4edae78 Compare April 26, 2026 02:13
@parse-github-assistant

Copy link
Copy Markdown

I will reformat the title to use the proper commit message syntax.

@parse-github-assistant parse-github-assistant Bot changed the title refactor: bump fast-xml-parser from 5.5.9 to 5.7.2 refactor: Bump fast-xml-parser from 5.5.9 to 5.7.2 Apr 26, 2026
@parse-github-assistant

Copy link
Copy Markdown

I will reformat the title to use the proper commit message syntax.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.7.1 branch 2 times, most recently from 5f95692 to 48fcb5e Compare May 1, 2026 12:18
@dependabot dependabot Bot changed the title refactor: Bump fast-xml-parser from 5.5.9 to 5.7.2 refactor: Bump fast-xml-parser from 5.5.9 to 5.8.0 May 17, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.7.1 branch from 48fcb5e to bad73fe Compare May 17, 2026 14:19
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 5.5.9 to 5.8.0.
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.5.9...v5.8.0)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.7.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-xml-parser-5.7.1 branch from bad73fe to acd63e9 Compare May 18, 2026 15:08
@mtrezza

mtrezza commented Jul 13, 2026

Copy link
Copy Markdown
Member

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 13, 2026

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Jul 13, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

Updates package-lock.json with newer XML parsing packages, transitive helpers, and synchronized dependency metadata.

Changes

XML tooling dependency refresh

Layer / File(s) Summary
XML package resolution
package-lock.json
Locks newer versions of @nodable/entities, fast-xml-builder, fast-xml-parser, path-expression-matcher, and strnum, and adds xml-naming.
Top-level dependency records
package-lock.json
Synchronizes top-level versions, integrity metadata, optional metadata, and fast-xml-parser transitive requirements.

Estimated code review effort: 1 (Trivial) | ~5 minutes

Possibly related PRs


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (1 error, 1 inconclusive)

Check name Status Explanation Resolution
Description check ❌ Error The description omits the required Issue, Approach, and Tasks sections from the repository template. Add the template sections and complete the issue link, approach summary, and task checklist items.
Engage In Review Feedback ❓ Inconclusive The tip commit only bumps package-lock.json and the repo contains no review thread or response evidence. Provide the PR review comments or discussion history so I can verify whether feedback was engaged before resolution.
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: bumping fast-xml-parser.
Linked Issues check ✅ Passed The lockfile upgrades fast-xml-parser to 5.8.0, which includes the fixes referenced for issues #705 and #817.
Out of Scope Changes check ✅ Passed The changes are confined to package-lock.json dependency updates and do not add unrelated modifications.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Security Check ✅ Passed Only package-lock changed; updated fast-xml-parser 5.8.0 and fast-xml-builder 1.2.0 are above known advisory fix ranges, with no risky install-script additions.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/npm_and_yarn/fast-xml-parser-5.7.1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mtrezza
mtrezza merged commit a2ea125 into alpha Jul 13, 2026
22 checks passed
@mtrezza
mtrezza deleted the dependabot/npm_and_yarn/fast-xml-parser-5.7.1 branch July 13, 2026 12:05
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.10.1-alpha.1

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Jul 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code state:released-alpha Released as alpha version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants