Bumps fast-xml-parser and @aws-sdk/xml-builder. These dependencies needed to be updated together.
Updates fast-xml-parser from 5.5.8 to 5.7.2
Release notes
Sourced from fast-xml-parser's releases.
backward compatibility for numerical external entity, fix #705, #817
- allow numerical external entity for backward compatibility
- fix #705: attributesGroupName working with preserveOrder
- fix #817: stackoverflow when tag expression is very long
upgrade @nodable/entities and FXB
- Use
@nodable/entities v2.1.0
- breaking changes
- single entity scan. You're not allowed to use entity value to form another entity name.
- you cant add numeric external entity
- entity error message when expantion limit is crossed might change
- typings are updated for new options related to process entity
- please follow documentation of
@nodable/entities for more detail.
- performance
- if processEntities is false, then there should not be impact on performance.
- if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
- if processEntities is true, and you pass entity decoder separately
- if no entity then performance should be same as before
- if there are entities then performance should be increased from past versions
- ignoreAttributes is not required to be set to set xml version for NCR entity value
- update 'fast-xml-builder' to sanitize malicious CDATA and comment's content
use @nodable/entities to replace entities
- No API change
- No change in performance for basic usage
- No typing change
- No config change
- new dependency
- breaking: error messages for entities might have been changed.
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.12...v5.6.0
performance improvment, increase entity expansion default limit
- increase default entity explansion limit as many projects demand for that
maxEntitySize: 10000,
maxExpansionDepth: 10000,
maxTotalExpansions: Infinity,
maxExpandedLength: 100000,
maxEntityCount: 1000,
- performance improvement
- reduce calls to toString
- early return when entities are not present
- prepare rawAttrsForMatcher only if user sets
jPath: false
Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.9...v5.5.10
fix typins and matcher instance in callbacks
combine typings file to avoid configuration changes
... (truncated)
Changelog
Sourced from fast-xml-parser's changelog.
Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.
Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion
5.7.3 / 2006年05月05日
- fix: alwaysCreateTextNode should create text node when attributes are present for self closing node
- fix stop node expression when ns prefix is removed (found by iruizsalinas)
- update XML Builder to 1.1.7
- mark addEntity deprecated
5.7.2 / 2026年04月25日
- allow numerical external entity for backward compatibility
- fix #705: attributesGroupName working with preserveOrder
- fix #817: stackoverflow when tag expression is very long
5.7.1 / 2026年04月20日
- fix typo in CJS typing file
5.7.0 / 2026年04月17日
- Use
@nodable/entities v2.1.0
- breaking changes
- single entity scan. You're not allowed to user entity value to form another entity name.
- you cant add numeric external entity
- entity error message when expantion limit is crossed might change
- typings are updated for new options related to process entity
- please follow documentation of
@nodable/entities for more detail.
- performance
- if processEntities is false, then there should not be impact on performance.
- if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
- if processEntities is true, and you pass entity decoder separately
- if no entity then performance should be same as before
- if there are entities then performance should be increased from past versions
- ignoreAttributes is not required to be set to set xml version for NCR entity value
- update 'fast-xml-builder' to sanitize malicious CDATA and comment's content
5.6.0 / 2026年04月15日
- fix: entity replacement for numeric entities
- use
@nodable/entities to replace entities
- this may change some error messages related to entities expansion limit or inavlid use
- post check would be exposed in future version
5.5.12 / 2026年04月13日
- Performance Improvement: update path-expression-matcher
- use proxy pattern than Proxy class
5.5.11 / 2026年04月08日
- Performance Improvement
- integrate ExpressionSet for stopNodes
... (truncated)
Commits
b1d5b90 update releas info
78571ae tests for long tag expression
ebaedc0 allow numerical external entities for backward compatibility
91245eb update changelog
79dd40d fix #705: don not group and nest attributes when both preserveOrder and attri...
d6bce3b allow long attribute expressions
9a2561b remove unnecessary
0f08303 fix typo
f529642 update to release v5.7.0
52a8583 Revert "improve performance of attributes reading"
- Additional commits viewable in compare view
Updates @aws-sdk/xml-builder from 3.972.17 to 3.972.22
Changelog
Sourced from @aws-sdk/xml-builder's changelog.
3.972.22 (2026年04月28日)
Bug Fixes
- xml-builder: inline nodable/entities for dist format compatibility (#7968) (02b6be6)
Chores
- xml-builder: manual version bump for 3.972.21 release (#7969) (99bfb4b)
3.972.21 (2026年04月27日)
Bug Fixes
- xml-builder: fix(xml-builder): inline nodable/entities for dist format compatibility (#7968)
3.972.20 (2026年04月27日)
Bug Fixes
- xml-builder: use xml 1.1 parsing behavior for entities (#7964) (7a30bce)
3.972.19 (2026年04月23日)
Chores
3.972.18 (2026年04月16日)
Chores
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Bumps fast-xml-parser and @aws-sdk/xml-builder. These dependencies needed to be updated together.
Updates
fast-xml-parserfrom 5.5.8 to 5.7.2Release notes
Sourced from fast-xml-parser's releases.
... (truncated)
Changelog
Sourced from fast-xml-parser's changelog.
... (truncated)
Commits
b1d5b90update releas info78571aetests for long tag expressionebaedc0allow numerical external entities for backward compatibility91245ebupdate changelog79dd40dfix #705: don not group and nest attributes when both preserveOrder and attri...d6bce3ballow long attribute expressions9a2561bremove unnecessary0f08303fix typof529642update to release v5.7.052a8583Revert "improve performance of attributes reading"Updates
@aws-sdk/xml-builderfrom 3.972.17 to 3.972.22Changelog
Sourced from @aws-sdk/xml-builder's changelog.
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.