Skip to content

Conversation

@snatalenko
Copy link

@snatalenko snatalenko commented Feb 2, 2026

What/Why/How?

Upgrade fast-xml-parser dependency to ^5.3.4 to remediate vulnerability CVE-2026-25128. The change updates the package version in dependencies and lockfile with no API changes required.

Reference

Testing

Existing test suite executed with updated dependency and passed without regressions. Local smoke testing of sampling output confirmed behavior parity.

Screenshots (optional)

Check yourself

  • Code is linted
  • Tested
  • All new/updated code is covered with tests

Security

  • Security impact of change has been considered
  • Code follows company security practices and guidelines

Security review completed.

@snatalenko snatalenko requested a review from a team as a code owner February 2, 2026 21:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant