Skip to content

chore: fix fast-xml-parser vulnerability#3141

Open
Simone319 wants to merge 8 commits intomainfrom
fix/fast-xml-parser
Open

chore: fix fast-xml-parser vulnerability#3141
Simone319 wants to merge 8 commits intomainfrom
fix/fast-xml-parser

Conversation

@Simone319
Copy link
Copy Markdown
Contributor

Problem

Update fast-xml-parser version to fix vulnerability in >= 4.1.3, < 4.5.4 and >= 5.0.0, < 5.3.6

Issue number, if available:

Changes

Corresponding docs PR, if applicable:

Validation

Checklist

  • If this PR includes a functional change to the runtime behavior of the code, I have added or updated automated test coverage for this change.
  • If this PR requires a change to the Project Architecture README, I have included that update in this PR.
  • If this PR requires a docs update, I have linked to that docs PR above.
  • If this PR modifies E2E tests, makes changes to resource provisioning, or makes SDK calls, I have run the PR checks with the run-e2e label set.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@Simone319 Simone319 requested review from a team as code owners March 15, 2026 17:31
@Simone319 Simone319 added the run-e2e Label that will include e2e tests in PR checks workflow label Mar 15, 2026
@changeset-bot
Copy link
Copy Markdown

changeset-bot bot commented Mar 15, 2026

🦋 Changeset detected

Latest commit: e7eef0c

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 14 packages
Name Type
@aws-amplify/integration-tests Minor
@aws-amplify/backend-deployer Minor
@aws-amplify/backend-function Minor
@aws-amplify/model-generator Minor
@aws-amplify/backend-secret Minor
@aws-amplify/form-generator Minor
@aws-amplify/platform-core Minor
@aws-amplify/backend-auth Minor
@aws-amplify/plugin-types Minor
@aws-amplify/cli-core Minor
@aws-amplify/backend Minor
@aws-amplify/sandbox Minor
@aws-amplify/seed Minor
@aws-amplify/backend-cli Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

Comment thread package-lock.json
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The amount of changes in the package-lock.json looks huge. Do we know why is it so?

@Simone319 Simone319 requested a review from a team as a code owner March 16, 2026 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

run-e2e Label that will include e2e tests in PR checks workflow

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants