Skip to content

Fix: Critical vulnerability in fast-xml-parser#207

Merged
SbsCruz merged 1 commit into
mainfrom
fix/security-vulnerabilities-fast-xml-parser
May 13, 2026
Merged

Fix: Critical vulnerability in fast-xml-parser#207
SbsCruz merged 1 commit into
mainfrom
fix/security-vulnerabilities-fast-xml-parser

Conversation

@SbsCruz
Copy link
Copy Markdown
Collaborator

@SbsCruz SbsCruz commented May 13, 2026

This PR addresses the critical vulnerability in fast-xml-parser by forcing version 5.7.3 across all dependencies using Yarn resolutions.

This fixes the issue where @rnx-kit/tools-apple was pulling an older, vulnerable version.

Related Security Alert: Dependabot #195

@SbsCruz SbsCruz self-assigned this May 13, 2026
@SbsCruz SbsCruz added the dependencies Pull requests that update a dependency file label May 13, 2026
@SbsCruz SbsCruz force-pushed the fix/security-vulnerabilities-fast-xml-parser branch from 5a331a9 to 62eb7e5 Compare May 13, 2026 17:40
Copy link
Copy Markdown

@suany0805 suany0805 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you for working on this

@SbsCruz SbsCruz merged commit 6653d5a into main May 13, 2026
5 checks passed
@SbsCruz SbsCruz deleted the fix/security-vulnerabilities-fast-xml-parser branch May 13, 2026 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants