Skip to content

fix(deps): bump fast-xml-parser from 4.3.4 to 4.4.1.#26202

Merged
bergeron merged 1 commit intodevelopfrom
brian/xml-dep-bump
Jul 29, 2024
Merged

fix(deps): bump fast-xml-parser from 4.3.4 to 4.4.1.#26202
bergeron merged 1 commit intodevelopfrom
brian/xml-dep-bump

Conversation

@bergeron
Copy link
Copy Markdown
Contributor

@bergeron bergeron commented Jul 29, 2024

Description

Fix audit:

└─ fast-xml-parser
   ├─ ID: 1098305
   ├─ Issue: fast-xml-parser vulnerable to ReDOS at currency parsing
   ├─ URL: https://github.com/advisories/GHSA-mpg4-rc92-vx8v
   ├─ Severity: high
   ├─ Vulnerable Versions: <4.4.1
   │ 
   ├─ Tree Versions
   │  └─ 4.3.4

Open in GitHub Codespaces

Related issues

Manual testing steps

Screenshots/Recordings

Before

After

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

@bergeron bergeron requested a review from a team as a code owner July 29, 2024 19:13
@github-actions
Copy link
Copy Markdown
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

@sonarqubecloud
Copy link
Copy Markdown

Copy link
Copy Markdown
Member

@Gudahtt Gudahtt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@bergeron bergeron merged commit f53dc06 into develop Jul 29, 2024
@bergeron bergeron deleted the brian/xml-dep-bump branch July 29, 2024 19:34
@github-actions github-actions bot locked and limited conversation to collaborators Jul 29, 2024
@metamaskbot metamaskbot added the release-12.4.0 Issue or pull request that will be included in release 12.4.0 label Jul 29, 2024
@metamaskbot
Copy link
Copy Markdown
Collaborator

Builds ready [a1aaee8]
Page Load Metrics (152 ± 146 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint613641147134
domContentLoaded9167333718
load381453152305146
domInteractive9167333718
Bundle size diffs [🚨 Warning! Bundle size has increased!]
  • background: 0 Bytes (0.00%)
  • ui: 0 Bytes (0.00%)
  • common: 634 Bytes (0.01%)

@metamaskbot metamaskbot added release-12.2.0 Issue or pull request that will be included in release 12.2.0 and removed release-12.4.0 Issue or pull request that will be included in release 12.4.0 labels Aug 28, 2024
@metamaskbot
Copy link
Copy Markdown
Collaborator

Missing release label release-12.2.0 on PR. Adding release label release-12.2.0 on PR and removing other release labels(release-12.4.0), as PR was cherry-picked in branch 12.2.0.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

release-12.2.0 Issue or pull request that will be included in release 12.2.0 team-assets

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants