Skip to content

chore(deps): bump fast-xml-parser, @aws-sdk/client-s3, @aws-sdk/s3-request-presigner and @google-cloud/storage#29

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/multi-69faa4e1a6
Closed

chore(deps): bump fast-xml-parser, @aws-sdk/client-s3, @aws-sdk/s3-request-presigner and @google-cloud/storage#29
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/multi-69faa4e1a6

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 18, 2026

Bumps fast-xml-parser, @aws-sdk/client-s3, @aws-sdk/s3-request-presigner and @google-cloud/storage. These dependencies needed to be updated together.
Updates fast-xml-parser from 4.4.1 to 5.3.6

Release notes

Sourced from fast-xml-parser's releases.

Entity security and performance

  • Improve security and performance of entity processing
    • new options maxEntitySize, maxExpansionDepth, maxTotalExpansions, maxExpandedLength, allowedTags,tagFilter
    • fast return when no edtity is present
    • improvement replacement logic to reduce number of calls

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.3.5...v5.3.6

v5.3.5

What's Changed

New Contributors

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.3.4...v5.3.5

fix: handle HTML numeric and hex entities when out of range

No release notes provided.

bug fix and performance improvements

  • fix #775: transformTagName with allowBooleanAttributes adds an unnecessary attribute
  • Performance improvement for stopNodes (By Maciek Lamberski)

Replace Buffer with Uint8Array

  • Launched Separate CLI module
  • Replace Buffer with Uint8Array

Support EMPTY and ANY with ELEMENT in DOCTYPE

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.2.4...v5.2.4

upgrade to ESM module and fixing value parsing issues

  • Support ESM modules
  • fix value parsing issues
  • a feature to access tag location is added (metadata)
  • fix to read DOCTYPE correctly

Full Changelog: https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md

Summary update on all the previous releases from v4.2.4

  • Multiple minor fixes provided in the validator and parser
  • v6 is added for experimental use.
  • ignoreAttributes support function, and array of string or regex
  • Add support for parsing HTML numeric entities
  • v5 of the application is ESM module now. However, JS is also supported

... (truncated)

Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

5.3.6 / 2026-02-14

  • Improve security and performance of entity processing
    • new options maxEntitySize, maxExpansionDepth, maxTotalExpansions, maxExpandedLength, allowedTags,tagFilter
    • fast return when no edtity is present
    • improvement replacement logic to reduce number of calls

5.3.5 / 2026-02-08

  • fix: Escape regex char in entity name
  • update strnum to 2.1.2
  • add missing exports in CJS typings

5.3.4 / 2026-01-30

  • fix: handle HTML numeric and hex entities when out of range

5.3.3 / 2025-12-12

  • fix #775: transformTagName with allowBooleanAttributes adds an unnecessary attribute

5.3.2 / 2025-11-14

  • fix for import statement for v6

5.3.1 / 2025-11-03

5.3.0 / 2025-10-03

  • Use Uint8Array in place of Buffer in Parser

5.2.5 / 2025-06-08

  • Inform user to use fxp-cli instead of in-built CLI feature
  • Export typings for direct use

5.2.4 / 2025-06-06

  • fix (#747): fix EMPTY and ANY with ELEMENT in DOCTYPE

5.2.3 / 2025-05-11

  • fix (#747): support EMPTY and ANY with ELEMENT in DOCTYPE

5.2.2 / 2025-05-05

  • fix (#746): update strnum to fix parsing issues related to enotations

5.2.1 / 2025-04-22

  • fix: read DOCTYPE entity value correctly
  • read DOCTYPE NOTATION, ELEMENT exp but not using read values

5.2.0 / 2025-04-03

... (truncated)

Commits

Updates @aws-sdk/client-s3 from 3.717.0 to 3.992.0

Release notes

Sourced from @​aws-sdk/client-s3's releases.

v3.992.0

3.992.0(2026-02-17)

New Features
  • clients: update client endpoints as of 2026-02-17 (72c78059)
  • client-ec2: Add Operator field to CreatePlacementGroup and DescribePlacementGroup APIs. (ccdf06ad)
  • client-rds: Adds support for the StorageEncryptionType field to specify encryption type for DB clusters, DB instances, snapshots, automated backups, and global clusters. (976ce193)
  • client-grafana: This release updates Amazon Managed Grafana's APIs to support customer managed KMS keys. (276a337c)
  • client-workspaces-web: Adds support for branding customization without requiring a custom wallpaper. (dce78467)

For list of updated packages, view updated-packages.md in assets-3.992.0.zip

v3.991.0

3.991.0(2026-02-16)

Documentation Changes
  • client-arc-region-switch: Clarify documentation on ARC Region Switch start-plan-execution operation (c24d7a88)
  • client-ecr: Adds support for enabling blob mounting, and removes support for Clair based image scanning (e3cf5218)
  • client-ec2: Documentation updates for EC2 Secondary Networks (68029df3)
New Features
  • clients: update client endpoints as of 2026-02-16 (c3afa911)
  • client-qconnect: Update MessageType enum to include missing types. (9aaf67f2)
  • client-kms: Added support for Decrypt and ReEncrypt API's to use dry run feature without ciphertext for authorization validation (492b2819)
  • client-kafka: Amazon MSK now supports dual-stack connectivity (IPv4 and IPv6) for existing MSK clusters. You can enable dual-stack on existing clusters by specifying the NetworkType parameter in updateConnectivity API. (67a33d9a)

For list of updated packages, view updated-packages.md in assets-3.991.0.zip

v3.990.0

3.990.0(2026-02-13)

New Features
  • client-inspector2: Added .Net 10 (dotnet10) and Node 24.x (node24.x) runtime support for lambda package scanning (168caeb6)
  • client-sagemaker: Enable g7e instance type support for SageMaker Processing, and enable single file configuration provisioning for HyperPod Slurm, where customers have the option to use HyperPod API to provide the provisioning parameters. (6f77d876)
  • client-ec2: This release adds geography information to EC2 region and availability zone APIs. DescribeRegions now includes a Geography field, while DescribeAvailabilityZones includes both Geography and SubGeography fields, enabling better geographic classification for AWS regions and zones. (eed96c05)
  • client-cloudwatch: Adding new evaluation states that provides information about the alarm evaluation process. Evaluation error Indicates configuration errors in alarm setup that require review and correction. Evaluation failure Indicates temporary CloudWatch issues. (5a085a8a)
  • client-connect: API release for headerr notifications in the admin website. APIs allow customers to publish brief messages (including URLs) to a specified audience, and a new header icon will indicate when unread messages are available. (11a9568e)
Tests

... (truncated)

Changelog

Sourced from @​aws-sdk/client-s3's changelog.

3.992.0 (2026-02-17)

Note: Version bump only for package @​aws-sdk/client-s3

3.991.0 (2026-02-16)

Note: Version bump only for package @​aws-sdk/client-s3

3.990.0 (2026-02-13)

Note: Version bump only for package @​aws-sdk/client-s3

3.989.0 (2026-02-12)

Note: Version bump only for package @​aws-sdk/client-s3

3.988.0 (2026-02-11)

Note: Version bump only for package @​aws-sdk/client-s3

3.987.0 (2026-02-10)

Note: Version bump only for package @​aws-sdk/client-s3

3.986.0 (2026-02-09)

... (truncated)

Commits

Updates @aws-sdk/s3-request-presigner from 3.717.0 to 3.992.0

Release notes

Sourced from @​aws-sdk/s3-request-presigner's releases.

v3.992.0

3.992.0(2026-02-17)

New Features
  • clients: update client endpoints as of 2026-02-17 (72c78059)
  • client-ec2: Add Operator field to CreatePlacementGroup and DescribePlacementGroup APIs. (ccdf06ad)
  • client-rds: Adds support for the StorageEncryptionType field to specify encryption type for DB clusters, DB instances, snapshots, automated backups, and global clusters. (976ce193)
  • client-grafana: This release updates Amazon Managed Grafana's APIs to support customer managed KMS keys. (276a337c)
  • client-workspaces-web: Adds support for branding customization without requiring a custom wallpaper. (dce78467)

For list of updated packages, view updated-packages.md in assets-3.992.0.zip

v3.991.0

3.991.0(2026-02-16)

Documentation Changes
  • client-arc-region-switch: Clarify documentation on ARC Region Switch start-plan-execution operation (c24d7a88)
  • client-ecr: Adds support for enabling blob mounting, and removes support for Clair based image scanning (e3cf5218)
  • client-ec2: Documentation updates for EC2 Secondary Networks (68029df3)
New Features
  • clients: update client endpoints as of 2026-02-16 (c3afa911)
  • client-qconnect: Update MessageType enum to include missing types. (9aaf67f2)
  • client-kms: Added support for Decrypt and ReEncrypt API's to use dry run feature without ciphertext for authorization validation (492b2819)
  • client-kafka: Amazon MSK now supports dual-stack connectivity (IPv4 and IPv6) for existing MSK clusters. You can enable dual-stack on existing clusters by specifying the NetworkType parameter in updateConnectivity API. (67a33d9a)

For list of updated packages, view updated-packages.md in assets-3.991.0.zip

v3.990.0

3.990.0(2026-02-13)

New Features
  • client-inspector2: Added .Net 10 (dotnet10) and Node 24.x (node24.x) runtime support for lambda package scanning (168caeb6)
  • client-sagemaker: Enable g7e instance type support for SageMaker Processing, and enable single file configuration provisioning for HyperPod Slurm, where customers have the option to use HyperPod API to provide the provisioning parameters. (6f77d876)
  • client-ec2: This release adds geography information to EC2 region and availability zone APIs. DescribeRegions now includes a Geography field, while DescribeAvailabilityZones includes both Geography and SubGeography fields, enabling better geographic classification for AWS regions and zones. (eed96c05)
  • client-cloudwatch: Adding new evaluation states that provides information about the alarm evaluation process. Evaluation error Indicates configuration errors in alarm setup that require review and correction. Evaluation failure Indicates temporary CloudWatch issues. (5a085a8a)
  • client-connect: API release for headerr notifications in the admin website. APIs allow customers to publish brief messages (including URLs) to a specified audience, and a new header icon will indicate when unread messages are available. (11a9568e)
Tests

... (truncated)

Changelog

Sourced from @​aws-sdk/s3-request-presigner's changelog.

3.992.0 (2026-02-17)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.991.0 (2026-02-16)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.990.0 (2026-02-13)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.989.0 (2026-02-12)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.988.0 (2026-02-11)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.987.0 (2026-02-10)

Note: Version bump only for package @​aws-sdk/s3-request-presigner

3.986.0 (2026-02-09)

... (truncated)

Commits

Updates @google-cloud/storage from 7.14.0 to 7.19.0

Release notes

Sourced from @​google-cloud/storage's releases.

v7.19.0

7.19.0 (2026-02-05)

Features

  • Enable full object checksum validation on JSON path (#2687) (08a8962)

Bug Fixes

  • deps: Update dependency fast-xml-parser to v5 [security] (#2713) (420935a)

v7.18.0

7.18.0 (2025-11-28)

Features

  • listBuckets: Add support for returning partial success (#2678) (c7004da)

v7.17.3

7.17.3 (2025-11-03)

Bug Fixes

  • 🐛 fix the issue 2667, do not mutate object given to options … (#2668) (8a9f259)
  • Revert implement path containment to prevent traversal attacks (254b6b2)

v7.17.2

7.17.2 (2025-10-06)

Bug Fixes

  • Common Service: should retry a request failed (#2652) (b38b5d2)
  • Implement path containment to prevent traversal attacks (#2654) (08d7abf)

v7.17.1

7.17.1 (2025-08-27)

Bug Fixes

  • Respect useAuthWithCustomEndpoint flag for resumable uploads (#2637) (707b4f2)

v7.17.0

7.17.0 (2025-08-18)

... (truncated)

Changelog

Sourced from @​google-cloud/storage's changelog.

7.19.0 (2026-02-05)

Features

  • Enable full object checksum validation on JSON path (#2687) (08a8962)

Bug Fixes

  • deps: Update dependency fast-xml-parser to v5 [security] (#2713) (420935a)

7.18.0 (2025-11-28)

Features

  • listBuckets: Add support for returning partial success (#2678) (c7004da)

7.17.3 (2025-11-03)

Bug Fixes

  • 🐛 fix the issue 2667, do not mutate object given to options … (#2668) (8a9f259)
  • Revert implement path containment to prevent traversal attacks (254b6b2)

7.17.2 (2025-10-06)

Bug Fixes

  • Common Service: should retry a request failed (#2652) (b38b5d2)
  • Implement path containment to prevent traversal attacks (#2654) (08d7abf)

7.17.1 (2025-08-27)

Bug Fixes

  • Respect useAuthWithCustomEndpoint flag for resumable uploads (#2637) (707b4f2)

7.17.0 (2025-08-18)

Features

... (truncated)

Commits
  • 95a2af4 chore(main): release 7.19.0 (#2694)
  • 420935a fix(deps): update dependency fast-xml-parser to v5 [security] (#2713)
  • 4e3c328 test: skip system tests requiring public access (#2717)
  • 3052265 chore: fix lint failures (#2685)
  • 08a8962 feat: Enable full object checksum validation on JSON path (#2687)
  • 3dcda1b chore: lint failures (#2681)
  • 3e5210f chore(main): release 7.18.0 (#2684)
  • c7004da feat(listBuckets): Add support for returning partial success (#2678)
  • 633a13a chore(python): remove configure_previous_major_version_branches (#2675)
  • bae7040 samples: Add Soft Delete policy and object management samples (#2676)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

…quest-presigner and @google-cloud/storage

Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser), [@aws-sdk/client-s3](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/clients/client-s3), [@aws-sdk/s3-request-presigner](https://github.com/aws/aws-sdk-js-v3/tree/HEAD/packages/s3-request-presigner) and [@google-cloud/storage](https://github.com/googleapis/nodejs-storage). These dependencies needed to be updated together.

Updates `fast-xml-parser` from 4.4.1 to 5.3.6
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v4.4.1...v5.3.6)

Updates `@aws-sdk/client-s3` from 3.717.0 to 3.992.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/clients/client-s3/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.992.0/clients/client-s3)

Updates `@aws-sdk/s3-request-presigner` from 3.717.0 to 3.992.0
- [Release notes](https://github.com/aws/aws-sdk-js-v3/releases)
- [Changelog](https://github.com/aws/aws-sdk-js-v3/blob/main/packages/s3-request-presigner/CHANGELOG.md)
- [Commits](https://github.com/aws/aws-sdk-js-v3/commits/v3.992.0/packages/s3-request-presigner)

Updates `@google-cloud/storage` from 7.14.0 to 7.19.0
- [Release notes](https://github.com/googleapis/nodejs-storage/releases)
- [Changelog](https://github.com/googleapis/nodejs-storage/blob/main/CHANGELOG.md)
- [Commits](googleapis/nodejs-storage@v7.14.0...v7.19.0)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.3.6
  dependency-type: indirect
- dependency-name: "@aws-sdk/client-s3"
  dependency-version: 3.992.0
  dependency-type: indirect
- dependency-name: "@aws-sdk/s3-request-presigner"
  dependency-version: 3.992.0
  dependency-type: indirect
- dependency-name: "@google-cloud/storage"
  dependency-version: 7.19.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 18, 2026
@vercel
Copy link
Contributor

vercel bot commented Feb 18, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
notescape-2.0 Ready Ready Preview, Comment Feb 18, 2026 3:04am

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Feb 28, 2026

Superseded by #35.

@dependabot dependabot bot closed this Feb 28, 2026
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/multi-69faa4e1a6 branch February 28, 2026 18:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants