Skip to content

Fix fast-xml-parser vulnerability#577

Open
waisingyiu wants to merge 2 commits intomainfrom
wsy/fix-fast-xml-parser-vulnerability
Open

Fix fast-xml-parser vulnerability#577
waisingyiu wants to merge 2 commits intomainfrom
wsy/fix-fast-xml-parser-vulnerability

Conversation

@waisingyiu
Copy link
Contributor

@waisingyiu waisingyiu commented Feb 12, 2026

What does this change?

Our dependency vulnerability dashboard raised a high-severity vulnerability in the fast-xml-parser which is being used by Typerighter.

This dependency is a transitive dependency from GuCDK in the cdk script.

The pull request bumps the GuCDK to the latest version (v62.3.2) which pulls a more recent version of faxt-xml-parser (v5.3.4) that fixes the vulnerability. It also bumps the node version above nodejs 18 as required by the new GuCDK.

How has this change been tested?

Deploy to CODE and run a smoke test, creating a new rule and running a checker in Composer.

How can we measure success?

Resolve the vulnerability on Typerighter in the dependency vulnerability dashboard.

Have we considered potential risks?

Low risk, as it affects the CDK and it passes the test without generating a new snapshot.

@waisingyiu waisingyiu added the maintenance Departmental tracking: maintenance work, not a fix or a feature label Feb 12, 2026
@github-actions
Copy link

github-actions bot commented Feb 12, 2026

@waisingyiu waisingyiu force-pushed the wsy/fix-fast-xml-parser-vulnerability branch from 3c0a4b9 to a89bf97 Compare February 12, 2026 14:06
@waisingyiu waisingyiu changed the title Move dependencies in cdk to devDependencies Fix fast-xml-parser vulnerability Feb 12, 2026
@waisingyiu waisingyiu force-pushed the wsy/fix-fast-xml-parser-vulnerability branch from a89bf97 to a162695 Compare February 12, 2026 14:13
@waisingyiu waisingyiu marked this pull request as ready for review February 12, 2026 15:26
@waisingyiu waisingyiu requested a review from a team as a code owner February 12, 2026 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance Departmental tracking: maintenance work, not a fix or a feature

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants