Skip to content

Security vulnerability in pinned dependency fast-xml-parser #2302

Description

@trygve-aaberge-adsk

Bug description

The latest version of @datadog/datadog-ci-base depends on the specific version [email protected]. This version of the package has reported security issues: GHSA-gh4j-gqv2-49f6

Could you upgrade the dependency?

It looks like this has been an issue several times before (#914, #1414, #2077). Is there a reason it needs to be pinned to a specific version and not use a ^?

Describe what you expected

No response

Steps to reproduce the issue

No response

Additional context

No response

Command

None

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Fields

No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions