Skip to content

Comments

fix(deps): update fast-xml-parser to 5.3.6#1656

Merged
jennifer-shehane merged 1 commit intocypress-io:masterfrom
MikeMcC399:update/fast-xml-parser
Feb 18, 2026
Merged

fix(deps): update fast-xml-parser to 5.3.6#1656
jennifer-shehane merged 1 commit intocypress-io:masterfrom
MikeMcC399:update/fast-xml-parser

Conversation

@MikeMcC399
Copy link
Collaborator

Situation

npm audit and Dependabot report a high severity vulnerability CVE-2026-26278 (GHSA-jmr7-xgp7-cmfj) in the transient dependency [email protected] of @actions/[email protected]

Change

Update to [email protected] by uninstalling @actions/cache and reinstalling @actions/[email protected]

Verification

git clean -xfd
npm ci
npm audit --omit=dev

Confirm there are no production severities reported.

  • Note: devDependencies currently contain a vulnerability from ajv as a transient dependency of eslint. This is a known open issue requiring action in the eslint repo.

@MikeMcC399 MikeMcC399 added bug Something isn't working type: dependencies labels Feb 18, 2026
@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 self-assigned this Feb 18, 2026
@MikeMcC399 MikeMcC399 marked this pull request as ready for review February 18, 2026 09:07
@jennifer-shehane jennifer-shehane merged commit e44ee0f into cypress-io:master Feb 18, 2026
86 checks passed
@github-actions
Copy link

🎉 This PR is included in version 7.1.3 🎉

The release is available on:

Your semantic-release bot 📦🚀

@MikeMcC399 MikeMcC399 deleted the update/fast-xml-parser branch February 18, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants