dependabot[bot] opened a new pull request, #1655:
URL: https://github.com/apache/daffodil-vscode/pull/1655

   Bumps 
[fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) from 
5.5.6 to 5.5.9.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/releases";>fast-xml-parser's
 releases</a>.</em></p>
   <blockquote>
   <h2>fix typins and matcher instance in callbacks</h2>
   <p>combine typings file to avoid configuration changes
   pass readonly instance of matcher to the call backs to avoid accidental 
push/pop call</p>
   <h2>fix bugs of entity parsing and value parsing</h2>
   <p>fix: entity expansion limits
   update strnum package to 2.2.0</p>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md";>fast-xml-parser's
 changelog</a>.</em></p>
   <blockquote>
   <p><!-- raw HTML omitted -->Note: If you find missing information about 
particular minor version, that version must have been changed without any 
functional change in this library.<!-- raw HTML omitted --></p>
   <p>Note: Due to some last quick changes on v4, detail of v4.5.3 &amp; v4.5.4 
are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm 
extremely sorry for the confusion</p>
   <p><strong>5.5.9 / 2026-03-23</strong></p>
   <ul>
   <li>combine typing files</li>
   </ul>
   <p><strong>4.5.5 / 2026-03-22</strong></p>
   <p>apply fixes from v5 (legacy maintenance branch v4-maintenance)</p>
   <ul>
   <li>support maxEntityCount</li>
   <li>support onDangerousProperty</li>
   <li>support maxNestedTags</li>
   <li>handle prototype pollution</li>
   <li>fix incorrect entity name replacement</li>
   <li>fix incorrect condition for entity expansion</li>
   </ul>
   <p><strong>5.5.8 / 2026-03-20</strong></p>
   <ul>
   <li>pass read only matcher in callback</li>
   </ul>
   <p><strong>5.5.7 / 2026-03-19</strong></p>
   <ul>
   <li>fix: entity expansion limits</li>
   <li>update strnum package to 2.2.0</li>
   </ul>
   <p><strong>5.5.6 / 2026-03-16</strong></p>
   <ul>
   <li>update builder dependency</li>
   <li>fix incorrect regex to replace . in entity name</li>
   <li>fix check for entitiy expansion for lastEntities and html entities 
too</li>
   </ul>
   <p><strong>5.5.5 / 2026-03-13</strong></p>
   <ul>
   <li>sanitize dangerous tag or attribute name</li>
   <li>error on critical property name</li>
   <li>support onDangerousProperty option</li>
   </ul>
   <p><strong>5.5.4 / 2026-03-13</strong></p>
   <ul>
   <li>declare Matcher &amp; Expression as unknown so user is not forced to 
install path-expression-matcher</li>
   </ul>
   <p><strong>5.5.3 / 2026-03-11</strong></p>
   <ul>
   <li>upgrade builder</li>
   </ul>
   <p><strong>5.5.2 / 2026-03-11</strong></p>
   <ul>
   <li>update dependency to fix typings</li>
   </ul>
   <p><strong>5.5.1 / 2026-03-10</strong></p>
   <ul>
   <li>fix dependency</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/a8934f903054c582b8ae6a12937fd4b22c380613";><code>a8934f9</code></a>
 upgrade strnum</li>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/23d13e40c35386069eec8e28c8bfdaabc3962680";><code>23d13e4</code></a>
 combine typing files</li>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/0c0a7dc500983c549c2b1c9e1987dfabc69eddda";><code>0c0a7dc</code></a>
 update maintenance docs</li>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/a92a665e00c146a4ea3ff7760f3399e5ed51dfc5";><code>a92a665</code></a>
 pass read only matcher in call back</li>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/a21c44123cdf0f8fb5b56d33386ed3be4e180953";><code>a21c441</code></a>
 update package detail</li>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/239b64aa1fc5c5455ddebbbb54a187eb68c9fdb7";><code>239b64a</code></a>
 check for min value for entity exapantion options</li>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/61cb666d13044b483aa495a6c020789f22e670b4";><code>61cb666</code></a>
 restrict more properties to be unsafe</li>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/41abd66adc54cbc6ebea615a9f5396d8582afdb1";><code>41abd66</code></a>
 performance improvement of reading DOCTYPE</li>
   <li><a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/commit/3dfcd20c8cffc310335510ff72a211be0672a8dd";><code>3dfcd20</code></a>
 refactor: performance improvement</li>
   <li>See full diff in <a 
href="https://github.com/NaturalIntelligence/fast-xml-parser/compare/v5.5.6...v5.5.9";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=fast-xml-parser&package-manager=npm_and_yarn&previous-version=5.5.6&new-version=5.5.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to