Skip to content

fix(deps): remove vulnerable transitive XML parser - #35

Draft
anandpant wants to merge 1 commit into
mainfrom
fix/security-xml-parser-2026-10-07
Draft

anandpant wants to merge 1 commit into
mainfrom
fix/security-xml-parser-2026-10-07

Conversation

@anandpant

@anandpant anandpant commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Refresh @aws-sdk/xml-builder from 3.972.5 to 3.972.41 within the existing AWS SDK dependency range.
  • The updated parent no longer depends on fast-xml-parser, removing vulnerable 5.3.6 and its unused strnum dependency without forcing an incompatible parser override.
  • Regenerate bun.lock with a targeted package-manager update; application dependencies and APIs are unchanged.

Security

Remediates the recorded parser dependency exposure: GHSA-8gc5-j5rx-235r and GHSA-8r6m-32jq-jx6q. No claim of observed exploitation.

Validation

  • Passed: bun update @aws-sdk/xml-builder --lockfile-only --ignore-scripts (Bun 1.4.2).
  • Passed: git diff --check; reviewed all parent ranges and confirmed no remaining fast-xml-parser entries in the resulting lockfile.
  • Passed with pinned Bun 1.3.10: bun install --frozen-lockfile --ignore-scripts, bun run typecheck, bun test, bun run build, and bun run check.
  • GitHub checks are running for exact head f6d1c67463b1d5828a2ced3729f8bfaedc697e7c; Socket checks passed.
  • Live Daytona integration requires the project's configured credentials and has not been run locally.

This is intentionally a draft pending CI and review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant