Skip to content

Bump fast-xml-parser and generator-jhipster#1626

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-b5d9a45b6f
Open

Bump fast-xml-parser and generator-jhipster#1626
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-b5d9a45b6f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 30, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-xml-parser to 5.8.0 and updates ancestor dependency generator-jhipster. These dependencies need to be updated together.

Updates fast-xml-parser from 5.2.2 to 5.8.0

Release notes

Sourced from fast-xml-parser's releases.

update strnum, FXB. Use xml-naming for DOCTYPE

  • integrate xml-naming to validate DOCTYPE entity name and notation name (using qname because of backward compatibility)
    • This will consider xml-version as well. '1.0' is default
  • update strnum to 2.3.0
    • You can set octal and binary parsing which is by deault off
  • update fast-xml-builder to 1.2.0
    • can sanitize tag names if found invalid
    • fix format output

fix minor old bugs and update builder

  • fix: alwaysCreateTextNode should create text node when attributes are present for self closing node
  • fix stop node expression when ns prefix is removed (found by iruizsalinas)
  • update XML Builder to 1.1.7
  • mark addEntity deprecated

backward compatibility for numerical external entity, fix #705, #817

  • allow numerical external entity for backward compatibility
  • fix #705: attributesGroupName working with preserveOrder
  • fix #817: stackoverflow when tag expression is very long

upgrade @​nodable/entities and FXB

  • Use @nodable/entities v2.1.0
    • breaking changes
      • single entity scan. You're not allowed to use entity value to form another entity name.
      • you cant add numeric external entity
      • entity error message when expantion limit is crossed might change
    • typings are updated for new options related to process entity
    • please follow documentation of @nodable/entities for more detail.
    • performance
      • if processEntities is false, then there should not be impact on performance.
      • if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
      • if processEntities is true, and you pass entity decoder separately
        • if no entity then performance should be same as before
        • if there are entities then performance should be increased from past versions
    • ignoreAttributes is not required to be set to set xml version for NCR entity value
  • update 'fast-xml-builder' to sanitize malicious CDATA and comment's content

use @​nodable/entities to replace entities

  • No API change
  • No change in performance for basic usage
  • No typing change
  • No config change
  • new dependency
  • breaking: error messages for entities might have been changed.

Full Changelog: NaturalIntelligence/fast-xml-parser@v5.5.12...v5.6.0

performance improvment, increase entity expansion default limit

  • increase default entity explansion limit as many projects demand for that
</tr></table> 

... (truncated)

Changelog

Sourced from fast-xml-parser's changelog.

Note: If you find missing information about particular minor version, that version must have been changed without any functional change in this library.

Note: Due to some last quick changes on v4, detail of v4.5.3 & v4.5.4 are not updated here. v4.5.4x is the last tag of v4 in github repository. I'm extremely sorry for the confusion

*5.8.0 / 2026-05-12

  • integrate xml-naming to validate DOCTYPE entity name and notation name (using qname becaue of backward compatibility)
    • This will consider xml-version as well. '1.0' is default
  • update strnum to 2.3.0
    • You can set octal and binary parsing which is bydeault off
  • update fast-xml-builder to 1.2.0
    • can sanitize tag names if found invalid
    • fix format output

5.7.3 / 2006-05-05

  • fix: alwaysCreateTextNode should create text node when attributes are present for self closing node
  • fix stop node expression when ns prefix is removed (found by iruizsalinas)
  • update XML Builder to 1.1.7
  • mark addEntity deprecated

5.7.2 / 2026-04-25

  • allow numerical external entity for backward compatibility
  • fix #705: attributesGroupName working with preserveOrder
  • fix #817: stackoverflow when tag expression is very long

5.7.1 / 2026-04-20

  • fix typo in CJS typing file

5.7.0 / 2026-04-17

  • Use @nodable/entities v2.1.0
    • breaking changes
      • single entity scan. You're not allowed to user entity value to form another entity name.
      • you cant add numeric external entity
      • entity error message when expantion limit is crossed might change
    • typings are updated for new options related to process entity
    • please follow documentation of @nodable/entities for more detail.
    • performance
      • if processEntities is false, then there should not be impact on performance.
      • if processEntities is true, but you dont pass entity decoder separately then performance may degrade by approx 8-10%
      • if processEntities is true, and you pass entity decoder separately
        • if no entity then performance should be same as before
        • if there are entities then performance should be increased from past versions
    • ignoreAttributes is not required to be set to set xml version for NCR entity value
  • update 'fast-xml-builder' to sanitize malicious CDATA and comment's content

5.6.0 / 2026-04-15

  • fix: entity replacement for numeric entities
  • use @​nodable/entities to replace entities
    • this may change some error messages related to entities expansion limit or inavlid use
    • post check would be exposed in future version

... (truncated)

Commits

Updates generator-jhipster from 8.11.0 to 9.1.0

Release notes

Sourced from generator-jhipster's releases.

v9.1.0

What's changed

🌟 Highlights

🍃 Spring Boot and security

  • Spring Boot 4.0.6 (#33553) - latest Spring Boot version for generated applications
  • Configuration sanitization for hardening (#32708) - tighter handling of generated configuration
  • JWT credentials fix (#33479) - fixes SecurityUtils.getCurrentUserJWT for JWT credentials

🅰️ Angular

  • OnPush change detection everywhere (#33218) - all generated components now use ChangeDetectionStrategy.OnPush
  • Rewritten service worker provider (#33329) - cleaner service worker setup in generated apps
  • SSR-safe html lang updates (#33330) - uses inject(DOCUMENT) for server-safe language updates

⚛️ React

  • Jest to Vitest migration (#33200) - generated React apps now use Vitest
  • react-top-loading-bar (#33039) - replaces react-redux-loading-bar
  • User management reducer fix (#33555) - fixes errorMessage handling

🟩 Vue

  • @​module-federation/vite (#33283) - Vue microfrontends now use the Vite integration
  • rsbuild microfrontends by default (#33455) - rsbuild is now the default for generated Vue microfrontends
  • Gateway resources through module federation (#33485) - exposes and loads gateway resources through module federation
  • Stale auth token cleanup (#33503) - removes outdated authentication tokens from storage

🧩 Internal improvements

  • Improved TypeScript support (#33332, #33096) - each generator exports its own types, and new blueprints are generated in TypeScript
  • CI/CD generator split (#33398, #33388) - moves commands into ci-cd and ci-cd:common
  • Typed generator utilities (#33352, #33351, #33391) - more typed helpers and better writeFiles inference

🤖 AI and generator workflow

  • AGENTS.md and AI assistant disclosure policy (#33130) - documents expectations for AI-assisted contributions

📊 By the numbers

🔧 More changes

🔧 Core generator and templates

... (truncated)

Commits
  • 6b7444c Release v9.1.0
  • fa02b11 Prepare for next release
  • 3f176f5 Fix: Restore Infinispan caching in integration tests (#33571)
  • 0d5b8f6 apply adjusted eslint ejs (#33570)
  • 213c090 build(deps): bump com.gorylenko.gradle-git-properties (#33569)
  • 4c54354 build(deps-dev): bump cypress in /generators/cypress/resources (#33568)
  • 6aa382f build(deps): bump dayjs in /generators/client/resources (#33567)
  • 2bfc0bf use individual rules in eslint-disable and apply other rules (#33560)
  • 4bbeacc build(deps): bump io.gatling.highcharts:gatling-charts-highcharts (#33566)
  • 980d609 build(deps-dev): bump io.gatling:gatling-maven-plugin (#33565)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 30, 2026
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-b5d9a45b6f branch from 72f1aa5 to 895f5d8 Compare June 1, 2026 23:38
Bumps [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser) to 5.8.0 and updates ancestor dependency [generator-jhipster](https://github.com/jhipster/generator-jhipster). These dependencies need to be updated together.


Updates `fast-xml-parser` from 5.2.2 to 5.8.0
- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)
- [Changelog](https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/CHANGELOG.md)
- [Commits](NaturalIntelligence/fast-xml-parser@v5.2.2...v5.8.0)

Updates `generator-jhipster` from 8.11.0 to 9.1.0
- [Release notes](https://github.com/jhipster/generator-jhipster/releases)
- [Commits](jhipster/generator-jhipster@v8.11.0...v9.1.0)

---
updated-dependencies:
- dependency-name: fast-xml-parser
  dependency-version: 5.8.0
  dependency-type: indirect
- dependency-name: generator-jhipster
  dependency-version: 9.1.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/multi-b5d9a45b6f branch from 895f5d8 to a38e589 Compare June 6, 2026 04:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants