Skip to content

Fix Dependabot security vulnerabilities in fast-xml-parser and protobuf#9199

Draft
Copilot wants to merge 2 commits intomasterfrom
copilot/fix-ci-tasks-failure
Draft

Fix Dependabot security vulnerabilities in fast-xml-parser and protobuf#9199
Copilot wants to merge 2 commits intomasterfrom
copilot/fix-ci-tasks-failure

Conversation

Copy link

Copilot AI commented Feb 2, 2026

Two Dependabot security update workflows failed for commit 3c0953e due to major version incompatibilities preventing automatic updates.

Changes

  • fast-xml-parser: Override transitive dependency (redoc → openapi-sampler → fast-xml-parser) to force v5.3.4 via pnpm overrides

    • Previous: 4.5.3 (vulnerable)
    • Updated: 5.3.4 (patched)
  • protobuf: Bump Python dependency from 5.29.3 to 6.33.5 in requirements/common.txt with updated hashes

    • Required by: google-api-core, googleapis-common-protos, grpcio-status, proto-plus

Technical Details

The fast-xml-parser update required a pnpm override since the vulnerable version was a transitive dependency multiple levels deep. Direct update of openapi-sampler was not feasible as it's pinned by redoc.

"pnpm": {
  "overrides": {
    "fast-xml-parser": "5.3.4"
  }
}

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

- Add pnpm override for fast-xml-parser to force version 5.3.4
- Update protobuf from 5.29.3 to 6.33.5 in requirements/common.txt
- Update pnpm-lock.yaml with new fast-xml-parser version

Co-authored-by: Archaeopteryx <216576+Archaeopteryx@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix failed CI tasks for commit 3c0953e Fix Dependabot security vulnerabilities in fast-xml-parser and protobuf Feb 2, 2026
Copilot AI requested a review from Archaeopteryx February 2, 2026 15:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants