Skip to content

chore(deps): Bump transitive dep fast-xml-parser#19433

Open
Lms24 wants to merge 1 commit intodevelopfrom
lms/chore-deps-bump-fast-xml-parser
Open

chore(deps): Bump transitive dep fast-xml-parser#19433
Lms24 wants to merge 1 commit intodevelopfrom
lms/chore-deps-bump-fast-xml-parser

Conversation

@Lms24
Copy link
Member

@Lms24 Lms24 commented Feb 19, 2026

bumps fast-xml-parser to 5.3.6 which resolves https://github.com/getsentry/sentry-javascript/security/dependabot/1062 partially. The remaining case was usage of the dep in @langchain/anthropic@0.3.x which we only use in node integration tests. Given we intentionally test against 0.x, I dismissed the alert due to this case.

h/t @chargome for the /fix-security-vulnerability skill 🙏

ref @langchain/anthropic

Closes #19437 (added automatically)
Closes #19449

@github-actions
Copy link
Contributor

github-actions bot commented Feb 19, 2026

size-limit report 📦

Path Size % Change Change
@sentry/browser 25.61 kB - -
@sentry/browser - with treeshaking flags 24.12 kB - -
@sentry/browser (incl. Tracing) 42.42 kB - -
@sentry/browser (incl. Tracing, Profiling) 47.08 kB - -
@sentry/browser (incl. Tracing, Replay) 81.24 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 70.86 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 85.93 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 98.09 kB - -
@sentry/browser (incl. Feedback) 42.33 kB - -
@sentry/browser (incl. sendFeedback) 30.28 kB - -
@sentry/browser (incl. FeedbackAsync) 35.28 kB - -
@sentry/browser (incl. Metrics) 26.78 kB - -
@sentry/browser (incl. Logs) 26.92 kB - -
@sentry/browser (incl. Metrics & Logs) 27.6 kB - -
@sentry/react 27.37 kB - -
@sentry/react (incl. Tracing) 44.76 kB - -
@sentry/vue 30.06 kB - -
@sentry/vue (incl. Tracing) 44.26 kB - -
@sentry/svelte 25.64 kB - -
CDN Bundle 28.16 kB - -
CDN Bundle (incl. Tracing) 43.25 kB - -
CDN Bundle (incl. Logs, Metrics) 29 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 44.09 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 68.08 kB - -
CDN Bundle (incl. Tracing, Replay) 80.12 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 80.99 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 85.56 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 86.46 kB - -
CDN Bundle - uncompressed 82.33 kB - -
CDN Bundle (incl. Tracing) - uncompressed 128.05 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 85.17 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 130.88 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 208.83 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 244.93 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 247.75 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 257.73 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 260.54 kB - -
@sentry/nextjs (client) 47.17 kB - -
@sentry/sveltekit (client) 42.88 kB - -
@sentry/node-core 52.18 kB +0.02% +7 B 🔺
@sentry/node 166.54 kB +0.01% +7 B 🔺
@sentry/node - without tracing 93.97 kB +0.01% +9 B 🔺
@sentry/aws-serverless 109.47 kB +0.01% +7 B 🔺

View base workflow run

@github-actions
Copy link
Contributor

github-actions bot commented Feb 19, 2026

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 9,113 - 9,110 +0%
GET With Sentry 1,586 17% 1,694 -6%
GET With Sentry (error only) 6,052 66% 6,094 -1%
POST Baseline 1,196 - 1,195 +0%
POST With Sentry 573 48% 589 -3%
POST With Sentry (error only) 1,043 87% 1,065 -2%
MYSQL Baseline 3,206 - 3,339 -4%
MYSQL With Sentry 480 15% 470 +2%
MYSQL With Sentry (error only) 2,675 83% 2,710 -1%

View base workflow run

@Lms24 Lms24 marked this pull request as ready for review February 19, 2026 20:13
@Lms24 Lms24 self-assigned this Feb 19, 2026
@Lms24 Lms24 requested review from a team, chargome and s1gr1d and removed request for a team February 19, 2026 20:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fast-xml-parser vulnerabilities in getsentry/sentry-javascript chore(deps): Bump transitive dep fast-xml-parser

3 participants

Comments