Fix CI Snyk vulnerabilities in liquidjs and fast-xml-parser#3686
Draft
Fix CI Snyk vulnerabilities in liquidjs and fast-xml-parser#3686
Conversation
…l-parser resolution - Update liquidjs from ^10.8.4 to ^10.25.0 in packages/actions-shared - Update liquidjs from ^10.8.4 to ^10.25.0 in packages/destination-actions - Update liquidjs from ^10.21.0 to ^10.25.0 in root package.json - Add fast-xml-parser resolution to 5.5.9 for AWS SDK transitive dependency Fixes: - SNYK-JS-LIQUIDJS-15443434: Directory Traversal (High Severity) - SNYK-JS-FASTXMLPARSER-15307668: XML Entity Expansion (High Severity) - SNYK-JS-FASTXMLPARSER-15324289: Incorrect Regular Expression (High Severity) - SNYK-JS-FASTXMLPARSER-15677840: XML Entity Expansion (High Severity) - SNYK-JS-FASTXMLPARSER-15699647: Improper Validation (High Severity)
Copilot
AI
changed the title
[WIP] Fix CI Snyk issue
Fix CI Snyk vulnerabilities in liquidjs and fast-xml-parser
Mar 24, 2026
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3686 +/- ##
==========================================
+ Coverage 80.83% 80.89% +0.06%
==========================================
Files 1382 1639 +257
Lines 27543 31642 +4099
Branches 5883 6962 +1079
==========================================
+ Hits 22264 25598 +3334
- Misses 4342 5087 +745
- Partials 937 957 +20 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
mdkhan-tw
reviewed
Mar 24, 2026
Contributor
mdkhan-tw
left a comment
There was a problem hiding this comment.
Can we try exhaustive testing? We had a sev because of liquidjs parsing error
Contributor
Yes... This yet to be tested on staging... |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk CI check failing due to high-severity vulnerabilities in
liquidjs@10.12.0andfast-xml-parser@5.3.4.Changes
liquidjs: Bump from
^10.8.4to^10.25.0across all packagesfast-xml-parser: Add yarn resolution to force
5.5.9@aws-sdk/*All existing liquidjs tests pass.
Warning
Firewall rules blocked me from connecting to one or more addresses (expand for details)
I tried to connect to the following addresses, but was blocked by firewall rules:
formulae.brew.sh/bin/curl /bin/curl -q --fail --compressed --silent --speed-limit 100 --speed-time 5 --location --remote-time --output /home/REDACTED/.cache/Homebrew/api/formula.jws.json --user-agent Linuxbrew/5.1.1 (Linux; x86_64 Ubuntu 24.04.3 LTS) curl/8.5.0 REDACTED user.email l/config(dns block)/bin/curl /bin/curl -q --fail --compressed --silent --speed-limit 100 --speed-time 5 --location --remote-time --output /home/REDACTED/.cache/Homebrew/api/cask.jws.json --user-agent Linuxbrew/5.1.1 (Linux; x86_64 Ubuntu 24.04.3 LTS) curl/8.5.0 REDACTED user.email lude(dns block)/bin/curl /bin/curl -q --fail --compressed --silent --speed-limit 100 --speed-time 5 --location --remote-time --output /home/REDACTED/.cache/Homebrew/api/formula_tap_migrations.jws.json --user-agent Linuxbrew/5.1.1 (Linux; x86_64 Ubuntu 24.04.3 LTS) curl/8.5.0 REDACTED user.email lude(dns block)https://api.github.com/repos/Homebrew/brew/tags/bin/curl /bin/curl -q --silent --max-time 3 --location --no-remote-time --output /dev/null --write-out %{http_code} --dump-header /home/linuxbrew/.linuxbrew/Homebrew/.git/GITHUB_HEADERS --user-agent Linuxbrew/5.1.1 (Linux; x86_64 Ubuntu 24.04.3 LTS) curl/8.5.0 --header X-GitHub-Api-Version:2022-11-28 --header Accept: application/vnd.github+json --header(http block)If you need me to access, download, or install something from one of these locations, you can either:
⚡ Quickly spin up Copilot coding agent tasks from anywhere on your macOS or Windows machine with Raycast.