Skip to content

Security Patches & Dependency Updates

Latest

Choose a tag to compare

@RubenHalman RubenHalman released this 05 Apr 12:51
· 2 commits to main since this release
Immutable release. Only release title and notes can be modified.

Security Patch: fast-xml-parser

Action: action-v3.7.1 | Core: core-v6.19.2 | CLI: v6.19.3 | VSX: v3.4.1

Several dependencies were updated to resolve known vulnerabilities:

  • fast-xml-parser updated to resolve security advisories in the XML parsing layer
  • minimatch (Action) bumped from v9 to v10 — resolves a ReDoS vulnerability in older versions
  • lodash (VSX) removed — functionality replaced with native alternatives
  • rollup (VSX) updated from v4.34 to v4.59 — build tooling security improvements
  • Node.js engine support extended to include v24 in the regex-scanner package

Platform Changes

  • Copado Plugin — The Copado marketplace listing has been delisted by Copado. We hope to restore the integration in the future.
  • Open VSX — The Open VSX Registry listing has been deprecated due to maintenance overhead. You can still generate a .vsix directly from our repository and install it manually in any compatible editor.