Thanks to visit codestin.com
Credit goes to github.com

Skip to content

[Security] now published as @xmldom/xmldom #271

@karfau

Description

@karfau

&TLDR;

We published 0.7.0 to npm as @xmldom/xmldom and will continue to publish updates there.
To get the security update, you have to switch the package you use in your package.json.

"quick post-mortem" by @brodybits

Types from DefinitelyTyped are now included as of @xmldom/xmldom version 0.7.1.

Here are some stats regarding packages transitioning from one package to the other:


Image Historical daily/weekly downloads

We are currently not aware of a badge that gives accurate numbers for dependents, data is form the 2025-02-13.
according to npm:

  • @xmldom/xmldom: 766
  • xmldom: 2412
    according to Github:
  • Image

Original Summary

To update the library to the newest version including the latest security fix you will have to install to from the github repo or download the artifact from the github release and install it locally.

For details of how to do that and asking questions please use the related discussion

We have filed a ticket at the npm support team addressing the issue.

We will Post updates about the current status here but lock this issue to only allow additions by maintainers, to allow people to subscribe and get informed when something changes.


Quick background from @brodybits

Metadata

Metadata

Labels

SecuritybugSomething isn't workingdocumentationImprovements or additions to documentation

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions