Update @expo/plist to suppress a warning?

#32 · open · 3 comments

View on GitHub ↗

mshibanami

Hi, This package currently relies on @expo/plist 0.0.x, which is quite outdated, as the latest version is 0.4.8. The problem is that @expo/plist 0.0.x depends on @xmldom/xmldom 0.7.x, which is no longer officially supported. When I install [my package](https://github.com/mshibanami/xcstrings-cli) that depends on `@bacons/xcode` using `npm install -g`, I receive the following warning: > npm WARN deprecated @xmldom/[email protected]: this version is no longer supported, please update to at least 0.8.* Would it be possible to update @expo/plist to the latest version, which uses xmldom 0.8.x? I quickly updated it and ran `yarn test` on my end, and no test cases failed, so the update might be straightforward. Lastly, thanks for maintaining this awesome project. I really appreciate your work. --- Edit (2026/05/23): As a temporary workaround, I created another npm package called [@mshibanami-org/xcode](https://www.npmjs.com/package/@mshibanami-org/xcode). The forked source code is here: https://github.com/mshibanami/xcode. Use it if you want.

Comments

klxiaoniu

https://github.com/advisories/GHSA-wh4c-j3r5-mjhp 0.7.x version of xmldom is vulnerable, which is used by this package currently

mshibanami

@EvanBacon ping, just in case you overlooked this issue.

shjd7

Any updates on this? Proposed bump: ```json "@expo/plist": "^0.8.1", "uuid": "^11.1.1" ```