Take fast-uri and js-yaml security patches (lockfile only) - #186
Merged
Merged
Conversation
bazauto
enabled auto-merge (squash)
September 9, 2026 17:30
bazauto
force-pushed
the
deps/fast-uri-js-yaml-advisories
branch
from
September 9, 2026 17:53
ce7289c to
39ecab6
Compare
Closes all eight open high-severity Dependabot alerts. Every one was fast-uri, on two version lines at once: 3.1.5 -> 3.1.7 and 4.1.2 -> 4.1.4, both transitive under Fastify (@fastify/ajv-compiler -> ajv, and fast-json-stringify). The same plain `npm audit fix` took js-yaml 4.3.1 -> 4.3.2, a high that npm audit reports and Dependabot had not raised, dev-only under eslint -> @eslint/eslintrc. package-lock.json is the only file that moves. No package.json changed, no direct dependency changed, and no --force was involved. Docs: the Repo notes section in docs/current-state.md said the only remaining --force suggestion was the drizzle-kit downgrade and that four residual moderate advisories were one chain. There are now two chains and seven advisories -- vitest@5 has joined it -- so both that section and the CLAUDE.md rule it backs are rewritten to match. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependabot had eight open alerts, all high, and all of them the same package:
fast-uri,caught on two version lines at once. Four advisories against the 3.x line installed here and
four against a 4.x copy deeper in the tree — SSRF via malformed IPv6 normalization and via
repeated hostname percent-decoding, and host confusion via percent-encoded scheme
normalization and skipped IDN canonicalization.
Both lines are transitive under Fastify:
@fastify/ajv-compiler→ajv→fast-urifor the3.x copy,
fast-json-stringify→fast-urifor the 4.x one. Nothing in this stack parses anattacker-supplied URI —
fast-uriis there to resolve JSON Schema$refs at route-compiletime, against schemas we wrote — so the exposure argument is weak in both directions. It did
not have to be settled: the fix is a patch bump on each line, which is cheaper than reasoning
about reachability.
Plain
npm audit fixdid the whole thing.package-lock.jsonis the only file that moves:fast-uri3.1.5 → 3.1.7 (advisories fixed in 3.1.6)fast-uri4.1.2 → 4.1.4 (fixed in 4.1.3)js-yaml4.3.1 → 4.3.2The
js-yamlbump came along in the same run. It is a high thatnpm auditreports andDependabot had not raised, and it is dev-only —
eslint→@eslint/eslintrc.No
package.jsonchanged, no direct dependency changed, andnpm audit fix --forcewas notinvolved.
npm auditnow reports zero high-severity advisories.What is deliberately not fixed
Seven moderate advisories remain, and both chains behind them need a breaking change:
drizzle-kit@0.18.1— the existing banned case, four advisories on one unreachable@esbuild-kit→esbuild@0.18.20chain. Still a major downgrade of the tool thatgenerates migrations against the live database.
vitest@5— new since the ban was written. GHSA-82fw-gwwq-j7x9, a path traversal in@vitest/mocker, with no fix on the 3.x line both workspaces declare. Reachable onlyagainst a running Vitest server on a developer's machine. A major-version migration of the
suite that guards a control system is worth doing on its own branch, deliberately, and not
as a side effect of an audit.
Docs
docs/current-state.md§Repo notes said the only remaining--forcesuggestion was thedrizzle-kit downgrade, and that "the four residual moderate advisories" were one chain. Both
halves are now false — there are two chains and seven advisories. That section is rewritten to
cover both, with the reachability argument for each, and the
CLAUDE.mdrule it backs isupdated to match.
Verification
Run on this branch, from the repo root:
Both workspace builds were run because there is no root
buildscript and CI is not the onlything that has to survive this — the bench box builds on the box at deploy time.
🤖 Generated with Claude Code
https://claude.ai/code/session_01SQMPj8UFbx1AwH3QgttGRV