Repository navigation
chore(deps): bump fast-uri from 3.1.3 to 3.1.7 in /functions/generate-thumbnail - #140
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.7. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.3...v3.1.7) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
roger-guifav
left a comment
There was a problem hiding this comment.
TL;DR
Bump de patch do fast-uri (transitivo do ajv) de 3.1.3 para 3.1.7 em functions/generate-thumbnail, fechando advisories públicos de segurança. Build e testes locais passam, mas o documento de licenças precisa ser regenerado e a ordem de merge com o PR 136 importa: o 136 regrava o mesmo lockfile mantendo fast-uri em 3.1.3, o que desfaria esta correção. O CI não executou por bloqueio de billing da conta.
Verdict: Ajustes necessários
(revisado no head SHA e98dd07)
Parecer
Bump de segurança gerado por automação, cirúrgico: só a entrada do fast-uri no lockfile, sem mudança de manifesto — o ajv declara faixa ^3.0.1, compatível. Fatos fora do diff: (1) o 3.1.7 é release de segurança da linha 3.x, merge com prioridade real; (2) o PR 136 regrava o lockfile deste mesmo diretório e mantém fast-uri em 3.1.3 — se mergear depois deste sem rebase, regride a correção; (3) o CI não rodou por billing, validação local substitui nesta rodada. Validação local verde. Pergunta de merge: mergearia logo após regenerar o documento de licenças, antes do 136 (que, aliás, tem bloqueador próprio de puppeteer/chromium para resolver antes).
Críticos (P0)
Nenhum.
Bloqueadores de correção (P1)
- Documento de licenças de terceiros fica desatualizado: docs/THIRD-PARTY-LICENSES.md fixa fast-uri 3.1.3 e este PR leva a 3.1.7 — a checagem de licenças do CI reprovará quando o billing for regularizado. Regenerar pelo script do repo e commitar neste PR.
Endereçar no PR (P2)
- Sequência de merge com o PR 136: os dois tocam o lockfile de functions/generate-thumbnail. Este sobe fast-uri para 3.1.7; o 136 mantém 3.1.3. Fixar a ordem: mergear este primeiro e rebasear o 136 garantindo fast-uri em 3.1.7 ou superior no lock final.
Endereçar no PR (P3 / nits)
Nenhum.
Acoes que somente o humano pode fazer (ainda...)
- Regularizar o billing da conta no GitHub Actions e re-executar o CI deste PR: os quatro jobs não iniciaram por bloqueio de conta, sem relação com o código.
Verificado
- Head revisado: e98dd07 (merge-base igual ao main atual)
- Diff: somente lockfile, entrada fast-uri 3.1.3 para 3.1.7 (consumidor: ajv 8.20.0)
- npm ci em functions/generate-thumbnail: limpo (324 pacotes)
- npm run build (tsc): limpo
- npm test (observability): 2 passando, 0 falhas
- CI: indisponível nesta rodada por bloqueio de billing da conta — limite declarado; validação local executada no lugar
Roger (Hermes KVM) - review v2 - e98dd07
Bumps fast-uri from 3.1.3 to 3.1.7.
Release notes
Sourced from fast-uri's releases.
Commits
412e40aBumped v3.1.79f4c943fix: backport port and IP-literal validation to v3.x (#216)1eb3ce4fix: treat unterminated bracket hosts as reg-names again (#214)6f970b2Bumped v3.1.6d941579fix: never run IDN canonicalization on bracketed IP literalsc0f0279test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)37f3417Merge commit from fork607bfbeMerge commit from forkae92a4cMerge commit from fork444ecdaMerge commit from forkDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.