chore(deps): bump fast-uri from 3.1.3 to 3.1.7 in /app/migrator - #141
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.7. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.3...v3.1.7) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
roger-guifav
left a comment
There was a problem hiding this comment.
TL;DR
Bump de patch do fast-uri (transitivo do ajv) de 3.1.3 para 3.1.7 em app/migrator, fechando advisories públicos de segurança. Instalação local limpa e a CLI do prisma continua intacta, mas o documento de licenças precisa ser regenerado e a ordem de merge com o PR 134 importa: o 134 regrava o mesmo lockfile prendendo fast-uri em 3.1.5, abaixo do alvo. O CI não executou por bloqueio de billing da conta.
Verdict: Ajustes necessários
(revisado no head SHA d5ec5f2)
Parecer
Bump de segurança gerado por automação, cirúrgico: só a entrada do fast-uri no lockfile, sem mudança de manifesto — o ajv (dependência transitiva do prisma) declara faixa ^3.0.1, compatível. Fatos fora do diff: (1) o 3.1.7 é release de segurança da linha 3.x, merge com prioridade real; (2) o PR 134 regrava o lockfile deste mesmo diretório e prende fast-uri em 3.1.5 — se mergear depois deste sem rebase, regride a correção; (3) o CI não rodou por billing, validação local substitui nesta rodada. Pergunta de merge: mergearia logo após regenerar o documento de licenças, antes do 134.
Críticos (P0)
Nenhum.
Bloqueadores de correção (P1)
- Documento de licenças de terceiros fica desatualizado: docs/THIRD-PARTY-LICENSES.md fixa fast-uri 3.1.3 e este PR leva a 3.1.7 — a checagem de licenças do CI reprovará quando o billing for regularizado. Regenerar pelo script do repo e commitar neste PR.
Endereçar no PR (P2)
- Sequência de merge com o PR 134: os dois tocam o lockfile de app/migrator. Este sobe fast-uri para 3.1.7; o 134 prende 3.1.5. Fixar a ordem: mergear este primeiro e rebasear o 134 garantindo fast-uri em 3.1.7 ou superior no lock final.
Endereçar no PR (P3 / nits)
Nenhum.
Acoes que somente o humano pode fazer (ainda...)
- Regularizar o billing da conta no GitHub Actions e re-executar o CI deste PR: os quatro jobs não iniciaram por bloqueio de conta, sem relação com o código.
Verificado
- Head revisado: d5ec5f2 (merge-base igual ao main atual)
- Diff: somente lockfile, entrada fast-uri 3.1.3 para 3.1.7 (consumidor: ajv 8.20.0, transitivo do prisma)
- npm ci em app/migrator: limpo (95 pacotes)
- CLI prisma 7.8.0 inalterada e operante — bump exclusivo de lockfile, sem tocar o prisma
- Migrator não tem suite de testes nem typecheck próprio — limite declarado da validação local
- CI: indisponível nesta rodada por bloqueio de billing da conta — limite declarado; validação local executada no lugar
Roger (Hermes KVM) - review v2 - d5ec5f2
Bumps fast-uri from 3.1.3 to 3.1.7.
Release notes
Sourced from fast-uri's releases.
Commits
412e40aBumped v3.1.79f4c943fix: backport port and IP-literal validation to v3.x (#216)1eb3ce4fix: treat unterminated bracket hosts as reg-names again (#214)6f970b2Bumped v3.1.6d941579fix: never run IDN canonicalization on bracketed IP literalsc0f0279test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)37f3417Merge commit from fork607bfbeMerge commit from forkae92a4cMerge commit from fork444ecdaMerge commit from forkDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.