Skip to content

chore(deps): bump fast-uri from 3.1.2 to 3.1.5 - #58

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.4
Closed

chore(deps): bump fast-uri from 3.1.2 to 3.1.5#58
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.1.2 to 3.1.5.

Release notes

Sourced from fast-uri's releases.

v3.1.5

⚠️ Security Warning

Fix for GHSA-7p8r-x3mc-p8w7

Full Changelog: fastify/fast-uri@v3.1.4...v3.1.5

v3.1.4

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v3.1.3...v3.1.4

v3.1.3

⚠️ Security Release

Full Changelog: fastify/fast-uri@v3.1.2...v3.1.3

Commits

@dependabot @github

dependabot Bot commented on behalf of github Jul 22, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@changeset-bot

changeset-bot Bot commented Jul 22, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 8c4fdf6

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

cursor[bot]
cursor Bot previously approved these changes Jul 22, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: low. Cursor Bugbot was not present on this PR, so approval follows policy and change scope. This is a narrow Dependabot patch bump of fast-uri in package-lock.json only; approved with no reviewers assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@yakimoto

Copy link
Copy Markdown
Contributor

Verified locally. CI can't run — Actions are refusing every job org-wide on an account-level billing lock (plan=free, locked=yes, confirmed live this morning on adk and dispatch-edge) — so this stands in for the checks until it clears.

npm ci (NODE_ENV=development)  → OK
npm run build                  → ESM ⚡️ Build success
npm run type-check             → tsc --noEmit, clean

Advisory delta, dev scope included, against main @ a199245:

total high mod low
main 7 3 2 2
this PR 6 2 2 2

fast-uri drops out of the audit entirely, clearing both of the repo's fast-uri alerts (>= 3.0.0, <= 3.1.3 and >= 3.0.0, < 3.1.3, both high) — 3.1.4 covers each range.

Same bump, same version, verified independently on wave-av/sdks in wave-av/sdks#48, where it was one of three that took that repo from 15 open alerts to 5.

Caveat for anyone re-checking these numbers: npm audit here inherits omit=dev from NODE_ENV=production and silently reports 5 instead of 7, hiding the dev-scope entries. Set NODE_ENV=development explicitly.

No objection from me — ready the moment CI is available. Merges stay on hold until branch protection is verified back, not merely reported mergeable: during this outage PRs went MERGEABLE because protection vanished, which reads exactly like CI recovering.

@dependabot dependabot Bot changed the title chore(deps): bump fast-uri from 3.1.2 to 3.1.4 chore(deps): bump fast-uri from 3.1.2 to 3.1.5 Aug 1, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-uri-3.1.4 branch 2 times, most recently from b10efd0 to 7498cac Compare August 1, 2026 23:13
@greptile-apps

greptile-apps Bot commented Aug 1, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Open in Devin Review

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.2...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-uri-3.1.4 branch from 7498cac to 8c4fdf6 Compare August 2, 2026 02:27
@dependabot @github

dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #85.

@dependabot dependabot Bot closed this Aug 5, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/fast-uri-3.1.4 branch August 5, 2026 20:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant