Skip to content

Bump fast-uri from 3.0.3 to 3.1.5 - #6132

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/fast-uri-3.1.5
Closed

Bump fast-uri from 3.0.3 to 3.1.5#6132
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/fast-uri-3.1.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.0.3 to 3.1.5.

Release notes

Sourced from fast-uri's releases.

v3.1.5

⚠️ Security Warning

Fix for GHSA-7p8r-x3mc-p8w7

Full Changelog: fastify/fast-uri@v3.1.4...v3.1.5

v3.1.4

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v3.1.3...v3.1.4

v3.1.3

⚠️ Security Release

Full Changelog: fastify/fast-uri@v3.1.2...v3.1.3

v3.1.2

⚠️ Security Release

What's Changed

Full Changelog: fastify/fast-uri@v3.1.1...v3.1.2

v3.1.1

⚠️ Security Release

What's Changed

... (truncated)

Commits


Note

Low Risk
Lockfile-only transitive dependency upgrade with security fixes to URI parsing; no direct code changes, so behavioral risk is low while reducing known URI-related vulnerability exposure.

Overview
Updates the lockfile so the resolved fast-uri version moves from 3.0.3 to 3.1.5. The package is pulled in transitively (e.g. via ajv), not as a direct app dependency.

3.1.1–3.1.5 are security releases that harden URI parsing (malformed fragments, authority handling, and related advisories). There are no application source changes—only package-lock.json (including minor lockfile cleanup such as removing a nested chain-registry entry under @chain-registry/utils).

Reviewed by Cursor Bugbot for commit 9e6a333. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 3, 2026
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.0.3 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.0.3...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-uri-3.1.5 branch from 9b0f67b to 9e6a333 Compare August 3, 2026 22:23
@dependabot @github

dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

1 similar comment
@dependabot @github

dependabot Bot commented on behalf of github Aug 6, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@dependabot @github

dependabot Bot commented on behalf of github Aug 7, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #6146.

@dependabot dependabot Bot closed this Aug 7, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/fast-uri-3.1.5 branch August 7, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants