Skip to content

fix(deps): patch fast-uri, undici and qs advisories - #66

Open
catinspace-au wants to merge 1 commit into
mainfrom
fix/security-deps
Open

catinspace-au wants to merge 1 commit into
mainfrom
fix/security-deps

Conversation

@catinspace-au

Copy link
Copy Markdown
Contributor

Clears the fast-uri Dependabot alerts, plus the undici and qs ones Dependabot auto-dismissed as dev-only. Lockfile only. package.json is untouched because the existing overrides and ranges already allow the fixed versions.

  • fast-uri 4.1.2 -> 4.2.1 (released 2026-09-18). Fixes #76, #77, #78, #79 and #84.
  • undici 8.10.0 -> 8.10.2 (2026-09-04). Fixes GHSA-3wwx-pv8p-q78v, the WebSocket permessage-deflate DoS from Slack (#85, auto-dismissed).
  • qs 6.15.3 -> 6.16.0 (2026-08-29). Fixes #80 and #81 (auto-dismissed).

Resolved with npm update --package-lock-only --before=2026-09-22, so nothing younger than 7 days got in. Nothing else in the lock moved.

vitest and @vitest/mocker (#82, #83) are NOT in here. Renovate's #63 already bumps them to 4.1.11 and its checks are green. Merge both. With the two together, npm audit reports 0 vulnerabilities (checked locally with a trial vitest bump on top of this branch).

Checked locally:

Lockfile-only bump inside the ranges package.json already allows, resolved with npm's --before set 7 days back so nothing younger than a week lands.

fast-uri 4.1.2 -> 4.2.1 clears GHSA-qw65-cvwx-89v3, GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf and GHSA-jqff-g426-hqxp (Dependabot #76-#79, #84). undici 8.10.0 -> 8.10.2 clears GHSA-3wwx-pv8p-q78v, the WebSocket permessage-deflate DoS (#85, auto-dismissed as dev-only). qs 6.15.3 -> 6.16.0 clears GHSA-x5fp-wj9c-mxmx and GHSA-4mjr-xmp4-gh2g (#80, #81, also auto-dismissed).

vitest and @vitest/mocker (#82, #83) are left to Renovate's #63, which already carries 4.1.11.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant