fix(deps): patch fast-uri, undici and qs advisories - #66
Open
catinspace-au wants to merge 1 commit into
Open
catinspace-au wants to merge 1 commit into
catinspace-au wants to merge 1 commit into
Conversation
Lockfile-only bump inside the ranges package.json already allows, resolved with npm's --before set 7 days back so nothing younger than a week lands. fast-uri 4.1.2 -> 4.2.1 clears GHSA-qw65-cvwx-89v3, GHSA-5jgf-p345-68v8, GHSA-f65p-4m7j-42xc, GHSA-fph4-wmhf-6fwf and GHSA-jqff-g426-hqxp (Dependabot #76-#79, #84). undici 8.10.0 -> 8.10.2 clears GHSA-3wwx-pv8p-q78v, the WebSocket permessage-deflate DoS (#85, auto-dismissed as dev-only). qs 6.15.3 -> 6.16.0 clears GHSA-x5fp-wj9c-mxmx and GHSA-4mjr-xmp4-gh2g (#80, #81, also auto-dismissed). vitest and @vitest/mocker (#82, #83) are left to Renovate's #63, which already carries 4.1.11.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears the fast-uri Dependabot alerts, plus the undici and qs ones Dependabot auto-dismissed as dev-only. Lockfile only.
package.jsonis untouched because the existingoverridesand ranges already allow the fixed versions.Resolved with
npm update --package-lock-only --before=2026-09-22, so nothing younger than 7 days got in. Nothing else in the lock moved.vitest and @vitest/mocker (#82, #83) are NOT in here. Renovate's #63 already bumps them to 4.1.11 and its checks are green. Merge both. With the two together,
npm auditreports 0 vulnerabilities (checked locally with a trial vitest bump on top of this branch).Checked locally:
npm test: 33 files, 792 tests pass.npm run lint: clean.npm run package: VSIX builds.npm audit: only the vitest advisory is left, and fix(deps): update dependency vitest to v4.1.11 [SECURITY] #63 covers it.