chore(deps): bump fast-uri from 3.1.6 to 3.1.8 - #6797
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.6 to 3.1.8. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.6...v3.1.8) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.8 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Semver Impact of This PR⚪ None (no version bump detected) 📋 Changelog PreviewThis is how your changes will appear in the changelog.
🤖 This preview updates automatically when you update the PR. |
| "deepmerge-ts": "^8.0.0", | ||
| "browserslist": "^4.28.7", | ||
| "fast-uri": "^3.1.6", | ||
| "fast-uri": "^3.1.8", |
There was a problem hiding this comment.
Stale fast-uri lock entry makes immutable CI installs fail
Please regenerate and commit yarn.lock alongside this resolution update. The lockfile still resolves fast-uri to 3.1.6, while the new resolution selects ^3.1.8. Yarn needs to update the lockfile to install the new resolution; immutable installs in CI will fail instead of applying the bump.
Evidence
package.jsonsets thefast-uriresolution to^3.1.8, butyarn.lockhas only a^3.1.6entry, resolved to 3.1.6.- The new resolution requires a lockfile update; the committed lockfile does not record the 3.1.8 resolution.
.github/workflows/buildandtest.ymlrunsyarn install; Yarn 4 enables immutable installs by default in CI, so the stale lockfile makes that install fail rather than update the dependency.
Identified by Warden · code-review · VPK-7LY
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 31d9827. Configure here.
| "deepmerge-ts": "^8.0.0", | ||
| "browserslist": "^4.28.7", | ||
| "fast-uri": "^3.1.6", | ||
| "fast-uri": "^3.1.8", |
There was a problem hiding this comment.
Lockfile still pins vulnerable version
Medium Severity
The resolutions bump to fast-uri ^3.1.8 is not reflected in yarn.lock, which still locks fast-uri@npm:^3.1.6 at 3.1.6. The GHSA-qw65-cvwx-89v3, GHSA-58mr-gqgx-xq4g, and GHSA-hrr3-gc8f-f4qj fixes therefore do not apply, and Yarn 4 immutable installs in CI will reject the lockfile. Flagged because the review guidelines require checking chore(deps) JS updates for changelog and compatibility impact.
Triggered by project rule: PR Review Guidelines for Cursor Bot
Reviewed by Cursor Bugbot for commit 31d9827. Configure here.


Bumps fast-uri from 3.1.6 to 3.1.8.
Release notes
Sourced from fast-uri's releases.
Commits
ead3ab7Bumped v3.1.8c88b59efix: normalize decoded reg-name case412e40aBumped v3.1.79f4c943fix: backport port and IP-literal validation to v3.x (#216)1eb3ce4fix: treat unterminated bracket hosts as reg-names again (#214)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.