Skip to content

chore: Bump fast-uri from 3.1.2 to 3.1.4 - #66

Merged
jperals merged 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.4
Jul 28, 2026
Merged

chore: Bump fast-uri from 3.1.2 to 3.1.4#66
jperals merged 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.4

Conversation

@ernst-dev

Copy link
Copy Markdown
Member

Bumps fast-uri from 3.1.2 to 3.1.4 to address two host-confusion vulnerabilities.

Lockfile-only change (transitive dependency; package-lock.json only). fast-uri has no dependencies, so only its single entry changes.

Severity Advisory Summary
High GHSA-v2hh-gcrm-f6hx Host confusion via literal backslash authority delimiter (patched 3.1.4)
High GHSA-4c8g-83qw-93j6 Host confusion via failed IDN canonicalization (patched 3.1.3)
  • Vulnerable versions: <= 3.1.3Patched version: 3.1.4

Opened by roko-dependabot-handler on behalf of @ernst-dev to remediate Dependabot alerts that had no auto-generated fix.

@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@ernst-dev
ernst-dev requested a review from a team as a code owner July 23, 2026 12:02
@ernst-dev
ernst-dev requested review from SpyZzey and removed request for a team July 23, 2026 12:02
@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@jperals
jperals added this pull request to the merge queue Jul 28, 2026
Merged via the queue into main with commit eff7a4a Jul 28, 2026
76 of 77 checks passed
@jperals
jperals deleted the dependabot/npm_and_yarn/fast-uri-3.1.4 branch July 28, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants