Skip to content

Bump fast-uri from 3.0.3 to 3.1.4 - #6097

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/fast-uri-3.1.4
Open

Bump fast-uri from 3.0.3 to 3.1.4#6097
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/fast-uri-3.1.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.0.3 to 3.1.4.

Release notes

Sourced from fast-uri's releases.

v3.1.4

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v3.1.3...v3.1.4

v3.1.3

⚠️ Security Release

Full Changelog: fastify/fast-uri@v3.1.2...v3.1.3

v3.1.2

⚠️ Security Release

What's Changed

Full Changelog: fastify/fast-uri@v3.1.1...v3.1.2

v3.1.1

⚠️ Security Release

What's Changed

New Contributors

... (truncated)

Commits


Note

Low Risk
Lockfile-only dependency bump that applies published security patches to a transitive URI parser; behavior change is limited to stricter URI validation, with no direct edits to app code.

Overview
Updates the lockfile so transitive fast-uri resolves to 3.1.4 (from 3.0.3), chiefly for packages such as ajv that depend on fast-uri.

That release line is marked as security fixes (URI authority backslash rejection, malformed fragment handling, and related advisories between 3.1.1–3.1.4). No application source changes—only package-lock.json, including a small unrelated lockfile adjustment under @chain-registry/utils.

Reviewed by Cursor Bugbot for commit fe90084. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 24, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-uri-3.1.4 branch 3 times, most recently from 2d0cd4f to 569862b Compare July 27, 2026 21:38
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.0.3 to 3.1.4.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.0.3...v3.1.4)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-uri-3.1.4 branch from 569862b to fe90084 Compare July 27, 2026 23:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants