Skip to content

build(deps): bump fast-uri from 3.1.7 to 3.1.8 in /scripts/ci/noema-document-reader - #2535

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/scripts/ci/noema-document-reader/fast-uri-3.1.8
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/scripts/ci/noema-document-reader/fast-uri-3.1.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.1.7 to 3.1.8.

Release notes

Sourced from fast-uri's releases.

v3.1.8

⚠️ Security Warning

This security release fixes the following medium-severity security advisory:

Users of the v3.x release line should upgrade to v3.1.8.

Full Changelog: fastify/fast-uri@v3.1.7...v3.1.8

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.7 to 3.1.8.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.7...v3.1.8)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 30, 2026 05:07
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 35ba926e-4edc-4ace-a16e-51dc449653ee

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added area: security Security boundary, hardening, or vulnerability prevention maintenance priority: high High-priority or P1 work status: needs-review Open pull request requiring current-head review or checks labels Sep 30, 2026 — with ChatGPT Codex Connector
@seonghobae
seonghobae marked this pull request as draft September 30, 2026 14:49

Copy link
Copy Markdown
Contributor

Ready is review admission only. Exact head f9165e865c13f0a9e9fe935a3eb4c76e959b43cc has terminal non-GREEN evidence: CodeQL PR run 36671985504 = failure; Security Scan run 36671985569 = failure; Python Security run 36671985583 = failure. I moved the PR back to Draft. Return to Ready only on a new exact head with applicable terminal GREEN checks, zero substantive unresolved threads, and qualifying independent review. No rerun, status synthesis, bypass, force push, destructive rebase, merge, or closure was used.

Copy link
Copy Markdown
Contributor

Verified complete successor transfer

This Draft predecessor at exact head f9165e865c13f0a9e9fe935a3eb4c76e959b43cc changes only scripts/ci/noema-document-reader/package-lock.json, advancing fast-uri from 3.1.7 to 3.1.8 with tarball fast-uri-3.1.8.tgz and integrity sha512-GZMtZUTNRpOVIECoXwLNZS5xUGE+mVNbTB8h/7Rwh2TFWcBQiPzTgyZi05BF9UMZKkLJv8XBRJTlU7zg8+ZfMg==.

Canonical owner #2545 exact head 9a4af5e438283a31dc05814d6bc2818caee782a3 carries those exact lock bytes and additionally owns the version in package.json, rejects vulnerable hoisted or nested copies, passes the 5,170-test warnings-fatal suite, reports zero npm vulnerabilities, and has exact-head Security Scan and SAST success.

Every valid delta in this one-file predecessor is therefore present in the live successor with stronger executable contracts. Closing records verified successor carryover; it is not a claim that #2545 is merged or release-authoritative. #2545 remains subject to authenticated CodeQL evidence, independent approval, and ordinary protected merge.

@seonghobae seonghobae closed this Sep 30, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/scripts/ci/noema-document-reader/fast-uri-3.1.8 branch September 30, 2026 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: security Security boundary, hardening, or vulnerability prevention dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code maintenance priority: high High-priority or P1 work status: needs-review Open pull request requiring current-head review or checks

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant