Skip to content

deps: bump fast-uri from 3.1.0 to 3.1.2 - #65

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 9, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.1.0 to 3.1.2.

Release notes

Sourced from fast-uri's releases.

v3.1.2

⚠️ Security Release

What's Changed

Full Changelog: fastify/fast-uri@v3.1.1...v3.1.2

v3.1.1

⚠️ Security Release

What's Changed

New Contributors

Full Changelog: fastify/fast-uri@v3.1.0...v3.1.1

Commits
  • 919dd8e Bumped v3.1.2
  • c65ba57 fixup: linting
  • 6c86c17 Merge commit from fork
  • a95158a Handle malformed fragment decoding without throwing (#171)
  • cea547c Bumped v3.1.1
  • 876ce79 Merge commit from fork
  • dcdf690 ci: add lock-threads workflow (#169)
  • c860e65 build(deps-dev): bump neostandard from 0.12.2 to 0.13.0 (#167)
  • 9b4c6dc build(deps): bump fastify/workflows/.github/workflows/plugins-ci.yml (#166)
  • 85d09a9 build(deps): bump fastify/workflows/.github/workflows/plugins-ci-package-mana...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.2.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.0...v3.1.2)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 9, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Backlog-loop verification: checks/tests green except pre-existing base failures (delta: Head (3352908) = origin/main (ce7da5b) + exactly 1 commit (git rev-list --count origin/main ^origin/dependabot/npm_and_yarn/fast-uri-3.1.2 = 0), and the only changed file is package-lock.json — so base-vs-head is an exact baseline comparison.
CODE GATES (meaured, identical both sides): npm ci exit 0 / npm test 57 pass 0 fail / e2e 9 pass 0 fail / lint 0 errors 1 warning / typecheck exit 0 / build exit 0 — base identical. No gate is worse at head.
FAILING CHECK claude-review: FAILURE at head; also FAILURE for every dependabot PR on the same base ref (29/29 dependabot PRs FAILURE; #70 same annotation 2026-05-23, different diff), and repo-wide 49/52 PRs that ran it are red (47 FAILURE + 2 FAILURE,FAILURE) vs only 3 SUCCESS (#22/#24/#25, human author). Base is not green on this gate either — it is a repo-baseline condition, not a PR regression.
SECURITY DELTA (the real change): fast-uri 3.1.0 (base lock) -> 3.1.2 (head lock). Open high-severity fast-uri alerts: 7/7 apply to base version 3.1.0; 5/7 apply to head version 3.1.2 => merge closes 2 (#86 GHSA-v39h-62p7-jpjc, #87 GHSA-q3j6-qgpj-74h6) and leaves 5 open (#93,#92 need >=3.1.6, #81 >=3.1.5, #73 >=3.1.4, #72 >=3.1.3). Min version closing all 7 = 3.1.6 (3.1.8 exists in 3.x, latest is 4.2.1). npm audit totals UNCHANGED: base {low:1,moderate:8,high:10,total:19} -> head identical; npm audit still lists fast-uri high "3.0.0 - 3.1.5" at head.
Incidental: head lock also repairs a stale root version (base lock 0.1.0 vs base package.json 0.2.0 -> head 0.2.0).). Independent review: REQUEST_CHANGES.
GROK REVIEW OF PR #65 (agent-next/agent-ready, head dependabot/npm_and_yarn/fast-uri-3.1.2 @ 3352908, base main) — grok 1.0.41, ran headless, exit 0, VERDICT: REQUEST_CHANGES

RAW REVIEWER OUTPUT (verbatim, findings section):
"VERDICT: REQUEST_CHANGES

  1. package-lock.json:2318 — The indirect pin moves fast-uri from 3.1.0 to 3.1.2 (integrity matches the registry tarball), which is what the PR body claims for GHSA-q3j6-qgpj-74h6 and GHSA-v39h-62p7-jpjc. That pin is still vulnerable. GHSA-fph4-wmhf-6fwf (CVE-2026-75899, high) affects >=3.1.2 <3.1.6 and is an incomplete fix of the 3.1.2 authority-delimiter change, so this bump introduces it. 3.1.2 is also inside later ranges, including GHSA-v2hh-gcrm-f6hx (<=3.1.3) and GHSA-hrr3-gc8f-f4qj (>=3.0.0 <3.1.8). Both ajv copies still allow fast-uri ^3.0.1 (package-lock.json:875, package-lock.json:1375), and 3.1.8 satisfies that range. npm audit --package-lock-only on a lockfile resolved to 3.1.8 reports no fast-uri advisory; the same audit on this PR's tree reports fast-uri high. Retarget the single hoisted entry at package-lock.json:2318 to 3.1.8. The root 0.1.0 -> 0.2.0 lock metadata and the peer flag edits are what current npm rewrites alongside the bump, and no repo source imports fast-uri, so those are not separate defects."

PRIMARY VERIFICATION BY EXECUTION (each claim re-run by me; writer=devin/deepseek, reviewer=grok, verifier=this worker):

RECOMMENDED ACTION (evidence-backed, not executed — this loop is review-only for a foreign head): do not merge PR #65 as-is; retarget the single hoisted entry at package-lock.json:2318 to fast-uri 3.1.8 (in-range for ajv ^3.0.1), which by execution removes fast-uri from npm audit and closes all 7 alerts including the one 3.1.2 would newly open; the claude-review actor-policy failure needs an owner decision before the PR can go green.

DEVIATIONS (logged, conservative option taken):

  1. The task's "(head PR-head)" is an unsubstituted placeholder; the real head is dependabot/npm_and_yarn/fast-uri-3.1.2 (confirmed via gh pr view 65 --json headRefName,headRefOid = 3352908...). I pinned the review to that exact SHA rather than guessing; no other branch exists for this PR.
  2. The prescribed worktree path /tmp/loop-wt-agent-next_agent-ready-pr65 did not exist (only other runs' worktrees were present, untouched). I ran git fetch origin --prune in /home/robot/workspace/agent-next/agent-ready and created the worktree fresh via git worktree add --detach <path> 3352908a... as the safety contract requires.
  3. I added two clauses to the reviewer prompt: pin the concrete head SHA (placeholder) and "READ-ONLY review: do not modify, commit, or push anything" (grok ran with --always-approve inside a worktree of a shared repo). Review substance unchanged.
  4. Grok ran once, exit 0, well inside the 540s bound — no retry and no reviewer-lane-unavailable fallback was needed.
  5. No PR comment was posted: the STEPS 1-4 do not include one and the head is foreign (review-only). All mutation stayed inside my own /tmp worktree; the main tree is clean (git status --porcelain empty), HEAD still 8373df4, no loop/* branches created, no PR approved or merged.
  6. Cleanup done and verified: git -C /home/robot/workspace/agent-next/agent-ready worktree remove /tmp/loop-wt-agent-next_agent-ready-pr65 --force succeeded, git worktree list shows only the repo's three pre-existing worktrees, my /tmp/pr65-audit scratch and captured logs are deleted; the two other /tmp loop-wt-* directories belong to other runs and were left alone.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant