deps: bump qs from 6.14.1 to 6.15.2 - #70
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [qs](https://github.com/ljharb/qs) from 6.14.1 to 6.15.2. - [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md) - [Commits](ljharb/qs@v6.14.1...v6.15.2) --- updated-dependencies: - dependency-name: qs dependency-version: 6.15.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Reviewed by execution (fresh worktrees at head 33f3860 vs base e704b49). VERDICT: SHIP — merge-safe, strictly reduces qs advisory count (3 → 2). Follow-up below. Scope check: diff vs merge-base ce7da5b touches exactly 1 file: Tests/baseline-delta: head 57/57 pass = base 57/57 pass (no delta). typecheck/lint/build exit 0 at head. GitHub checks 8/9 SUCCESS; the one FAILURE ( OSV advisory delta (osv.dev, package qs):
The bump clears CVE-2026-2391 (arrayLimit bypass, ≤6.14.1) and CVE-2026-8723 (qs.stringify DoS, ≤6.15.1). Honest caveats: CVE-2026-82417 (DoS via attacker-controlled isBuffer, <6.16.0) persists, and CVE-2026-82562 (array-limit bypass via bracket-key comma parsing, range >=6.14.2 <=6.15.3) is newly in range with this bump — 6.14.1 was not affected by that one. Net: 3 → 2 moderate advisories, no new vulnerable package introduced ( Follow-up (clean in-range target): qs 6.16.0 (published 2026-08-29, after this PR was cut) is in-range for both consumers (^6.14.x) and clears ALL qs advisories per OSV. Recommend merging this as-is or retargeting the bump to 6.16.0; do not leave main on 6.14.1. Staleness: not superseded — this is the only qs PR (open or closed); main still pins 6.14.1. Branch is 4 months behind main, but main's root |
Independent review verdict: FIX-FIRST (retarget to qs 6.16.0)Reviewer: grok lane, headless, execution-based (writer != reviewer). Run in a detached worktree at Finding (major) —
|
| version | OSV advisories |
|---|---|
| 6.14.1 (base) | 3 — GHSA-4mjr-xmp4-gh2g (CVE-2026-82417), GHSA-q8mj-m7cp-5q26 (CVE-2026-8723), GHSA-w7fw-mjwx-w883 (CVE-2026-2391) |
| 6.15.2 (this PR) | 2 — GHSA-x5fp-wj9c-mxmx (CVE-2026-82562, fixed range >=6.14.2 <=6.15.3 — newly entered by this bump, 6.14.1 was not affected), GHSA-4mjr-xmp4-gh2g (CVE-2026-82417, >=2.2.5 <6.16.0) |
| 6.16.0 (clean target) | 0 |
6.16.0 satisfies both consumer ranges (express ^6.14.0, body-parser ^6.14.1). Concrete failure scenario: after merge, request parsing in the express/body-parser stack remains inside both unfixed advisory ranges, including the array-limit bypass this PR newly introduces relative to 6.14.1. Retarget the lock to 6.16.0.
Cleared by this bump (not the blocker): GHSA-q8mj-m7cp-5q26 (fixed in 6.15.2), GHSA-w7fw-mjwx-w883 (fixed in 6.14.2).
Verified green (execution receipts)
- Scope: only
package-lock.jsonchanged (6 insertions, 13 deletions); nopackage.jsonchange. - Tests:
npm test→tests 57, pass 57, fail 0, skipped 0(matches historical count). - Delivered version matches title:
node_modules/qs→ 6.15.2, registry integrity equals lock integrity. - Incidental
0.1.0 → 0.2.0lockfile version sync is correct:package.jsonwas already0.2.0at the merge-base and on main — the lock was the stale side. - Peer-flag churn (hono gains
peer:true; express/typescript/zod/acorn lose it) does not change resolved versions —npm lsexits 0 for all affected packages. - Not superseded / not conflict-stale: behind main by 1 commit (which does not touch the root lock),
git merge-tree→ 0 conflicts, MERGEABLE, no other open qs bump; main still resolves qs 6.14.1. npm auditat head:qsmoderate,fixAvailable: true; total advisory count unchanged (19 at base and head) — the remaining 19 are other dependencies.
Bumps qs from 6.14.1 to 6.15.2.
Changelog
Sourced from qs's changelog.
Commits
9aca407v6.15.25e33d33[Dev Deps] update@ljharb/eslint-config21f80b3[Fix]stringify: skip null/undefined entries inarrayFormat: 'comma'+ `e...a0a81ea[Fix]stringify: use configureddelimiteraftercharsetSentinele3062f7[Fix]stringify: applyformatterto encoded key understrictNullHandling0c180a4[Fix]stringify: skip null/undefined filter-array entries instead of crashi...3a8b94a[Tests] add regression tests for keys containing percent-encoded bracket text96755ab[readme] fix grammara419ce5[Fix]parse: handle nested bracket groups and add regression tests3f5e1c5v6.15.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.