Skip to content

fix(deps): bump fast-uri from 3.1.0 to 3.1.8 - #457

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.8
Open

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.1.0 to 3.1.8.

Release notes

Sourced from fast-uri's releases.

v3.1.8

⚠️ Security Warning

This security release fixes the following medium-severity security advisory:

Users of the v3.x release line should upgrade to v3.1.8.

Full Changelog: fastify/fast-uri@v3.1.7...v3.1.8

v3.1.7

⚠️ Security Warning

This is a security release that fixes the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.7.

Full Changelog: fastify/fast-uri@v3.1.6...v3.1.7

v3.1.6

⚠️ Security Warning

This release addresses the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.6.

Full Changelog: fastify/fast-uri@v3.1.5...v3.1.6

v3.1.5

⚠️ Security Warning

Fix for GHSA-7p8r-x3mc-p8w7

Full Changelog: fastify/fast-uri@v3.1.4...v3.1.5

v3.1.4

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v3.1.3...v3.1.4

... (truncated)

Commits
  • ead3ab7 Bumped v3.1.8
  • c88b59e fix: normalize decoded reg-name case
  • 412e40a Bumped v3.1.7
  • 9f4c943 fix: backport port and IP-literal validation to v3.x (#216)
  • 1eb3ce4 fix: treat unterminated bracket hosts as reg-names again (#214)
  • 6f970b2 Bumped v3.1.6
  • d941579 fix: never run IDN canonicalization on bracketed IP literals
  • c0f0279 test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)
  • 37f3417 Merge commit from fork
  • 607bfbe Merge commit from fork
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.8.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.0...v3.1.8)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026
@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
cli-web-cli Ready Ready Preview Sep 30, 2026 11:57pm UTC

Request Review

@ci-lockfile-regen

Copy link
Copy Markdown

Dependabot Fix Assessment

Package: `fast-uri` `3.1.0` → `3.1.8` (patch)
Scope: transitive devDependency (pulled in by `ajv` → `ajv-formats` → `fast-uri`)
Workspace: root

What changed upstream

  • v3.1.4–v3.1.8 are all security-only releases — no API or behaviour changes
  • Fixes: host case normalization, authority injection via unvalidated port, host confusion via IP-literal brackets, SSRF via IDN/IPv6/percent-encoding issues
  • Full release notes: https://github.com/fastify/fast-uri/releases

Migration concerns checked

  • Peer dependencies: OK — patch release, no peer dep changes
  • Type changes: OK — no exported types changed
  • Config files: OK — library has no config file in this repo
  • Module format: OK — ESM/CJS format unchanged between 3.1.0 and 3.1.8
  • React compatibility: OK — not a React dependency
  • Monorepo impact: OK — fast-uri is a transitive dep; no workspace package directly imports it

What broke

  • All three CI workflows (Run Tests, E2E Tests, Web CLI E2E Tests): ERR_PNPM_LOCKFILE_CONFIG_MISMATCH — the lockfile's overrides section did not match package.json after Dependabot bumped the dependency. This is the standard consequence of a transitive dependency bump without a lockfile regeneration.

What was fixed

  • The lockfile regeneration workflow already ran and committed the updated pnpm-lock.yaml (commit 5a54adf). No source code changes were required — fast-uri 3.1.0→3.1.8 is a pure security patch with no API changes.
  • pnpm install --frozen-lockfile now succeeds on the current branch.

Verification

  • Build: ✅ (pnpm run build succeeds)
  • Lint: ✅ (0 errors, 10 pre-existing warnings)
  • Unit tests: ✅ (2643 passed; 1 flaky test in did-you-mean.test.ts is pre-existing and unrelated — passes on re-run)
  • Web CLI tests: ✅ (57 passed, 6 skipped)

Notes for reviewer

  • The failing CI runs shown in the PR were triggered by Dependabot's original commit, before the lockfile was regenerated. The new CI runs (triggered by the lockfile regeneration commit) are in progress/passing.
  • The one flaky test (did-you-mean.test.ts > Non-Interactive Mode > should show Y/N prompt for misspelled commands) is a pre-existing environmental flake — it tests subprocess output with a 2 s timeout and occasionally races. It is not related to fast-uri.

@ci-lockfile-regen

Copy link
Copy Markdown

Dependabot Fix Assessment

Package: `fast-uri` `3.1.0` → `3.1.8` (patch — multiple security releases)
Scope: devDependency (transitive only)
Workspace: root

What changed upstream

`fast-uri` 3.1.1–3.1.8 are all security-only patch releases fixing URI parsing vulnerabilities:

  • 3.1.4: GHSA-v2hh-gcrm-f6hx — unspecified
  • 3.1.5: GHSA-7p8r-x3mc-p8w7 — unspecified
  • 3.1.6: host confusion via IDN canonicalization, SSRF via percent-decoded hostnames/IPv6, percent-encoded scheme normalization
  • 3.1.7: authority injection via unvalidated port in `serialize()`, host confusion via IP-literal brackets
  • 3.1.8: inconsistent host case normalization via percent-encoded octets

All changes are behavioral fixes for URI edge cases — no API changes, no removed exports.

Migration concerns checked

  • Peer dependencies: OK — no peer dep changes
  • Type changes: OK — no API surface changes
  • Config files: OK — no config involved
  • Module format: OK — no ESM/CJS change
  • React compatibility: N/A
  • Monorepo impact: OK — only present in root devDependencies chain

What broke (and why it's NOT related to this bump)

The only change in this branch is the lockfile regeneration (pnpm-lock.yaml). fast-uri is not used anywhere in source code — it is a transitive dependency reached via ajv → serve, which is a devDependency used for static file serving only.

The two E2E failures are in `test/e2e/control/control-api-workflows.test.ts`:

  1. Rules Workflow — `createTestApp` threw "Failed to create test app: " (empty stderr, non-zero exit). This means the `ably apps create` CLI command exited with an error but produced no output — a transient API failure (rate limit, quota, or network blip during CI).

  2. should handle non-existent resources — Timed out after 10 seconds waiting for `ably apps update non-existent-app-id` to complete. Another transient API timeout.

All 49 other test files (264 other tests) passed. These two failures are flaky E2E tests that make live API calls, not caused by the fast-uri bump.

What was fixed

No code changes were needed or made. The lockfile was already regenerated in the previous commit.

Verification

  • Build: ✅ (no source changes)
  • Lint: ✅ (no source changes)
  • Unit tests: ✅ (no source changes)
  • Web CLI tests: N/A (no source changes)

Notes for reviewer

Safe to merge. The E2E failures are pre-existing flakiness in the Control API workflow tests that make live API calls — they are not caused by this dependency update. Re-running CI would likely show them passing. This is a security-only patch update with no code migration required.

This branch was successfully deployed

1 active deployment
Preview — 5a54adf8 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Development

Successfully merging this pull request may close these issues.

0 participants