Skip to content

Bump fast-uri from 3.0.3 to 3.1.4#6097

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/fast-uri-3.1.4
Open

Bump fast-uri from 3.0.3 to 3.1.4#6097
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/fast-uri-3.1.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.0.3 to 3.1.4.

Release notes

Sourced from fast-uri's releases.

v3.1.4

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v3.1.3...v3.1.4

v3.1.3

⚠️ Security Release

Full Changelog: fastify/fast-uri@v3.1.2...v3.1.3

v3.1.2

⚠️ Security Release

What's Changed

Full Changelog: fastify/fast-uri@v3.1.1...v3.1.2

v3.1.1

⚠️ Security Release

What's Changed

New Contributors

... (truncated)

Commits


Note

Low Risk
No application source changes; only a transitive dependency security patch in the lockfile, which reduces exposure to known URI parsing issues.

Overview
Updates the lockfile so the hoisted fast-uri dependency moves from 3.0.3 to 3.1.4 (resolved tarball and integrity hash). It is pulled in transitively (e.g. via ajv), not as a direct app dependency.

3.1.x is a series of security releases for URI parsing (malformed fragments, authority handling, and related parse edge cases). The diff also drops a redundant nested chain-registry entry under @chain-registry/utils, consistent with lockfile normalization rather than an app change.

Reviewed by Cursor Bugbot for commit 6aa7ae4. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 24, 2026
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.0.3 to 3.1.4.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.0.3...v3.1.4)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-uri-3.1.4 branch from 6df765f to 6aa7ae4 Compare July 24, 2026 19:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants