Skip to content

chore(deps): bump fast-uri to 3.1.7 in the electron lockfile (4 HIGH alerts) - #12601

Merged
diegosouzapw merged 1 commit into
release/v3.8.51from
chore/bump-fast-uri-electron
Sep 3, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.51from
chore/bump-fast-uri-electron

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

Closes Dependabot alerts #196, #197, #198, #199 — four HIGH advisories on fast-uri (GHSA-jqff-g426-hqxp, GHSA-fph4-wmhf-6fwf, GHSA-f65p-4m7j-42xc, GHSA-5jgf-p345-68v8), all patched in 3.1.6.

Why this is one file and not fourteen

The Dependabot page showed 14 open alerts. Checking the tip before writing anything: origin/release/v3.8.51 already carries the patched versions for fast-uri, qs, browserslist, @xmldom/xmldom and @humanfs/node in the root package-lock.json. My first attempt at a bump was a no-op against a stale local checkout — those alerts close on their own with the next scan, and by the time I re-read the API the count was already down to 5.

What is genuinely still open is a second lockfile: electron/package-lock.json was still pinning fast-uri@3.1.5. That is what alerts #196–#199 report.

The change

Transitive, one copy, pulled by ajv (^3.0.1), so npm update fast-uri --package-lock-only lifts it without touching any manifest. The whole diff is three lines — version, resolved, integrity for that single entry:

-      "version": "3.1.5",
+      "version": "3.1.7",

check:lockfile (including the workspace lock/manifest consistency check) and check:tracked-artifacts pass.

Not fixed here

extract-zip (#191, HIGH, <= 2.0.1) has no published patch. It arrives through @openai/codex-security and is dev-scope. Closing it needs either an upstream release or a decision to drop/replace that dependency — neither belongs in a lockfile bump. Flagging rather than silently leaving it out of the PR description.

Targets release/v3.8.51.

Dependabot alerts #196–#199 — four HIGH advisories on fast-uri
(GHSA-jqff-g426-hqxp, GHSA-fph4-wmhf-6fwf, GHSA-f65p-4m7j-42xc,
GHSA-5jgf-p345-68v8), all patched in 3.1.6.

The root package-lock.json was already on a patched fast-uri (3.1.7) — those
alerts close on their own with the next scan. `electron/package-lock.json` is a
second lockfile and was still pinning 3.1.5, which is what these four alerts are
actually reporting.

Transitive, one copy, pulled by ajv (`^3.0.1`), so a package-lock-only update
lifts it without touching any manifest. The diff is three lines: version,
resolved and integrity for that single entry.

check:lockfile and check:tracked-artifacts pass.

Not fixed here: extract-zip (#191, HIGH, <= 2.0.1) has no published patch. It
comes in through @openai/codex-security and is dev-scope; it needs either an
upstream release or a decision to drop/replace the dependency, neither of which
belongs in a lockfile bump.
@diegosouzapw
diegosouzapw merged commit e1cf542 into release/v3.8.51 Sep 3, 2026
19 of 21 checks passed
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…uzapw#12601)

Dependabot alerts diegosouzapw#196–diegosouzapw#199 — four HIGH advisories on fast-uri
(GHSA-jqff-g426-hqxp, GHSA-fph4-wmhf-6fwf, GHSA-f65p-4m7j-42xc,
GHSA-5jgf-p345-68v8), all patched in 3.1.6.

The root package-lock.json was already on a patched fast-uri (3.1.7) — those
alerts close on their own with the next scan. `electron/package-lock.json` is a
second lockfile and was still pinning 3.1.5, which is what these four alerts are
actually reporting.

Transitive, one copy, pulled by ajv (`^3.0.1`), so a package-lock-only update
lifts it without touching any manifest. The diff is three lines: version,
resolved and integrity for that single entry.

check:lockfile and check:tracked-artifacts pass.

Not fixed here: extract-zip (diegosouzapw#191, HIGH, <= 2.0.1) has no published patch. It
comes in through @openai/codex-security and is dev-scope; it needs either an
upstream release or a decision to drop/replace the dependency, neither of which
belongs in a lockfile bump.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant