chore(deps): bump fast-uri to 3.1.7 in the electron lockfile (4 HIGH alerts) - #12601
Merged
Merged
Conversation
Dependabot alerts #196–#199 — four HIGH advisories on fast-uri (GHSA-jqff-g426-hqxp, GHSA-fph4-wmhf-6fwf, GHSA-f65p-4m7j-42xc, GHSA-5jgf-p345-68v8), all patched in 3.1.6. The root package-lock.json was already on a patched fast-uri (3.1.7) — those alerts close on their own with the next scan. `electron/package-lock.json` is a second lockfile and was still pinning 3.1.5, which is what these four alerts are actually reporting. Transitive, one copy, pulled by ajv (`^3.0.1`), so a package-lock-only update lifts it without touching any manifest. The diff is three lines: version, resolved and integrity for that single entry. check:lockfile and check:tracked-artifacts pass. Not fixed here: extract-zip (#191, HIGH, <= 2.0.1) has no published patch. It comes in through @openai/codex-security and is dev-scope; it needs either an upstream release or a decision to drop/replace the dependency, neither of which belongs in a lockfile bump.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…uzapw#12601) Dependabot alerts diegosouzapw#196–diegosouzapw#199 — four HIGH advisories on fast-uri (GHSA-jqff-g426-hqxp, GHSA-fph4-wmhf-6fwf, GHSA-f65p-4m7j-42xc, GHSA-5jgf-p345-68v8), all patched in 3.1.6. The root package-lock.json was already on a patched fast-uri (3.1.7) — those alerts close on their own with the next scan. `electron/package-lock.json` is a second lockfile and was still pinning 3.1.5, which is what these four alerts are actually reporting. Transitive, one copy, pulled by ajv (`^3.0.1`), so a package-lock-only update lifts it without touching any manifest. The diff is three lines: version, resolved and integrity for that single entry. check:lockfile and check:tracked-artifacts pass. Not fixed here: extract-zip (diegosouzapw#191, HIGH, <= 2.0.1) has no published patch. It comes in through @openai/codex-security and is dev-scope; it needs either an upstream release or a decision to drop/replace the dependency, neither of which belongs in a lockfile bump.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes Dependabot alerts #196, #197, #198, #199 — four HIGH advisories on
fast-uri(GHSA-jqff-g426-hqxp,GHSA-fph4-wmhf-6fwf,GHSA-f65p-4m7j-42xc,GHSA-5jgf-p345-68v8), all patched in3.1.6.Why this is one file and not fourteen
The Dependabot page showed 14 open alerts. Checking the tip before writing anything:
origin/release/v3.8.51already carries the patched versions forfast-uri,qs,browserslist,@xmldom/xmldomand@humanfs/nodein the rootpackage-lock.json. My first attempt at a bump was a no-op against a stale local checkout — those alerts close on their own with the next scan, and by the time I re-read the API the count was already down to 5.What is genuinely still open is a second lockfile:
electron/package-lock.jsonwas still pinningfast-uri@3.1.5. That is what alerts #196–#199 report.The change
Transitive, one copy, pulled by
ajv(^3.0.1), sonpm update fast-uri --package-lock-onlylifts it without touching any manifest. The whole diff is three lines —version,resolved,integrityfor that single entry:check:lockfile(including the workspace lock/manifest consistency check) andcheck:tracked-artifactspass.Not fixed here
extract-zip(#191, HIGH,<= 2.0.1) has no published patch. It arrives through@openai/codex-securityand is dev-scope. Closing it needs either an upstream release or a decision to drop/replace that dependency — neither belongs in a lockfile bump. Flagging rather than silently leaving it out of the PR description.Targets
release/v3.8.51.