Skip to content

build(deps): Bump fast-uri from 3.1.0 to 3.1.2 in /.github/workflows in the npm_and_yarn group across 1 directory#31084

Merged
pelikhan merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dot-github/workflows/npm_and_yarn-053c9c4054
May 9, 2026
Merged

build(deps): Bump fast-uri from 3.1.0 to 3.1.2 in /.github/workflows in the npm_and_yarn group across 1 directory#31084
pelikhan merged 1 commit into
mainfrom
dependabot/npm_and_yarn/dot-github/workflows/npm_and_yarn-053c9c4054

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 8, 2026

Bumps the npm_and_yarn group with 1 update in the /.github/workflows directory: fast-uri.

Updates fast-uri from 3.1.0 to 3.1.2

Release notes

Sourced from fast-uri's releases.

v3.1.2

⚠️ Security Release

What's Changed

Full Changelog: fastify/fast-uri@v3.1.1...v3.1.2

v3.1.1

⚠️ Security Release

What's Changed

New Contributors

Full Changelog: fastify/fast-uri@v3.1.0...v3.1.1

Commits
  • 919dd8e Bumped v3.1.2
  • c65ba57 fixup: linting
  • 6c86c17 Merge commit from fork
  • a95158a Handle malformed fragment decoding without throwing (#171)
  • cea547c Bumped v3.1.1
  • 876ce79 Merge commit from fork
  • dcdf690 ci: add lock-threads workflow (#169)
  • c860e65 build(deps-dev): bump neostandard from 0.12.2 to 0.13.0 (#167)
  • 9b4c6dc build(deps): bump fastify/workflows/.github/workflows/plugins-ci.yml (#166)
  • 85d09a9 build(deps): bump fastify/workflows/.github/workflows/plugins-ci-package-mana...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the /.github/workflows directory: [fast-uri](https://github.com/fastify/fast-uri).


Updates `fast-uri` from 3.1.0 to 3.1.2
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.0...v3.1.2)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 8, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 8, 2026

Smoke Project encountered failures. Check the logs for details.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 8, 2026

📰 DEVELOPING STORY: Smoke Copilot ARM64 reports was cancelled. Our correspondents are investigating the incident...

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented May 8, 2026

Hey @dependabot 👋 — thanks for the automated security bump of fast-uri (3.1.0 → 3.1.2)! This addresses a published security advisory (GHSA-v39h-62p7-jpjc), which is always appreciated.

A couple of things to note for maintainers reviewing this:

  • Process: The CONTRIBUTING.md for this project specifies that PRs should only be opened by core team members; community contributions are expected to go through the issue-and-agentic-plan workflow first. While Dependabot is automated and not a human contributor, this PR technically falls outside the documented contribution process — maintainers should confirm whether Dependabot is an approved automation for this repo.
  • No tests: The diff contains no test changes. For a dependency bump this is expected, but maintainers should verify CI passes before merging.

If a core team member would like to action this via an agent instead:

Update the fast-uri dependency in .github/workflows from version 3.1.0 to 3.1.2 to address the security advisory GHSA-v39h-62p7-jpjc. Only change the version pin in the relevant package-lock.json or yarn.lock inside the .github/workflows directory. Do not change any other dependencies. Verify CI configuration still works after the update.

Generated by Contribution Check · ● 7.3M ·

@pelikhan pelikhan merged commit ce01aaf into main May 9, 2026
316 of 388 checks passed
@pelikhan pelikhan deleted the dependabot/npm_and_yarn/dot-github/workflows/npm_and_yarn-053c9c4054 branch May 9, 2026 02:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant