Skip to content

Update fast-uri to 3.1.1 to fix CVE-2026-6321 (#1981)#1981

Closed
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D104695957
Closed

Update fast-uri to 3.1.1 to fix CVE-2026-6321 (#1981)#1981
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D104695957

Conversation

@rozele

@rozele rozele commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Summary:

Update the fast-uri transitive dependency from 3.1.0 to 3.1.1 in the yoga yarn.lock to remediate a high-severity security vulnerability (CVE-2026-6321, GHSA-q3j6-qgpj-74h6). fast-uri is a transitive dependency pulled in through ajv@8.18.0. The vulnerability affects versions <= 3.1.0 and is fixed in 3.1.1. Only the yarn.lock entry is changed — the version, resolved URL, and integrity hash are updated to match the published 3.1.1 package on npm.

Reviewed By: javache

Differential Revision: D104695957

@meta-cla meta-cla Bot added the CLA Signed label Jun 29, 2026
@meta-codesync

meta-codesync Bot commented Jun 29, 2026

Copy link
Copy Markdown

@rozele has exported this pull request. If you are a Meta employee, you can view the originating Diff in D104695957.

@meta-codesync meta-codesync Bot changed the title Update fast-uri to 3.1.1 to fix CVE-2026-6321 Update fast-uri to 3.1.1 to fix CVE-2026-6321 (#1981) Jun 29, 2026
rozele added a commit to rozele/yoga that referenced this pull request Jun 29, 2026
Summary:

Update the fast-uri transitive dependency from 3.1.0 to 3.1.1 in the yoga yarn.lock to remediate a high-severity security vulnerability (CVE-2026-6321, GHSA-q3j6-qgpj-74h6). fast-uri is a transitive dependency pulled in through ajv@8.18.0. The vulnerability affects versions <= 3.1.0 and is fixed in 3.1.1. Only the yarn.lock entry is changed — the version, resolved URL, and integrity hash are updated to match the published 3.1.1 package on npm.

Reviewed By: javache

Differential Revision: D104695957
@rozele rozele force-pushed the export-D104695957 branch from f3cbac5 to a0aad6a Compare June 29, 2026 14:35
Summary:

Update the fast-uri transitive dependency from 3.1.0 to 3.1.1 in the yoga yarn.lock to remediate a high-severity security vulnerability (CVE-2026-6321, GHSA-q3j6-qgpj-74h6). fast-uri is a transitive dependency pulled in through ajv@8.18.0. The vulnerability affects versions <= 3.1.0 and is fixed in 3.1.1. Only the yarn.lock entry is changed — the version, resolved URL, and integrity hash are updated to match the published 3.1.1 package on npm.

Reviewed By: javache

Differential Revision: D104695957
@rozele rozele force-pushed the export-D104695957 branch from a0aad6a to 6b635c8 Compare June 29, 2026 14:37
@meta-codesync meta-codesync Bot closed this in 6847182 Jun 29, 2026
@meta-codesync meta-codesync Bot added the Merged label Jun 29, 2026
@meta-codesync

meta-codesync Bot commented Jun 29, 2026

Copy link
Copy Markdown

This pull request has been merged in 6847182.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant