Skip to content

F265: Bump vulnerable fast-uri and undici - #62

Merged
mblode merged 1 commit into
mainfrom
f265-bump-vulnerable-fast-uri-and-undici
Sep 29, 2026
Merged

mblode merged 1 commit into
mainfrom
f265-bump-vulnerable-fast-uri-and-undici

Conversation

@mblode

@mblode mblode commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Bumps the lockfile only: fast-uri 3.1.6 → 3.1.8, undici 7.29.0 → 7.30.0 (shadcn) and 8.11.0 → 8.11.2 (jsdom). Empty changeset added for the CI gate.

Evidence: npm ls shows the new versions; npm run lint, check-types, test and build pass. GHSA ranges checked with gh api /advisories/<id>: fixed in fast-uri 3.1.7, undici 7.29.1 and 8.10.2; installed 3.1.8, 7.30.0, 8.11.2 are all past those.

Learned: the repo has no npm run verify, so proof is the CI set (lint, check-types, test, build) run by hand.

Signal

none: lockfile-only security bump, no user-visible change

🤖 Generated with Claude Code

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017ESkSjfybeQJF4Ln4VQq5e
@vercel

vercel Bot commented Sep 29, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
diffhub-web Ignored Ignored Sep 29, 2026 7:51pm UTC

Request Review

@mblode
mblode marked this pull request as ready for review September 29, 2026 20:04
@mblode

mblode commented Sep 29, 2026

Copy link
Copy Markdown
Owner Author
Verdict: pass. No repo proof (no verify script); lint, check-types, test, build pass. All four GHSAs fixed by the installed versions.

@mblode
mblode merged commit fde4fcd into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant