Skip to content

fix: update fast-uri to 3.1.6 to resolve CVE-2026-75931, CVE-2026-76172, CVE-2026-75899, CVE-2026-75975 - #195

Closed
independabot-soc2[bot] wants to merge 1 commit into
mainfrom
independabot/fast-uri-CVE-2026-75931
Closed

fix: update fast-uri to 3.1.6 to resolve CVE-2026-75931, CVE-2026-76172, CVE-2026-75899, CVE-2026-75975#195
independabot-soc2[bot] wants to merge 1 commit into
mainfrom
independabot/fast-uri-CVE-2026-75931

Conversation

@independabot-soc2

Copy link
Copy Markdown
Contributor

Hi, this is independabot — not Lili! You can ask her if you have questions, but she had no hand in generating this PR other than setting up the independabot schedule.

Please merge this PR yourself, if you approve.

BEFORE YOU MERGE

Instructions for resolving the vuln — test to make sure that nothing is broken, check compatibility, etc.

Bumped transitive dependency fast-uri (pulled in via ajv) from 3.1.5 to 3.1.6 via a package.json overrides entry, matching the existing brace-expansion override pattern. Dependabot could not auto-update this itself (update_not_possible error on all 4 alerts) due to the transitive nature of the dependency, so this batches all 4 open fast-uri alerts into a single override-based fix.

Highlight the risky code / where the dependency was used

fast-uri is a dev-only, transitive dependency of ajv (used by ts-loader/webpack tooling in build_ts). It is not used by any runtime/production code path, so compatibility risk is low.

Special instructions for this PR — e.g. if it's a Stainless thing

None. Standard overrides bump.

AFTER YOU MERGE

None.

@independabot-soc2

Copy link
Copy Markdown
Contributor Author

This PR was generated with Warp.

Comment @warp-agent on this PR to send it follow-up work.

@vorporeal vorporeal closed this Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants