Skip to content

security: pin fast-uri to 3.1.7 - #1311

Merged
michalharakal merged 1 commit into
developfrom
security/fast-uri-3.1.7
Sep 29, 2026
Merged

michalharakal merged 1 commit into
developfrom
security/fast-uri-3.1.7

Conversation

@michalharakal

Copy link
Copy Markdown
Contributor

Bumps the npm-fast-uri pin (sk.ainet.npm-pins, JS-scoped) from 3.1.6 to 3.1.7 and regenerates kotlin-js-store/yarn.lock via kotlinUpgradeYarnLock.

Fixes Dependabot alerts #137 (GHSA-58mr-gqgx-xq4g) and #138 (GHSA-qw65-cvwx-89v3). verifyNpmPins passes.

fast-uri 3.1.6 is affected by GHSA-58mr-gqgx-xq4g (host confusion via
an unclosed bracket in the URI authority) and GHSA-qw65-cvwx-89v3
(authority injection via an unvalidated port in serialize); 3.1.7
fixes both. Bump the NpmPinTarget.JS pin and regenerate
kotlin-js-store/yarn.lock via kotlinUpgradeYarnLock; verifyNpmPins
passes.
@michalharakal
michalharakal merged commit 4ef3295 into develop Sep 29, 2026
14 checks passed
@michalharakal
michalharakal deleted the security/fast-uri-3.1.7 branch September 29, 2026 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants