Skip to content

Bump fast-uri 3.1.2 → 3.1.5 (host confusion — GHSA-v2hh-gcrm-f6hx / GHSA-4c8g-83qw-93j6) - #62

Merged
sevgibson merged 1 commit into
masterfrom
security/fast-uri-3.1.5
Aug 3, 2026
Merged

Bump fast-uri 3.1.2 → 3.1.5 (host confusion — GHSA-v2hh-gcrm-f6hx / GHSA-4c8g-83qw-93j6)#62
sevgibson merged 1 commit into
masterfrom
security/fast-uri-3.1.5

Conversation

@sevgibson

Copy link
Copy Markdown
Contributor

Why

High: two fast-uri host-confusion advisories (issue #61, due 2026-08-24 — soonest of the assigned vulns):

Fix

fast-uri is a transitive dependency (range ^3.0.1), so this is a lockfile-only bump — re-resolved to the latest 3.x (3.1.5), clearing both advisories (patched 3.1.3 / 3.1.4). package.json is untouched (fast-uri stays transitive).

Closes #61.

🤖 Generated with Claude Code

…HSA-4c8g-83qw-93j6)

Security patch for the two fast-uri host-confusion advisories
(GHSA-v2hh-gcrm-f6hx literal-backslash authority delimiter, and
GHSA-4c8g-83qw-93j6 failed IDN canonicalization; issue #61). fast-uri is a
transitive dep (range ^3.0.1); re-resolved to the latest 3.x (3.1.5), which
clears both. yarn.lock-only — package.json is untouched.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@sevgibson
sevgibson requested a review from jlocke2 August 3, 2026 16:56
@sevgibson

Copy link
Copy Markdown
Contributor Author

@claude Please review?

@sevgibson
sevgibson merged commit 57c7623 into master Aug 3, 2026
1 check passed
@sevgibson
sevgibson deleted the security/fast-uri-3.1.5 branch August 3, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

⚠️ HIGH security issue [dependabot:npm/fast-uri] in fast-uri

2 participants