chore(deps): consolidated dep bumps + fast-uri security fix (CVE-2026-6321, CVE-2026-6322)#108
Conversation
…e, fast-uri - codeql-action v3: 0daab03 → 68bde55 (3.35.3 → 3.35.4) - dependency-review-action v4: 2031cfc → a1d282b (4.9.0 → 5.0.0) - @types/node: 25.6.0 → 25.6.2 - fast-uri: 3.1.0 → 3.1.2 (closes CVE-2026-6321, CVE-2026-6322)
|
ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThis PR updates GitHub Actions workflow pins in two workflow files. The CodeQL workflow pins the ChangesWorkflow Configuration Updates
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
github/codeql-actionv3:0daab03→68bde55(3.35.3 → 3.35.4) — closes PR chore(deps): bump github/codeql-action from 3.35.3 to 4.35.4 #105actions/dependency-review-actionv4:2031cfc→a1d282b(4.9.0 → 5.0.0) — closes PR chore(deps): bump actions/dependency-review-action from 4.9.0 to 5.0.0 #106@types/node: 25.6.0 → 25.6.2 — closes PR chore(deps-dev): bump @types/node from 25.6.0 to 25.6.2 in /server #107fast-uri: 3.1.0 → 3.1.2 — addresses CVE-2026-6321 (path traversal, CVSS 7.5) and CVE-2026-6322 (host confusion, CVSS 7.5) via transitive update throughfastify → @fastify/ajv-compilerandfastify → fast-json-stringifyTest plan
npm test— 1641 passing, 0 failuresnpx tsc --noEmit— cleannpm audit— 0 vulnerabilities after updateSummary by CodeRabbit