Skip to content

chore(deps): bump fast-uri from 3.1.6 to 3.1.8 - #69

Merged
nxn94 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.8
Sep 29, 2026
Merged

nxn94 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-3.1.8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.1.6 to 3.1.8.

Release notes

Sourced from fast-uri's releases.

v3.1.8

⚠️ Security Warning

This security release fixes the following medium-severity security advisory:

Users of the v3.x release line should upgrade to v3.1.8.

Full Changelog: fastify/fast-uri@v3.1.7...v3.1.8

v3.1.7

⚠️ Security Warning

This is a security release that fixes the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.7.

Full Changelog: fastify/fast-uri@v3.1.6...v3.1.7

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.6 to 3.1.8.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.6...v3.1.8)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from nxn94 as a code owner September 28, 2026 23:49
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
nxn94 added a commit that referenced this pull request Sep 29, 2026
* fix(security): sanitise verifyUrl URL through new URL() + require https

Resolves CodeQL alert #37 (js/file-access-to-http in
unified-downloader.js @ 283). The HEAD-probe took a URL string that
originated from a file read (cache.js or config.js download_urls)
and passed it straight into fetch() — the taint flow was real
even though the cache file is operationally only written by this
module from successful resolver round-trips.

Fix: parse the URL through the WHATWG URL parser (new URL()) and
require protocol === 'https:', then pass parsed.toString() to
fetch. new URL() is the CodeQL-recognised sanitiser for this query
— the file -> fetch edge becomes string -> parsed URL ->
re-stringified URL -> fetch, and the protocol gate blocks any
non-https scheme that might have landed there via a tampered cache
file or a misauthored config.json entry.

Tests:
  - unified-downloader-timers.test.js: 4 new cases covering
    http://, file://, malformed, and the canonical https: accept
    path. fetch is asserted NOT to have been called for any
    non-https / malformed input.
  - fallback-chain.test.js: replaced the file:// cache fixture
    URL with https://example.invalid/... (verifyUrl now rejects
    file://). Replaced the real-curl spawnImpl with a shim that
    copies the placeholder fixture so the test no longer depends
    on curl's file:// support or network egress for example.invalid.

Docs:
  - AGENTS.md 'Repo quirks': new bullet on the verifyUrl
    sanitisation contract.
  - docs/troubleshooting.md: new 'verifyUrl rejects the cached URL'
    section covering the operator-visible behaviour (non-https
    URLs now log a rejection and the resolver falls through).

* fix(deps): pin undici override >= 7.29.1 (closes Dependabot alert #12)

CVE-2026-85024 / GHSA-3wwx-pv78v: undici's WebSocket client crashes
the entire Node.js process on a malformed DEFLATE block after a
permessage-deflate size limit (CWE-248 uncaught exception, CVSS 5.9).

We don't use undici's WebSocket client directly (no new WebSocket()
call in our source). cheerio 1.2.0 depends on undici ^7.19.0 and
its npm-published resolution landed on the vulnerable 7.29.0. Pin
undici to ^7.29.1 via package.json overrides, same pattern already
used for brace-expansion, minimatch, and js-yaml (closes prior
Dependabot alerts). Lockfile now resolves undici to 7.30.0 (the
patched line is >= 7.29.1).

Dependabot opened a separate PR (#69) to fix the related fast-uri
CVE-2026-84394; that will be merged onto main after this branch
lands.

---------

Co-authored-by: nxn (via Hermes) <nxn@openclaw.local>
@nxn94
nxn94 merged commit bca4289 into main Sep 29, 2026
5 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/fast-uri-3.1.8 branch September 29, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant