Skip to content

chore(deps): bump fast-uri from 2.4.4 to 2.4.6 - #2167

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-2.4.6
Open

chore(deps): bump fast-uri from 2.4.4 to 2.4.6#2167
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fast-uri-2.4.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 2.4.4 to 2.4.6.

Release notes

Sourced from fast-uri's releases.

v2.4.6

⚠️ Security Warning

This is a security release that fixes the following high-severity security advisories:

Users of the v2.x release line should upgrade to v2.4.6.

Full Changelog: fastify/fast-uri@v2.4.5...v2.4.6

v2.4.5

⚠️ Security Warning

This release addresses the following high-severity security advisories:

Users of the v2.x release line should upgrade to v2.4.5.

Full Changelog: fastify/fast-uri@v2.4.4...v2.4.5

Commits
  • ccd1f8d Bumped v2.4.6
  • 812bd8e fix: backport port and IP-literal validation to v2.x (#215)
  • 134064e fix: treat unterminated bracket hosts as reg-names again (#214)
  • 21e274e Bumped v2.4.5
  • c04a58d fix: never run IDN canonicalization on bracketed IP literals
  • 10ab491 fix(ci): declare tape in devDependencies
  • a941e62 Merge commit from fork
  • 9161ede Merge commit from fork
  • 8c15dbe Merge commit from fork
  • 0256bc8 Merge commit from fork
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 2, 2026
@dependabot
dependabot Bot deployed to test-trigger-is September 2, 2026 17:58 Active
@rugpanov

rugpanov commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

🤖 Integration tests ❌ 3 of 4 test jobs failed for b79713eb (0 passed, 1 skipped).
View run

@rugpanov

rugpanov commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Not merging until the JFrog db-npm mirror serves fast-uri@2.4.6. The failing checks are all the same yarn install error — YN0035: fast-uri@npm:2.4.6: 403 (Forbidden) — because the mirror hasn't ingested 2.4.6 yet, not a code issue. The bump itself is fine (transitive, in-range, security patch; lockfile-only). Once the mirror has it, re-run CI / @dependabot rebase and merge.

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 2.4.4 to 2.4.6.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v2.4.4...v2.4.6)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 2.4.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/fast-uri-2.4.6 branch from b79713e to 46c5580 Compare September 3, 2026 15:02
@dependabot
dependabot Bot deployed to test-trigger-is September 3, 2026 15:02 Active
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

If integration tests don't run automatically, an authorized user can run them manually by following the instructions below:

Trigger:
go/deco-tests-run/vscode

Inputs:

  • PR number: 2167
  • Commit SHA: 46c5580f52f30fa553cc369e5f8f6139240edf3f

Checks will be approved automatically on success.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant