Skip to content

chore: upgrade fast-uri to ^3.1.8 to address CVE-2026-86472 - #1701

Open
claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/fast-uri-2026-09
Open

claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/fast-uri-2026-09

Conversation

@claude

@claude claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Fixes SOU-2388

Summary

Refreshes the yarn.lock entry for the transitive dependency fast-uri from 3.1.7 to 3.1.8 (requested by ajv@8.18.0 via ^3.1.2).

The existing range already admits the patched version, so this is a lockfile-only refresh via yarn up -R fast-uri. No package.json changes or resolutions overrides.

Note: the conventional cursor/cve/fast-uri branch name is still held by a stale branch from merged PRs (#1626, #1541), so this PR uses cursor/cve/fast-uri-2026-09.

Verification

  • yarn why fast-uri: the only instance resolves to fast-uri@npm:3.1.8.
  • yarn workspace @sourcebot/backend test: 309 passed.
  • yarn workspace @sourcebot/web test: 1506 passed.

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only transitive dependency patch with no application code changes; existing semver range already allowed 3.1.8.

Overview
Bumps the transitive dependency fast-uri from 3.1.7 to 3.1.8 via a yarn.lock refresh only (no package.json or resolution overrides). This picks up the fix for CVE-2026-86472 (inconsistent host case normalization for percent-encoded uppercase octets in scheme-relative URIs).

The [Unreleased] changelog Fixed section documents the upgrade.

Reviewed by Cursor Bugbot for commit d9cba3d. Bugbot is set up for automated code reviews on this repo. Configure here.

github-actions Bot and others added 2 commits September 30, 2026 14:27
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 54485638-5f23-49dc-8f9e-474383ccfbe6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants