Skip to content

Patch qs and fast-uri to close Dependabot alerts - #223

Merged
wasimxyz merged 1 commit into
stagingfrom
chore/npm-audit-fix
Sep 4, 2026
Merged

Patch qs and fast-uri to close Dependabot alerts#223
wasimxyz merged 1 commit into
stagingfrom
chore/npm-audit-fix

Conversation

@wasimxyz

@wasimxyz wasimxyz commented Sep 4, 2026

Copy link
Copy Markdown
Member

Summary

  • Apply npm audit fix in web/package-lock.json: qs 6.15.2 → 6.16.0 and fast-uri 3.1.5 → 3.1.7 (plus the side-channel transitives qs pulled in).
  • Closes the open Dependabot alerts on those packages (GHSA-x5fp-wj9c-mxmx and the fast-uri 3.1.6+ advisories, including the 3.1.7 port-injection fix).
  • Leaves @better-auth/oauth-provider on 1.6. npm audit fix --force would jump it to 1.7, which we rolled back in Roll Better Auth back to 1.6 so MCP clients can register #218 because MCP clients could not register.

Test plan

  • CI make check / web install from the updated lockfile
  • Confirm the qs and fast-uri Dependabot alerts auto-close after merge

Made with Cursor

Patches transitive qs and fast-uri so the open Dependabot alerts close.
Leaves Better Auth on 1.6 because that upgrade needs --force.

Co-authored-by: Cursor <cursoragent@cursor.com>
@vercel

vercel Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
data-hub Ready Ready Preview Sep 4, 2026 5:49pm UTC

Request Review

@wasimxyz wasimxyz self-assigned this Sep 4, 2026
@wasimxyz
wasimxyz merged commit 24e2368 into staging Sep 4, 2026
4 checks passed
@wasimxyz
wasimxyz deleted the chore/npm-audit-fix branch September 4, 2026 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant