Skip to content

fix: upgrade fast-uri to 3.1.2 to address CVE-2026-6321 and CVE-2026-…#8731

Merged
rohitsaw115 merged 1 commit into
masterfrom
CGD-1102-upgrade-vulnerable-dependencies
May 11, 2026
Merged

fix: upgrade fast-uri to 3.1.2 to address CVE-2026-6321 and CVE-2026-…#8731
rohitsaw115 merged 1 commit into
masterfrom
CGD-1102-upgrade-vulnerable-dependencies

Conversation

@yashvanthbl137-crypto
Copy link
Copy Markdown
Contributor

Ticket: CGD-1102

@linear-code
Copy link
Copy Markdown

linear-code Bot commented May 11, 2026

CGD-1102

@yashvanthbl137-crypto yashvanthbl137-crypto marked this pull request as ready for review May 11, 2026 09:29
@yashvanthbl137-crypto yashvanthbl137-crypto requested a review from a team as a code owner May 11, 2026 09:29
Copy link
Copy Markdown

@diksha190 diksha190 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving from a security perspective.

This PR correctly remediates CVE-2026-6321 (CVSS 7.5 - High).

Fix Validation:

  • Uses Yarn resolutions to force fast-uri@3.1.2 across all dependencies
  • Lockfile correctly updated with patched version + integrity hash
  • All 22 CI checks passed (no breaking changes)
  • Follows repo's existing security override pattern

@yashvanthbl137-crypto yashvanthbl137-crypto requested a review from a team May 11, 2026 09:56
@yashvanthbl137-crypto yashvanthbl137-crypto removed the request for review from a team May 11, 2026 10:03
@rohitsaw115 rohitsaw115 merged commit c20d504 into master May 11, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants