Skip to content

chore(deps): bump fast-uri from 3.1.2 to 4.1.1 in /test-projects/expo-purchasely-test - #264

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/test-projects/expo-purchasely-test/fast-uri-4.1.1
Open

chore(deps): bump fast-uri from 3.1.2 to 4.1.1 in /test-projects/expo-purchasely-test#264
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/test-projects/expo-purchasely-test/fast-uri-4.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.1.2 to 4.1.1.

Release notes

Sourced from fast-uri's releases.

v4.1.1

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v4.1.0...v4.1.1

v4.1.0

What's Changed

Full Changelog: fastify/fast-uri@v4.0.1...v4.1.0

v4.0.1

⚠️ Security Release

What's Changed

New Contributors

Full Changelog: fastify/fast-uri@v4.0.0...v4.0.1

v4.0.0

What's Changed

Full Changelog: fastify/fast-uri@v3.1.2...v4.0.0

v3.1.4

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v3.1.3...v3.1.4

v3.1.3

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 4.1.1.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.2...v4.1.1)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 4.1.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 24, 2026
@greptile-apps

greptile-apps Bot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

PR author is in the excluded authors list.

Copy link
Copy Markdown

Dependabot PR Review — 2026-07-25 (research only, no merges/approvals taken this run)

Note: GitHub Issues are disabled on this repository, so this comment thread substitutes for the usual cross-repo Dependabot tracking issue. Posting the full batch summary here (on the lowest/most-attention-needing PR) and cross-linking from the other four.

Summary

5 open Dependabot PRs, all npm_and_yarn/javascript, all green CI across the full matrix (lint, test, build-android, build-ios, build-rn-0-86-android/ios, iOS Unit Tests). No hold labels. mergeable_state: blocked on all five (pending-review branch protection, not a conflict — each PR has exactly 1 comment, the automated Dependabot body) — no ·@·d·ependabot r·ebase needed.

# Package Version Change Bump Scope CI Action
#264 (this PR) fast-uri 3.1.2 → 4.1.1 Major /test-projects/expo-purchasely-test (dev/test-only) 🟢 Green Needs human sign-off (major, but low risk — see notes)
#265 fast-xml-parser 5.10.0 → 5.10.1 Patch /test-projects/rn-purchasely-test (dev/test-only) 🟢 Green Auto-merge candidate
#266 shell-quote 1.8.4 → 1.10.0 Minor root 🟢 Green Auto-merge candidate — security fix
#267 body-parser 1.20.5 → 1.20.6 Patch root 🟢 Green Auto-merge candidate — security fix
#268 shell-quote 1.8.4 → 1.10.0 Minor /test-projects/expo-purchasely-test (dev/test-only) 🟢 Green Auto-merge candidate — security fix (duplicate of #266 for a different directory)

Changelog analysis

No merge conflicts, no config changes needed.

Ask

@kherembourg — assigning for visibility as the most recently active human contributor on this repo. Reply here to confirm auto-merging #265/#266/#267/#268 (and optionally the low-risk major #264), or to hold/override any of them. No PRs in this batch were merged or approved this run.


Generated by Claude Code

Copy link
Copy Markdown

Automated Dependabot review (2026-07-26) — research only, no merge/approve action taken.

Major bump (3.1.2 → 4.1.1), test-projects/expo-purchasely-test. Flagging as major per policy, but this is itself a security release (GHSA-v2hh-gcrm-f6hx) and the dependency is scoped to a test project only — not shipped in any published react-native-purchasely* package. Changelog across 3.x→4.x shows internal refactors (types migration to tstyche, RFC 3986 percent-encoding/scheme-normalization fixes) with no documented breaking API removals. CI green across all 7 checks. No hold label, no merge conflicts.

Note: issues are disabled on this repo, so this review is posted as PR comments (see also #267, #266, #268, #265, #269) rather than a single tracking issue.

@kherembourg — major bump, needs your explicit sign-off per policy even though blast radius looks limited to the test project. Reply here to confirm, hold, or override.

Related: #267, #266, #268, #265, #269


Generated by Claude Code

Copy link
Copy Markdown

Dependabot PR Review — 2026-07-27

Issues are disabled on this repo, so posting the review summary here instead of a tracking issue (cross-linking the batch: #269, #268, #267, #266, #265, #264). This is a research-only pass — nothing has been approved or merged.

First Dependabot review cycle for this repo. 6 open Dependabot PRs, all in test-projects/ or repo-root, mostly patch/minor with one major (security-driven). 5 of 6 are CI-green:

# Package Version Change Bump CI Action
#269 postcss (/test-projects/expo-purchasely-test) 8.5.12 → 8.5.23 patch 🔴 build-ios failing CI failing — needs investigation
#268 shell-quote (/test-projects/expo-purchasely-test) 1.8.4 → 1.10.0 minor 🟢 green Auto-merge candidate — awaiting confirmation
#267 body-parser (root) 1.20.5 → 1.20.6 patch (security fix) 🟢 green Auto-merge candidate — awaiting confirmation
#266 shell-quote (root) 1.8.4 → 1.10.0 minor 🟢 green Auto-merge candidate — awaiting confirmation
#265 fast-xml-parser (/test-projects/rn-purchasely-test) 5.10.0 → 5.10.1 patch 🟢 green Auto-merge candidate — awaiting confirmation
#264 (this PR) fast-uri (/test-projects/expo-purchasely-test) 3.1.2 → 4.1.1 major (security fix) 🟢 green Review changelog — see notes

Notes:

No repo-level default merge method could be determined via the available tools — flagging for whoever confirms this to state a preference (squash is GitHub's common default).

@kherembourg — flagging for visibility as the most recently active human contributor on this repo. Reply here (or on the respective PRs) to confirm auto-merging #268/#267/#266/#265, whether to merge #264 despite the major bump (security fix, low risk per above), and whether to investigate or hold #269's build-ios failure.

No PRs in this batch were merged or approved.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot PR Review — 2026-07-28 (6 open PRs)

Note: this repo has GitHub Issues disabled, so this tracking summary is posted here (the major-version bump, which needs the most scrutiny) instead of a standalone issue. Cross-posted as a link on the other 5 PRs.

6 open Dependabot PRs across the monorepo (root + test-projects/expo-purchasely-test + test-projects/rn-purchasely-test). None carry a hold/do-not-merge label. All are dependency-only diffs (1-2 files, single commit).

PR # Package Location Version Change Bump CI Action
#269 postcss test-projects/expo-purchasely-test 8.5.12 → 8.5.23 patch ⚠️ build-ios failed, other 6 checks green Investigate CI failure before merging (likely unrelated flake — postcss is a transitive devDependency of the Expo test project, not linked to the native iOS build)
#268 shell-quote test-projects/expo-purchasely-test 1.8.4 → 1.10.0 minor ✅ 7/7 green Merge
#267 body-parser root 1.20.5 → 1.20.6 patch (security) ✅ 7/7 green Merge
#266 shell-quote root 1.8.4 → 1.10.0 minor ✅ 7/7 green Merge
#265 fast-xml-parser test-projects/rn-purchasely-test 5.10.0 → 5.10.1 patch ✅ 7/7 green Merge
#264 (this PR) fast-uri test-projects/expo-purchasely-test 3.1.2 → 4.1.1 major ✅ 7/7 green Review changelog below, then merge if acceptable

All PRs currently show mergeable_state: blocked (branch protection / review requirement), not merge conflicts.

Changelog analysis — major bump (this PR, fast-uri 3.1.2 → 4.1.1)

Only v4.0.0 in this range introduces breaking changes:

  • Type system overhaul: types migrated from tsd to tstyche; deprecated TS types were removed. Affects TypeScript consumers relying on the old deprecated type exports, not runtime JS behavior.
  • Escape/normalization fixes (v4.0.0–v4.1.1): lowercase scheme normalization, percent-encoding normalization in query/fragment, trailing empty path segment preservation — behavior-correcting, not functionality-removing.
  • Two security releases bundled in this range: GHSA-4c8g-83qw-93j6 (v4.0.1) and GHSA-v2hh-gcrm-f6hx (v4.1.1).

fast-uri is a transitive dependency (via ajv) inside a test-project's devDependency tree, not shipped in the published SDK packages, so blast radius for the RN library itself is minimal. CI is green. Flagging the major bump per policy rather than assuming it's safe.

Security notes

Contributor

@kherembourg is the sole active human contributor on this repo over the recent commit history (all recent commits, including the v6 migration merge, are authored by them). Flagging for review/confirmation.

Next steps

Waiting for human confirmation via comments before taking any merge/rebase action. Please confirm:

  1. Whether to proceed with the 4 straightforward merges (chore(deps): bump shell-quote from 1.8.4 to 1.10.0 in /test-projects/expo-purchasely-test #268, chore(deps): bump body-parser from 1.20.5 to 1.20.6 #267, chore(deps): bump shell-quote from 1.8.4 to 1.10.0 #266, chore(deps): bump fast-xml-parser from 5.10.0 to 5.10.1 in /test-projects/rn-purchasely-test #265).
  2. Whether this fast-uri major bump is acceptable to merge as-is.
  3. Whether to investigate/rebase chore(deps): bump postcss from 8.5.12 to 8.5.23 in /test-projects/expo-purchasely-test #269 given its failing build-ios check, or wait for a rebase to see if it clears.

Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant