Skip to content

chore(deps): bump fast-uri from 3.1.3 to 3.1.7 in /packages/gateway - #5

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/gateway/fast-uri-3.1.7
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/packages/gateway/fast-uri-3.1.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown

Bumps fast-uri from 3.1.3 to 3.1.7.

Release notes

Sourced from fast-uri's releases.

v3.1.7

⚠️ Security Warning

This is a security release that fixes the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.7.

Full Changelog: fastify/fast-uri@v3.1.6...v3.1.7

v3.1.6

⚠️ Security Warning

This release addresses the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.6.

Full Changelog: fastify/fast-uri@v3.1.5...v3.1.6

v3.1.5

⚠️ Security Warning

Fix for GHSA-7p8r-x3mc-p8w7

Full Changelog: fastify/fast-uri@v3.1.4...v3.1.5

v3.1.4

⚠️ Security Release

Fix for GHSA-v2hh-gcrm-f6hx

Full Changelog: fastify/fast-uri@v3.1.3...v3.1.4

Commits
  • 412e40a Bumped v3.1.7
  • 9f4c943 fix: backport port and IP-literal validation to v3.x (#216)
  • 1eb3ce4 fix: treat unterminated bracket hosts as reg-names again (#214)
  • 6f970b2 Bumped v3.1.6
  • d941579 fix: never run IDN canonicalization on bracketed IP literals
  • c0f0279 test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)
  • 37f3417 Merge commit from fork
  • 607bfbe Merge commit from fork
  • ae92a4c Merge commit from fork
  • 444ecda Merge commit from fork
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.3 to 3.1.7.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.3...v3.1.7)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 2, 2026
@sonarqubecloud

sonarqubecloud Bot commented Sep 2, 2026

Copy link
Copy Markdown

@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Author

Superseded by #16.

@dependabot dependabot Bot closed this Oct 1, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/packages/gateway/fast-uri-3.1.7 branch October 1, 2026 05:59
ucchino pushed a commit to ucchino/console that referenced this pull request Oct 2, 2026
ucchino pushed a commit to ucchino/console that referenced this pull request Oct 2, 2026
WHATS_MISSING_2 off-grid-ai#5: ZERO fairness or bias checks existed, on a tenant whose live
apps underwrite personal loans and assess death claims. Three quality checks per
pipeline cover grounding, relevance and PII; none asked whether outcomes skew by
any attribute. For credit decisions this is the exposure a regulator opens with.

The measurement is the one lending regulators use: each group's selection rate
against the best-performing group, with the four-fifths (0.8) ratio as the screen.
It is a SCREEN, not a verdict - below 0.8 means "explain this", and the copy says
so rather than asserting discrimination.

What it refuses to do matters more than what it does. A fairness number from a
handful of cases is worse than none, because it gets quoted:
- a group under 20 decided cases is reported untestable and never scored;
- a protected attribute absent from the data is reported ABSENT, never imputed -
  inferring gender or religion from a name to audit fairness would create the
  profiling the audit exists to prevent;
- an attribute with near-unique values is refused as an identifier, not reported
  as a disparity per person (this fired on real data: cost_centre and expense_type
  are near-unique on this tenant);
- a FAILED run is excluded rather than counted as a decline, because counting a
  crash as an adverse outcome invents adverse impact out of an outage;
- "nobody approved anywhere" is ratio 1, not a false flag from 0/0.

Filed, not just computed. A control that has never run is not a control - the same
lesson retention taught - so a check is RUN and RETAINED with its whole report,
including the untestable findings, because "we looked on this date and could not
yet test gender" is the defensible position.

Ran it live on all four decisioning apps across both tenants. Every one honestly
reports UNTESTED rather than clear (3-10 decided cases each), names the six
protected attributes absent from the records, and states the REMEDY - the decision
record has to carry them. Without that last part a reader concludes the platform
cannot do fairness, when in fact the decisions simply do not carry the fields.

9 tests cover the arithmetic the live data cannot yet exercise: a real 0.44 ratio
flagged, even rates passing, under-minimum groups unscored, identifiers refused,
the 0/0 edge, absent attributes, and coverage.
ucchino pushed a commit to ucchino/console that referenced this pull request Oct 2, 2026
WHATS_MISSING_2 off-grid-ai#5 (fairness), off-grid-ai#11 (both controls exercised) and the priority
ordering updated with live evidence.

The access review closure is the one worth reading: completing it for real on both
tenants exercised the rule shipped earlier today, and the refusal is the proof.
Submitting a review that KEEPS the flagged never-signed-in admin without a written
justification is rejected live with "full admin access and has never signed in —
say why this access is being kept". Before that, the artefact's worst line was its
only silent one.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants