chore(deps): bump fastify from 5.8.3 to 5.8.5 in the npm-security group across 1 directory#3152
chore(deps): bump fastify from 5.8.3 to 5.8.5 in the npm-security group across 1 directory#3152dependabot[bot] wants to merge 2 commits intomainfrom
Conversation
Bumps the npm-security group with 1 update in the / directory: [fastify](https://github.com/fastify/fastify). Updates `fastify` from 5.8.3 to 5.8.5 - [Release notes](https://github.com/fastify/fastify/releases) - [Commits](fastify/fastify@v5.8.3...v5.8.5) --- updated-dependencies: - dependency-name: fastify dependency-version: 5.8.5 dependency-type: direct:production dependency-group: npm-security ... Signed-off-by: dependabot[bot] <support@github.com>
size-limit report 📦
|
…rn/npm-security-dd6aeadc3f * origin/main: (34 commits) fix(pro-dummy): make manual node-renderer validation reliable (#3200) [codex] Add Markdown Prettier CI check (#3242) Add /stress-test Claude Code command for adversarial QA (#3207) Document examples catalog and naming plan (#3191) test(dummy): enable StrictMode in OSS and Pro dummies (#3206) ci: exclude bot-blocking URLs from lychee link check (#3214) Remove stale Coveralls integration (#3204) docs: normalize external GitHub repo slugs in links and generators (#3198) docs: add Example Migrations page (#3125) (#3197) docs: warn about react_component helper collision with react-rails (#3143) (#3160) docs: legacy Webpacker and migration-fit guidance (#3138) (#3157) fix(specs): boot dummy specs without readline and drop redundant pnpm workspace (#3190) docs: add RSC migration success stories page (#1985) (#3162) Fix Bencher reporting permanently broken on pushes to main (#3148) docs: add example migrations guide (#3126) docs: remove defunct guavapass.com reference (#3199) chore: remove redundant --rsc-pro install generator flag (#3105) ci: warn (don't fail) on Bencher main regression (#3168) test: enable RSpec --profile to surface slowest package tests (#3176) fix(node-renderer): expose performance in VM context when supportModules (#3158) ...
Code Review: fastify 5.8.3 → 5.8.5 Security BumpVerdict: Approve and merge. This is a clean, low-risk security patch with a clear upstream CVE. What This PR DoesBumps The vulnerability is in fastify's AssessmentSecurity impact is real but limited in this codebase. Diff is correct and minimal.
No breaking changes. 5.8.3 → 5.8.5 is a patch release; the Dependabot compatibility score supports no regressions. One Follow-Up Item (not blocking)The updated basic-ftp@5.2.0:
deprecated: Security vulnerability fixed in 5.2.1, please upgradeThis is not introduced by this PR, but it is now visible. A separate Dependabot PR for whichever package pulls in |
Bumps the npm-security group with 1 update in the / directory: fastify.
Updates
fastifyfrom 5.8.3 to 5.8.5Release notes
Sourced from fastify's releases.
Commits
3983cceBumped v5.8.53ce3ae6Merge commit from forkb06a196docs(ecosystem): add@pompelmi/fastify-plugin(#6610)909c5d5chore: Bump actions/dependency-review-action from 4.8.3 to 4.9.0 (#6630)4db21a3chore: Bump borp from 0.21.0 to 1.0.0 (#6633)0f4e544chore: Bump markdownlint-cli2 from 0.21.0 to 0.22.0 (#6632)33a2fcdchore: Bump pnpm/action-setup from 4.2.0 to 5.0.0 (#6629)fd35d82ci: reduce cron schedules from daily/weekly to monthly (#6623)8dee9befix: restore trustProxy function for number and string types, add null check ...d457aedchore: upgrade to typescript v6.0.2 (#6605)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.