Skip to content

fix: update fast-uri to resolve CVE-2026-13676 and CVE-2026-16221 - #23

Open
independabot-soc2[bot] wants to merge 1 commit into
mainfrom
independabot/fast-uri-CVE-2026-16221
Open

fix: update fast-uri to resolve CVE-2026-13676 and CVE-2026-16221#23
independabot-soc2[bot] wants to merge 1 commit into
mainfrom
independabot/fast-uri-CVE-2026-16221

Conversation

@independabot-soc2

Copy link
Copy Markdown
Contributor

Hi, this is independabot — not Lili! You can ask her if you have questions, but she had no hand in generating this PR other than setting up the independabot schedule.

Please merge this PR yourself, if you approve.

BEFORE YOU MERGE

Instructions for resolving the vuln — test to make sure that nothing is broken, check compatibility, etc.

Updated transitive dependency fast-uri (pulled in via ajv, used by @modelcontextprotocol/sdk, ajv-formats, and @prisma/streams-local) via an overrides entry in package.json, since it's not a direct dependency.

Highlight the risky code / where the dependency was used

fast-uri is a URI parsing helper used internally by ajv (JSON schema validation). It's not called directly from application code, so risk of behavior change is low. ajv is a dependency of @modelcontextprotocol/sdk, ajv-formats, and @prisma/streams-local.

Special instructions for this PR

None — straightforward transitive dependency bump via overrides.

AFTER YOU MERGE

None.

Automated by independabot.

Co-Authored-By: Oz oz-agent@warp.dev

Co-Authored-By: Oz <oz-agent@warp.dev>
@independabot-soc2
independabot-soc2 Bot requested review from dplakon and liliwilson and removed request for liliwilson August 3, 2026 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant