Skip to content

Bump the npm_and_yarn group across 2 directories with 4 updates - #108

Merged
dodok8 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-2a4808fa1e
Oct 6, 2026
Merged

dodok8 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-2a4808fa1e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the npm_and_yarn group with 4 updates in the / directory: seroval, @fastify/busboy, devalue and source-map-js.
Bumps the npm_and_yarn group with 4 updates in the /packages/web directory: seroval, @fastify/busboy, devalue and source-map-js.

Updates seroval from 1.5.4 to 1.6.3

Release notes

Sourced from seroval's releases.

1.5.5

  • fix: streaming serialization cleanup (#77)
  • fix: preserve own proto properties through serialize (#81)
  • fix: preserve circular own proto properties through deferred assignment (#82)
  • fix: use element length for bigint typed array views (#83)
  • fix: unescape regexp source in the serialized output (#84)

Credits to @​spokodev and @​greymoth-jp

Commits

Updates @fastify/busboy from 3.2.0 to 3.2.2

Release notes

Sourced from @​fastify/busboy's releases.

v3.2.2

⚠️ Security Release

Fix for GHSA-gxm5-99cw-xjw9

v3.2.1 - Security release

This is a security release for @fastify/busboy.

It addresses the following security advisories:

Users should upgrade to v3.2.1.

Full Changelog: fastify/busboy@v3.2.0...v3.2.1

Commits
  • 4e8de12 Bumped v3.2.2
  • cc7da17 Merge commit from fork
  • b404d60 Bumped v3.2.1
  • 4c872cf gitignore ai stuff
  • 632a237 Merge commit from fork
  • 957a24b Merge commit from fork
  • d515ff4 chore(.npmrc): add min-release-age
  • 0e2b3ba chore: bump fastify/workflows/.github/workflows/plugins-ci.yml (#226)
  • 733ee94 chore: bump fastify/workflows/.github/workflows/lock-threads.yml (#225)
  • a3d075e test: cover multipart stream resume callback (#223)
  • Additional commits viewable in compare view

Updates devalue from 5.9.2 to 5.9.4

Release notes

Sourced from devalue's releases.

v5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

v5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Changelog

Sourced from devalue's changelog.

5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Commits

Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Updates seroval from 1.5.4 to 1.6.3

Release notes

Sourced from seroval's releases.

1.5.5

  • fix: streaming serialization cleanup (#77)
  • fix: preserve own proto properties through serialize (#81)
  • fix: preserve circular own proto properties through deferred assignment (#82)
  • fix: use element length for bigint typed array views (#83)
  • fix: unescape regexp source in the serialized output (#84)

Credits to @​spokodev and @​greymoth-jp

Commits

Updates @fastify/busboy from 3.2.0 to 3.2.2

Release notes

Sourced from @​fastify/busboy's releases.

v3.2.2

⚠️ Security Release

Fix for GHSA-gxm5-99cw-xjw9

v3.2.1 - Security release

This is a security release for @fastify/busboy.

It addresses the following security advisories:

Users should upgrade to v3.2.1.

Full Changelog: fastify/busboy@v3.2.0...v3.2.1

Commits
  • 4e8de12 Bumped v3.2.2
  • cc7da17 Merge commit from fork
  • b404d60 Bumped v3.2.1
  • 4c872cf gitignore ai stuff
  • 632a237 Merge commit from fork
  • 957a24b Merge commit from fork
  • d515ff4 chore(.npmrc): add min-release-age
  • 0e2b3ba chore: bump fastify/workflows/.github/workflows/plugins-ci.yml (#226)
  • 733ee94 chore: bump fastify/workflows/.github/workflows/lock-threads.yml (#225)
  • a3d075e test: cover multipart stream resume callback (#223)
  • Additional commits viewable in compare view

Updates devalue from 5.9.2 to 5.9.4

Release notes

Sourced from devalue's releases.

v5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

v5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Changelog

Sourced from devalue's changelog.

5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Commits

Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
Bumps the npm_and_yarn group with 4 updates in the / directory: [seroval](https://github.com/lxsmnsyc/seroval), [@fastify/busboy](https://github.com/fastify/busboy), [devalue](https://github.com/sveltejs/devalue) and [source-map-js](https://github.com/7rulnik/source-map-js).
Bumps the npm_and_yarn group with 4 updates in the /packages/web directory: [seroval](https://github.com/lxsmnsyc/seroval), [@fastify/busboy](https://github.com/fastify/busboy), [devalue](https://github.com/sveltejs/devalue) and [source-map-js](https://github.com/7rulnik/source-map-js).

Updates `seroval` from 1.5.4 to 1.6.3
- [Release notes](https://github.com/lxsmnsyc/seroval/releases)
- [Commits](https://github.com/lxsmnsyc/seroval/commits)

Updates `@fastify/busboy` from 3.2.0 to 3.2.2
- [Release notes](https://github.com/fastify/busboy/releases)
- [Commits](fastify/busboy@v3.2.0...v3.2.2)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

Updates `seroval` from 1.5.4 to 1.6.3
- [Release notes](https://github.com/lxsmnsyc/seroval/releases)
- [Commits](https://github.com/lxsmnsyc/seroval/commits)

Updates `@fastify/busboy` from 3.2.0 to 3.2.2
- [Release notes](https://github.com/fastify/busboy/releases)
- [Commits](fastify/busboy@v3.2.0...v3.2.2)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: seroval
  dependency-version: 1.6.3
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: "@fastify/busboy"
  dependency-version: 3.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: seroval
  dependency-version: 1.6.3
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: "@fastify/busboy"
  dependency-version: 3.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dodok8
dodok8 force-pushed the dependabot/npm_and_yarn/npm_and_yarn-2a4808fa1e branch from 6dadb51 to ac34859 Compare October 6, 2026 07:47
@dodok8
dodok8 enabled auto-merge October 6, 2026 07:51
@sij411
sij411 self-requested a review October 6, 2026 07:54
@dodok8
dodok8 merged commit 08edd29 into main Oct 6, 2026
11 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm_and_yarn-2a4808fa1e branch October 6, 2026 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants