Skip to content

Bump the npm_and_yarn group across 1 directory with 4 updates - #111

Merged
dodok8 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-e79f9f1a5a
Oct 6, 2026
Merged

dodok8 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/npm_and_yarn-e79f9f1a5a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 4 updates in the / directory: seroval, @fastify/busboy, devalue and source-map-js.

Updates seroval from 1.5.4 to 1.6.3

Release notes

Sourced from seroval's releases.

1.5.5

  • fix: streaming serialization cleanup (#77)
  • fix: preserve own proto properties through serialize (#81)
  • fix: preserve circular own proto properties through deferred assignment (#82)
  • fix: use element length for bigint typed array views (#83)
  • fix: unescape regexp source in the serialized output (#84)

Credits to @​spokodev and @​greymoth-jp

Commits

Updates @fastify/busboy from 3.2.0 to 3.2.2

Release notes

Sourced from @​fastify/busboy's releases.

v3.2.2

⚠️ Security Release

Fix for GHSA-gxm5-99cw-xjw9

v3.2.1 - Security release

This is a security release for @fastify/busboy.

It addresses the following security advisories:

Users should upgrade to v3.2.1.

Full Changelog: fastify/busboy@v3.2.0...v3.2.1

Commits
  • 4e8de12 Bumped v3.2.2
  • cc7da17 Merge commit from fork
  • b404d60 Bumped v3.2.1
  • 4c872cf gitignore ai stuff
  • 632a237 Merge commit from fork
  • 957a24b Merge commit from fork
  • d515ff4 chore(.npmrc): add min-release-age
  • 0e2b3ba chore: bump fastify/workflows/.github/workflows/plugins-ci.yml (#226)
  • 733ee94 chore: bump fastify/workflows/.github/workflows/lock-threads.yml (#225)
  • a3d075e test: cover multipart stream resume callback (#223)
  • Additional commits viewable in compare view

Updates devalue from 5.9.2 to 5.9.4

Release notes

Sourced from devalue's releases.

v5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

v5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Changelog

Sourced from devalue's changelog.

5.9.4

Patch Changes

  • 067b125: perf: annotate module-level Object.freeze calls as pure so unused operation tables tree-shake

5.9.3

Patch Changes

  • 6861dbb: fix: avoid scanning sparse array holes in uneval traversal and shared-array population
  • 9ec5130: fix: reject non-string null-prototype object keys in parse and unflatten to prevent bypassing the __proto__ check
  • dae8153: fix: prevent unhandled internal rejections in stringifyAsync when serializing multiple promises
  • 84f6f67: fix: prevent quadratic uneval output expansion for repeated strings and bigints
  • 6861dbb: fix: avoid eager allocation when evaluating sparse arrays emitted by uneval
  • 8f8d78e: fix: validate revived backing buffers before constructing typed arrays
  • 46dc877: fix: serialize only the visible bytes of Node Buffers in stringify, stringifyAsync and uneval, preventing disclosure of unrelated data from their shared allocation pool
Commits

Updates source-map-js from 1.2.1 to 1.2.2

Release notes

Sourced from source-map-js's releases.

v1.2.2

Changelog

Sourced from source-map-js's changelog.

1.2.2

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 6, 2026
@sij411
sij411 self-requested a review October 6, 2026 07:41
@sij411 sij411 self-assigned this Oct 6, 2026
Bumps the npm_and_yarn group with 4 updates in the / directory: [seroval](https://github.com/lxsmnsyc/seroval), [@fastify/busboy](https://github.com/fastify/busboy), [devalue](https://github.com/sveltejs/devalue) and [source-map-js](https://github.com/7rulnik/source-map-js).


Updates `seroval` from 1.5.4 to 1.6.3
- [Release notes](https://github.com/lxsmnsyc/seroval/releases)
- [Commits](https://github.com/lxsmnsyc/seroval/commits)

Updates `@fastify/busboy` from 3.2.0 to 3.2.2
- [Release notes](https://github.com/fastify/busboy/releases)
- [Commits](fastify/busboy@v3.2.0...v3.2.2)

Updates `devalue` from 5.9.2 to 5.9.4
- [Release notes](https://github.com/sveltejs/devalue/releases)
- [Changelog](https://github.com/sveltejs/devalue/blob/main/CHANGELOG.md)
- [Commits](sveltejs/devalue@v5.9.2...v5.9.4)

Updates `source-map-js` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/7rulnik/source-map-js/releases)
- [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md)
- [Commits](7rulnik/source-map-js@v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: seroval
  dependency-version: 1.6.3
  dependency-type: direct:production
  dependency-group: npm_and_yarn
- dependency-name: "@fastify/busboy"
  dependency-version: 3.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: devalue
  dependency-version: 5.9.4
  dependency-type: indirect
  dependency-group: npm_and_yarn
- dependency-name: source-map-js
  dependency-version: 1.2.2
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
@dodok8
dodok8 force-pushed the dependabot/npm_and_yarn/npm_and_yarn-e79f9f1a5a branch from e5b5d20 to e7720e2 Compare October 6, 2026 07:48
@dodok8
dodok8 enabled auto-merge October 6, 2026 07:52
@dodok8
dodok8 merged commit 5f1f7ae into main Oct 6, 2026
11 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/npm_and_yarn-e79f9f1a5a branch October 6, 2026 07:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants