chore(deps): bump fast-uri from 3.1.2 to 4.1.1 in /test-projects/expo-purchasely-test#264
Conversation
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.2 to 4.1.1. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.2...v4.1.1) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 4.1.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
PR author is in the excluded authors list. |
|
Dependabot PR Review — 2026-07-25 (research only, no merges/approvals taken this run) Note: GitHub Issues are disabled on this repository, so this comment thread substitutes for the usual cross-repo Dependabot tracking issue. Posting the full batch summary here (on the lowest/most-attention-needing PR) and cross-linking from the other four. Summary5 open Dependabot PRs, all
Changelog analysis
No merge conflicts, no config changes needed. Ask@kherembourg — assigning for visibility as the most recently active human contributor on this repo. Reply here to confirm auto-merging #265/#266/#267/#268 (and optionally the low-risk major #264), or to hold/override any of them. No PRs in this batch were merged or approved this run. Generated by Claude Code |
|
Automated Dependabot review (2026-07-26) — research only, no merge/approve action taken. Major bump (3.1.2 → 4.1.1), Note: issues are disabled on this repo, so this review is posted as PR comments (see also #267, #266, #268, #265, #269) rather than a single tracking issue. @kherembourg — major bump, needs your explicit sign-off per policy even though blast radius looks limited to the test project. Reply here to confirm, hold, or override. Related: #267, #266, #268, #265, #269 Generated by Claude Code |
Dependabot PR Review — 2026-07-27Issues are disabled on this repo, so posting the review summary here instead of a tracking issue (cross-linking the batch: #269, #268, #267, #266, #265, #264). This is a research-only pass — nothing has been approved or merged. First Dependabot review cycle for this repo. 6 open Dependabot PRs, all in
Notes:
No repo-level default merge method could be determined via the available tools — flagging for whoever confirms this to state a preference (squash is GitHub's common default). @kherembourg — flagging for visibility as the most recently active human contributor on this repo. Reply here (or on the respective PRs) to confirm auto-merging #268/#267/#266/#265, whether to merge #264 despite the major bump (security fix, low risk per above), and whether to investigate or hold #269's No PRs in this batch were merged or approved. Generated by Claude Code |
Bumps fast-uri from 3.1.2 to 4.1.1.
Release notes
Sourced from fast-uri's releases.
... (truncated)
Commits
f3e437fBumped v4.1.1ec639c9ignore ai files0542a21Merge commit from fork3a87738Bumped v4.0.190f1653fix: preserve trailing empty path segment in removeDotSegments (RFC 3986 §5.2...7fc49a9fix: normalize percent-encoding in query and fragment (#183)d2bf521Bumped v4.0.121ea1f9Merge commit from fork28dad0achore: bump actions/checkout from 6 to 7 (#186)a7ab6c9chore: replace http with https in urls (#184)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.