Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Bump fast-uri from 3.1.5 to 3.1.6 in /ExtensionPack - #14731

Merged
Sean McManus (sean-mcmanus) merged 1 commit into
mainfrom
dependabot/npm_and_yarn/ExtensionPack/fast-uri-3.1.6
Sep 3, 2026
Merged

Bump fast-uri from 3.1.5 to 3.1.6 in /ExtensionPack#14731
Sean McManus (sean-mcmanus) merged 1 commit into
mainfrom
dependabot/npm_and_yarn/ExtensionPack/fast-uri-3.1.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Bumps fast-uri from 3.1.5 to 3.1.6.

Release notes

Sourced from fast-uri's releases.

v3.1.6

⚠️ Security Warning

This release addresses the following high-severity security advisories:

Users of the v3.x release line should upgrade to v3.1.6.

Full Changelog: fastify/fast-uri@v3.1.5...v3.1.6

Commits
  • 6f970b2 Bumped v3.1.6
  • d941579 fix: never run IDN canonicalization on bracketed IP literals
  • c0f0279 test: adapt decoded-scheme handler assertion to 3.x (no mailto scheme)
  • 37f3417 Merge commit from fork
  • 607bfbe Merge commit from fork
  • ae92a4c Merge commit from fork
  • 444ecda Merge commit from fork
  • f1138cf fix: handle malformed URNs without throwing (#211)
  • 4ebffaa fix: preserve malformed URN input (#210)
  • 0819d5f fix: preserve URI component case in equality (#207)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.6.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.6)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 2, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 2, 2026 23:40
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 2, 2026
@github-project-automation github-project-automation Bot moved this to Pull Request in cpptools Sep 2, 2026
@sean-mcmanus
Sean McManus (sean-mcmanus) merged commit 9e4a502 into main Sep 3, 2026
6 checks passed
@github-project-automation github-project-automation Bot moved this from Pull Request to Done in cpptools Sep 3, 2026
@sean-mcmanus
Sean McManus (sean-mcmanus) deleted the dependabot/npm_and_yarn/ExtensionPack/fast-uri-3.1.6 branch September 3, 2026 02:10
Sean McManus (sean-mcmanus) added a commit that referenced this pull request Sep 9, 2026
* Use npm ci in issue workflows (#14702)

* Pin the Yarn bootstrap and add SHA-512 lock checksums (#14703)

* Add SHA-512 checksums to yarn.lock

* Pin the Yarn bootstrap install

* Register LLVM component for LLDB-MI (#14704)

* Add xobjgen to gitignore (for Linux/Mac). (#14707)

* Retry transient Yarn install failures (#14708)

* Ensure the language client is always ready before using it (#14617)

* Update 1.34.0 changelog (#14710)

* Update changelog and version for 1.34.1 (#14714)

* Update clang-tidy checks to 23.1.0 (#14713)

* Use native file type mappings for TypeScript-side classification (#14711)

* Add 1.34.2 changelog (#14722)

* Add 1.34.2 changelog

* Remove ignored network isolation policy (#14728)

* Bump fast-uri from 3.1.5 to 3.1.6 in /ExtensionPack (#14731)

Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.5 to 3.1.6.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.5...v3.1.6)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump @xmldom/xmldom from 0.8.13 to 0.8.15 in /Extension (#14733)

Bumps [@xmldom/xmldom](https://github.com/xmldom/xmldom) from 0.8.13 to 0.8.15.
- [Release notes](https://github.com/xmldom/xmldom/releases)
- [Changelog](https://github.com/xmldom/xmldom/blob/master/CHANGELOG.md)
- [Commits](xmldom/xmldom@0.8.13...0.8.15)

---
updated-dependencies:
- dependency-name: "@xmldom/xmldom"
  dependency-version: 0.8.15
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Bump browserslist from 4.28.1 to 4.28.8 in /Extension (#14732)

Bumps [browserslist](https://github.com/browserslist/browserslist) from 4.28.1 to 4.28.8.
- [Release notes](https://github.com/browserslist/browserslist/releases)
- [Changelog](https://github.com/browserslist/browserslist/blob/main/CHANGELOG.md)
- [Commits](browserslist/browserslist@4.28.1...4.28.8)

---
updated-dependencies:
- dependency-name: browserslist
  dependency-version: 4.28.8
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Remove unused gulp-sourcemaps dependency (#14729)

* Remove unused gulp-sourcemaps dependency

* Remove orphaned dependency resolutions

* Fix custom configuration provider regression (#14725)

* Restore custom configuration provider checks

* Ignore empty crash report files (#14730)

* Ignore empty crash report files

* Preserve pending crash reads across clients

* Keep crash writing state for pending reports

* Fix fast-uri dependency. (#14735)

* Fix fast-uri dependency.

* Also for Themes.

* Implement session state tracking for "Run and Debug" button when Inte… (#14719)

* Implement session state tracking for "Run and Debug" button when IntelliSense is disabled and add corresponding tests

* Enhance session state tracking for build and debug by updating folder open status and adding tests

* Fix build and debug folder session state tracking

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <[email protected]>

* Potential fix for pull request finding

Co-authored-by: Copilot Autofix powered by AI <[email protected]>

---------

Co-authored-by: Copilot Autofix powered by AI <[email protected]>
Co-authored-by: Sean McManus <[email protected]>

* Fix #11263: Make Edit Configurations UI fully theme-aware in custom themes (#14692)

* Fix #11263: use theme-aware colors in Edit Configurations UI

* Enhance dropdown styling with theme-aware colors in settings UI

---------

Co-authored-by: Sean McManus <[email protected]>

* Add processFilter for remote attach process selection (#14684)

* Add processFilter for remote attach process selection

When attaching to a process on a remote target, the process always has
to be selected by hand, even though the launch configuration already
knows which executable it belongs to. A generated configuration cannot
hard-code processId either, because the pid changes on every boot and
on every restart of the service, so the picker is the only option.

Add an optional processFilter regular expression to the cppdbg attach
configuration. When set, it is matched against the label, description
and detail of the remote process list:

  exactly one match  attach to that process directly
  more than one      show the picker with only the matching entries
  no match           show the full picker, as before

All three fields are considered because the item format depends on the
transport: useExtendedRemote reports the user and the full command line
in the label, while pipeTransport reports the process name in the label
and the command line in the detail.

An invalid regular expression is reported instead of being silently
ignored.

This affects remote attach only (pipeTransport and useExtendedRemote);
local attach continues to use program-based matching.

Closes #14682

* Extract remote process filtering into a helper

Move the matching logic out of RemoteAttachPicker into a standalone
function so that it can be unit tested without a VS Code quick pick or
a live connection to a remote target.

No functional change.

* Add unit tests for processFilter matching

Cover empty and non-string filter values, matching against label,
description and detail, multiple matches, an invalid regular
expression, and a regression case ensuring missing fields are not
treated as empty strings.

---------

Co-authored-by: Adrian Freihofer <[email protected]>
Co-authored-by: Sean McManus <[email protected]>

* Bump the github-actions group with 2 updates (#14738)

Bumps the github-actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).


Updates `github/codeql-action/init` from 4.37.7 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@ff2f1c6...cdf488f)

Updates `github/codeql-action/analyze` from 4.37.7 to 4.37.9
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@ff2f1c6...cdf488f)

---
updated-dependencies:
- dependency-name: github/codeql-action/init
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: github-actions
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>

* Fix localization translation errors (#14737)

* Localization - Translated Strings

* Fix localization translation errors

* Address localization review feedback

* Fix localization review feedback

---------

Co-authored-by: csigs <[email protected]>

* Update changelog for 1.34.3 (#14740)

* Update changelog and version for 1.34.4. (#14748)

* Enable PR CI for release and insiders (#14751)

* Fix localization string import (#14743)

* Fix localization string import
* Correct conversion cycle translations

* Add Run and Debug session state tests (#14736)

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: Bob Brown <[email protected]>
Co-authored-by: Colen Garoutte-Carson <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Prashant Kumar Rai <[email protected]>
Co-authored-by: Copilot Autofix powered by AI <[email protected]>
Co-authored-by: afreof <[email protected]>
Co-authored-by: Adrian Freihofer <[email protected]>
Co-authored-by: csigs <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant