Skip to content

build(deps): bump qs and verdaccio - #8591

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-072a00cab4
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-072a00cab4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps qs to 6.16.0 and updates ancestor dependency verdaccio. These dependencies need to be updated together.

Updates qs from 6.15.3 to 6.16.0

Changelog

Sourced from qs's changelog.

6.16.0

  • [New] stringify: add a depth option to bound recursion depth (default Infinity)
  • [Fix] stringify: serialize Date values when a filter is provided
  • [Fix] parse: enforce arrayLimit on comma groups under []= when throwOnLimitExceeded is set
  • [Fix] parse: flatten a collection appended to an overflowed array (#571)
  • [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or drop own keys) on an empty array with own properties
  • [Fix] stringify: encode dots in a top-level key with a primitive value when encodeDotInKeys is set (#562)
  • [Docs] threat model: clarify stringify deep-nesting DoS is caller-bounded
  • [Docs] clarify arrayLimit is a representation threshold, not an element-count cap
  • [Tests] parse: remove a test that pinned []= comma groups escaping arrayLimit
  • [Tests] stringify: pin current encodeDotInKeys separator-dot behavior
  • [Dev Deps] update @ljharb/eslint-config, eslint
  • [Dev Deps] update eslint, evalmd
Commits
  • bb9379e v6.16.0
  • 62fd254 [Fix] stringify: serialize Date values when a filter is provided
  • 8859c37 [Fix] parse: enforce arrayLimit on comma groups under []= when `throwOn...
  • 8079adc [Tests] parse: remove a test that pinned []= comma groups escaping `array...
  • d56f48c [Fix] parse: flatten a collection appended to an overflowed array
  • e83d321 [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • 7e87a07 [Dev Deps] update @ljharb/eslint-config, eslint
  • 9a76af2 [Dev Deps] update eslint, evalmd
  • 3a890d4 [Dev Deps] update eslint, evalmd
  • b433a9b [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or dro...
  • Additional commits viewable in compare view

Updates verdaccio from 6.9.0 to 6.10.5

Release notes

Sourced from verdaccio's releases.

v6.10.5

Patch Changes

  • 2ccbacf: Migrate the 6.x release workflow to Changesets action v2 and CLI v3.

  • c159460: Improve validation of Search v1 query parameters.

    size and from now accept only plain string values; anything else falls back to the default page size and offset, as other non-numeric values already did. Only plain string parameters are forwarded to uplinks. An uplink search response that cannot be read now ends that uplink's results, and local results are still returned. Unexpected errors in the search endpoint are reported through the regular error handler. Registry configuration does not need to change.

  • ec341ee: Validate Search v1 query text before starting a search.

    Search requests must provide a single, non-blank text string. Missing or invalid search text now receives HTTP 400 with the JSON error code ERR_TEXT_MISSING, before searching local packages or uplinks.

    Earlier 6.x releases could accept searches without text. Clients that call the search API directly must now supply a non-blank query. Valid query text is preserved, and searches with no matching packages continue to return HTTP 200 with an empty results array.

  • 35e8373: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/auth: 8.1.4 → 8.1.5
    • @verdaccio/config: 8.3.1 → 8.3.2
    • @verdaccio/core: 8.3.1 → 8.3.2
    • @verdaccio/hooks: 8.1.5 → 8.1.6
    • @verdaccio/loaders: 8.1.4 → 8.1.5
    • @verdaccio/local-storage-legacy: 11.4.4 → 11.4.5
    • @verdaccio/logger: 8.1.4 → 8.1.5
    • @verdaccio/middleware: 8.1.5 → 8.1.6
    • @verdaccio/package-filter: 13.2.2 → 13.2.3
    • @verdaccio/signature: 8.1.4 → 8.1.5
    • @verdaccio/tarball: 13.1.4 → 13.1.5
    • @verdaccio/ui-theme: 9.0.0-next-9.31 → 9.0.0-next-9.33
    • @verdaccio/url: 13.1.4 → 13.1.5
    • verdaccio-audit: 13.1.5 → 13.1.6
    • verdaccio-htpasswd: 13.1.4 → 13.1.5

    Package name validation now follows the npm rules for existing packages: names that start with an underscore, use @ without a scope, or contain characters that are not URL-friendly are rejected with HTTP 400 instead of being looked up. Packages whose names cannot be stored as a directory of the same name on every platform (for example nul or aux.js) are still served from uplinks, but are not cached locally and cannot be published to local storage; a warning is logged when one is requested. Rename any private package with such a name before upgrading. Registry configuration does not need to change.

  • 3d1ca06: Improve version validation in GET /<package>/<version>.

    The endpoint now resolves only versions and dist-tags that the package actually defines. A version or tag name that the package does not define now returns HTTP 404 (version not found) in every case, instead of an internal server error for some names. Requests for existing versions, ranges and dist-tags behave as before, and registry configuration does not need to change.

    Update the internal @verdaccio/* modules to their latest 8.x releases (@verdaccio/core and @verdaccio/config 8.3.1, @verdaccio/auth 8.1.4, @verdaccio/middleware 8.1.5, verdaccio-htpasswd 13.1.4, @verdaccio/local-storage-legacy 11.4.4, verdaccio-auth-memory 13.1.4, verdaccio-memory 10.5.4, verdaccio-audit 13.1.5 and the rest of the set), which improve validation of user registration, authentication, API tokens and request parameters. When the htpasswd file is reloaded, users removed from it now stop authenticating without a restart.

    Update brace-expansion and ignore two advisories without a published fix (braces, http-cache-semantics) that are not reachable from the registry code paths.

v6.10.4

Patch Changes

  • 7730e60: Update express to 4.22.3 — directly and through @verdaccio/middleware 8.1.4, verdaccio-audit 13.1.4 and @verdaccio/test-helper 4.1.4 — so the registry's entire HTTP stack resolves qs 6.16.0, which fixes several denial-of-service advisories in query-string handling: a remotely triggerable crash in qs.stringify (TypeError on crafted input), an arrayLimit bypass through bracket-key comma parsing that allows memory exhaustion, and a DoS via an attacker-controlled isBuffer check (GHSA-4mjr-xmp4-gh2g). A body-parser/qs resolution covers the one remaining consumer that pins qs below the fix. Query-string parsing behaviour is otherwise unchanged and no configuration change is needed.

... (truncated)

Changelog

Sourced from verdaccio's changelog.

6.10.5

Patch Changes

  • 2ccbacf: Migrate the 6.x release workflow to Changesets action v2 and CLI v3.

  • c159460: Improve validation of Search v1 query parameters.

    size and from now accept only plain string values; anything else falls back to the default page size and offset, as other non-numeric values already did. Only plain string parameters are forwarded to uplinks. An uplink search response that cannot be read now ends that uplink's results, and local results are still returned. Unexpected errors in the search endpoint are reported through the regular error handler. Registry configuration does not need to change.

  • ec341ee: Validate Search v1 query text before starting a search.

    Search requests must provide a single, non-blank text string. Missing or invalid search text now receives HTTP 400 with the JSON error code ERR_TEXT_MISSING, before searching local packages or uplinks.

    Earlier 6.x releases could accept searches without text. Clients that call the search API directly must now supply a non-blank query. Valid query text is preserved, and searches with no matching packages continue to return HTTP 200 with an empty results array.

  • 35e8373: Update verdaccio dependencies to the latest npm dist-tag (@verdaccio/ui-theme tracks next-9):

    • @verdaccio/auth: 8.1.4 → 8.1.5
    • @verdaccio/config: 8.3.1 → 8.3.2
    • @verdaccio/core: 8.3.1 → 8.3.2
    • @verdaccio/hooks: 8.1.5 → 8.1.6
    • @verdaccio/loaders: 8.1.4 → 8.1.5
    • @verdaccio/local-storage-legacy: 11.4.4 → 11.4.5
    • @verdaccio/logger: 8.1.4 → 8.1.5
    • @verdaccio/middleware: 8.1.5 → 8.1.6
    • @verdaccio/package-filter: 13.2.2 → 13.2.3
    • @verdaccio/signature: 8.1.4 → 8.1.5
    • @verdaccio/tarball: 13.1.4 → 13.1.5
    • @verdaccio/ui-theme: 9.0.0-next-9.31 → 9.0.0-next-9.33
    • @verdaccio/url: 13.1.4 → 13.1.5
    • verdaccio-audit: 13.1.5 → 13.1.6
    • verdaccio-htpasswd: 13.1.4 → 13.1.5

    Package name validation now follows the npm rules for existing packages: names that start with an underscore, use @ without a scope, or contain characters that are not URL-friendly are rejected with HTTP 400 instead of being looked up. Packages whose names cannot be stored as a directory of the same name on every platform (for example nul or aux.js) are still served from uplinks, but are not cached locally and cannot be published to local storage; a warning is logged when one is requested. Rename any private package with such a name before upgrading. Registry configuration does not need to change.

  • 3d1ca06: Improve version validation in GET /<package>/<version>.

    The endpoint now resolves only versions and dist-tags that the package actually defines. A version or tag name that the package does not define now returns HTTP 404 (version not found) in every case, instead of an internal server error for some names. Requests for existing versions, ranges and dist-tags behave as before, and registry configuration does not need to change.

    Update the internal @verdaccio/* modules to their latest 8.x releases (@verdaccio/core and @verdaccio/config 8.3.1, @verdaccio/auth 8.1.4, @verdaccio/middleware 8.1.5, verdaccio-htpasswd 13.1.4, @verdaccio/local-storage-legacy 11.4.4, verdaccio-auth-memory 13.1.4, verdaccio-memory 10.5.4, verdaccio-audit 13.1.5 and the rest of the set), which improve validation of user registration, authentication, API tokens and request parameters. When the htpasswd file is reloaded, users removed from it now stop authenticating without a restart.

    Update brace-expansion and ignore two advisories without a published fix (braces, http-cache-semantics) that are not reachable from the registry code paths.

6.10.4

Patch Changes

  • 7730e60: Update express to 4.22.3 — directly and through @verdaccio/middleware 8.1.4, verdaccio-audit 13.1.4 and @verdaccio/test-helper 4.1.4 — so the registry's entire HTTP stack resolves qs 6.16.0, which fixes several denial-of-service advisories in query-string handling: a remotely triggerable crash in qs.stringify (TypeError on crafted input), an arrayLimit bypass through bracket-key comma parsing that allows memory exhaustion, and a DoS via an attacker-controlled isBuffer check (GHSA-4mjr-xmp4-gh2g). A body-parser/qs

... (truncated)

Commits
Attestation changes

This version has no provenance attestation, while the previous version (6.9.0) was attested. Review the package versions before updating.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [qs](https://github.com/ljharb/qs) to 6.16.0 and updates ancestor dependency [verdaccio](https://github.com/verdaccio/verdaccio). These dependencies need to be updated together.


Updates `qs` from 6.15.3 to 6.16.0
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.3...v6.16.0)

Updates `verdaccio` from 6.9.0 to 6.10.5
- [Release notes](https://github.com/verdaccio/verdaccio/releases)
- [Changelog](https://github.com/verdaccio/verdaccio/blob/v6.10.5/CHANGELOG.md)
- [Commits](verdaccio/verdaccio@v6.9.0...v6.10.5)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
- dependency-name: verdaccio
  dependency-version: 6.10.5
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 7, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 7, 2026 16:24
@dependabot dependabot Bot added the javascript Pull requests that update Javascript code label Oct 7, 2026
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: fa09b6f7-3bb4-40d7-a621-7ef971ab50a2

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

📊 Benchmark results

Comparing with 75c66ae

  • Dependency count: 1,019 ⬆️ 0.49% increase vs. 75c66ae
  • Package size: 380 MB ⬆️ 1.56% increase vs. 75c66ae
  • Number of ts-expect-error directives: 331 (no change)

@pkg-pr-new

pkg-pr-new Bot commented Oct 7, 2026

Copy link
Copy Markdown

Open in StackBlitz

npm i https://pkg.pr.new/netlify-cli@8591

commit: 4c332b1

@sarahetter

Copy link
Copy Markdown
Contributor

Superseded by #8590 (verdaccio 6.10.5, qs 6.16.0), which has merged.

@sarahetter sarahetter closed this Oct 7, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-072a00cab4 branch October 7, 2026 16:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant