Repository navigation
fix: Bump qs from 6.15.3 to 6.16.0 - #3458
Conversation
|
🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review. Tip
Note Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect. Caution Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe lockfile updates the Changesqs Dependency Update
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~3 minutes Merge Risk: ⚪ Minimal · up to No merge-blocking risk is identified in this dependency-only update. Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 inconclusive)
✅ Passed checks (6 passed)
Full details: Engage In Review FeedbackExplanation The supplied review metadata reports zero actionable findings for the current review, so it shows no current feedback requiring engagement. It explicitly does not establish whether earlier review comments exist or whether they were resolved after discussion. The repository contains no local review-comment metadata that can answer this gap. Resolution Provide the complete review discussion history, including earlier feedback comments, discussion engagement, and each comment’s final state. Confirm that every applicable comment was either implemented by a commit or retracted after the contributor convinced the reviewer. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
# [9.3.0-alpha.8](9.3.0-alpha.7...9.3.0-alpha.8) (2026-09-24) ### Bug Fixes * Bump qs from 6.15.3 to 6.16.0 ([#3458](#3458)) ([04f5acb](04f5acb))
|
🎉 This change has been released in version 9.3.0-alpha.8 |
Pull Request
Issue
Closes #3446
Bumps the transitive production dependency
qs(viaexpressandbody-parser) from 6.15.3 to 6.16.0, which fixes the security advisories GHSA-x5fp-wj9c-mxmx and GHSA-4mjr-xmp4-gh2g.Approach
Lock file only.
npm update qschanges only thenode_modules/qsentry inpackage-lock.json.Changes
stringify: add adepthoption to bound recursion depth (defaultInfinity)stringify: serialize Date values when a filter is providedparse: enforcearrayLimiton comma groups under[]=whenthrowOnLimitExceededis set (GHSA-x5fp-wj9c-mxmx)parse: flatten a collection appended to an overflowed array ([Fix]parse: flatten a collection appended to an overflowed array ljharb/qs#571)utils:isBuffer: do not invoke a non-callableconstructor.isBuffer(GHSA-4mjr-xmp4-gh2g)stringify: do not letallowEmptyArraysskip cycle detection (or drop own keys) on an empty array with own propertiesstringify: encode dots in a top-level key with a primitive value whenencodeDotInKeysis set ([Fix]stringify: encode dots in a top-level key with a primitive value whenencodeDotInKeysis set ljharb/qs#562)Breaking Changes
None
Code Changes Required
None. The upgrade is a drop-in replacement.
express5.2.1 uses its defaultsimplequery parser (node:querystring), and the dashboard does not change it.body-parser2.2.2 (urlencoded({ extended: true })) callsqs.parsewithout thecommaorthrowOnLimitExceededoptions and does not callqs.stringify, so the changed code paths do not apply to normal input.Tasks
Summary by CodeRabbit