Skip to content

chore(deps): bump @fastify/busboy from 3.2.0 to 3.2.2 in /frontend - #2421

Merged
JSv4 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/fastify/busboy-3.2.2
Oct 9, 2026
Merged

JSv4 merged 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/fastify/busboy-3.2.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps @fastify/busboy from 3.2.0 to 3.2.2.

Release notes

Sourced from @​fastify/busboy's releases.

v3.2.2

⚠️ Security Release

Fix for GHSA-gxm5-99cw-xjw9

v3.2.1 - Security release

This is a security release for @fastify/busboy.

It addresses the following security advisories:

Users should upgrade to v3.2.1.

Full Changelog: fastify/busboy@v3.2.0...v3.2.1

Commits
  • 4e8de12 Bumped v3.2.2
  • cc7da17 Merge commit from fork
  • b404d60 Bumped v3.2.1
  • 4c872cf gitignore ai stuff
  • 632a237 Merge commit from fork
  • 957a24b Merge commit from fork
  • d515ff4 chore(.npmrc): add min-release-age
  • 0e2b3ba chore: bump fastify/workflows/.github/workflows/plugins-ci.yml (#226)
  • 733ee94 chore: bump fastify/workflows/.github/workflows/lock-threads.yml (#225)
  • a3d075e test: cover multipart stream resume callback (#223)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [@fastify/busboy](https://github.com/fastify/busboy) from 3.2.0 to 3.2.2.
- [Release notes](https://github.com/fastify/busboy/releases)
- [Commits](fastify/busboy@v3.2.0...v3.2.2)

---
updated-dependencies:
- dependency-name: "@fastify/busboy"
  dependency-version: 3.2.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 9, 2026
@claude

claude Bot commented Oct 9, 2026

Copy link
Copy Markdown

Review: lockfile-only Dependabot bump of the transitive dependency @fastify/busboy from 3.2.0 to 3.2.2 (frontend/yarn.lock, 3 lines). The range ^3.1.1 already allows 3.2.2, so no package.json change is needed.

  • Code quality: the diff is minimal and touches only the version, resolved URL and integrity hash.
  • Security: this is a good change. 3.2.1 and 3.2.2 are security releases covering three advisories. I'd merge it for that reason.
  • Bugs and performance: I don't expect either. This is a patch-level bump and its dependents don't appear to use the API in a way that could break.
  • Tests: no new tests are needed. I didn't run CI or the tests myself, so please confirm the frontend build and CI are green before merging.
  • Repo conventions: a changelog.d/ fragment isn't strictly required for a dependency bump. If you want it recorded, a security fragment would fit.

Looks good to merge once CI passes.

@JSv4
JSv4 merged commit 2acb3f4 into main Oct 9, 2026
13 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 9, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/frontend/fastify/busboy-3.2.2 branch October 9, 2026 13:57
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant