Skip to content

chore(deps): update dependency qs to v6.9.7 (develop) - autoclosed#899

Closed
mend-for-github-com[bot] wants to merge 1 commit intodevelopfrom
whitesource-remediate/develop-qs-6.x-lockfile
Closed

chore(deps): update dependency qs to v6.9.7 (develop) - autoclosed#899
mend-for-github-com[bot] wants to merge 1 commit intodevelopfrom
whitesource-remediate/develop-qs-6.x-lockfile

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented May 21, 2025

This PR contains the following updates:

Package Type Update Change
qs dependencies patch 6.9.4 -> 6.9.7

By merging this PR, the issue #829 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
High High 7.5 CVE-2022-24999

Reachable


Release Notes

ljharb/qs (qs)

v6.9.7

Compare Source

  • [Fix] parse: ignore __proto__ keys (#​428)
  • [Fix] stringify: avoid encoding arrayformat comma when encodeValuesOnly = true (#​424)
  • [Robustness] stringify: avoid relying on a global undefined (#​427)
  • [readme] remove travis badge; add github actions/codecov badges; update URLs
  • [Docs] add note and links for coercing primitive values (#​408)
  • [Tests] clean up stringify tests slightly
  • [meta] fix README.md (#​399)
  • Revert "[meta] ignore eclint transitive audit warning"
  • [actions] backport actions from main
  • [Dev Deps] backport updates from main

v6.9.6

Compare Source

  • [Fix] restore dist dir; mistakenly removed in d4f6c32

v6.9.5

Compare Source

  • [Fix] stringify: do not encode parens for RFC1738
  • [Fix] stringify: fix arrayFormat comma with empty array/objects (#​350)
  • [Refactor] format: remove util.assign call
  • [meta] add "Allow Edits" workflow; update rebase workflow
  • [actions] switch Automatic Rebase workflow to pull_request_target event
  • [Tests] stringify: add tests for #​378
  • [Tests] migrate tests to Github Actions
  • [Tests] run nyc on all tests; use tape runner
  • [Dev Deps] update eslint, @ljharb/eslint-config, browserify, mkdirp, object-inspect, tape; add aud

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label May 21, 2025
@mend-for-github-com
Copy link
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json

@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency qs to v6.9.7 (develop) chore(deps): update dependency qs to v6.9.7 (develop) - autoclosed Jul 13, 2025
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/develop-qs-6.x-lockfile branch July 13, 2025 09:10
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency qs to v6.9.7 (develop) - autoclosed chore(deps): update dependency qs to v6.9.7 (develop) Jul 19, 2025
@mend-for-github-com mend-for-github-com bot reopened this Jul 19, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/develop-qs-6.x-lockfile branch from 03dd3b2 to 1431487 Compare July 19, 2025 08:19
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency qs to v6.9.7 (develop) chore(deps): update dependency qs to v6.9.7 (develop) - abandoned Jul 28, 2025
@mend-for-github-com
Copy link
Author

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency qs to v6.9.7 (develop) - abandoned chore(deps): update dependency qs to v6.9.7 (develop) Aug 4, 2025
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency qs to v6.9.7 (develop) chore(deps): update dependency qs to v6.9.7 (develop) - autoclosed Sep 5, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants