Skip to content

deps: bump qs from 6.14.1 to 6.15.2 - #70

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/qs-6.15.2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/qs-6.15.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 23, 2026

Copy link
Copy Markdown
Contributor

Bumps qs from 6.14.1 to 6.15.2.

Changelog

Sourced from qs's changelog.

6.15.2

  • [Fix] stringify: skip null/undefined entries in arrayFormat: 'comma' + encodeValuesOnly instead of crashing in encoder
  • [Fix] stringify: use configured delimiter after charsetSentinel (#555)
  • [Fix] stringify: apply formatter to encoded key under strictNullHandling (#554)
  • [Fix] stringify: skip null/undefined filter-array entries instead of crashing in encoder (#551)
  • [Fix] parse: handle nested bracket groups and add regression tests (#530)
  • [readme] fix grammar (#550)
  • [Dev Deps] update @ljharb/eslint-config
  • [Tests] add regression tests for keys containing percent-encoded bracket text

6.15.1

  • [Fix] parse: parameterLimit: Infinity with throwOnLimitExceeded: true silently drops all parameters
  • [Deps] update @ljharb/eslint-config
  • [Dev Deps] update @ljharb/eslint-config, iconv-lite
  • [Tests] increase coverage

6.15.0

  • [New] parse: add strictMerge option to wrap object/primitive conflicts in an array (#425, #122)
  • [Fix] duplicates option should not apply to bracket notation keys (#514)

6.14.2

  • [Fix] parse: mark overflow objects for indexed notation exceeding arrayLimit (#546)
  • [Fix] arrayLimit means max count, not max index, in combine/merge/parseArrayValue
  • [Fix] parse: throw on arrayLimit exceeded with indexed notation when throwOnLimitExceeded is true (#529)
  • [Fix] parse: enforce arrayLimit on comma-parsed values
  • [Fix] parse: fix error message to reflect arrayLimit as max index; remove extraneous comments (#545)
  • [Robustness] avoid .push, use void
  • [readme] document that addQueryPrefix does not add ? to empty output (#418)
  • [readme] clarify parseArrays and arrayLimit documentation (#543)
  • [readme] replace runkit CI badge with shields.io check-runs badge
  • [meta] fix changelog typo (arrayLength → arrayLimit)
  • [actions] fix rebase workflow permissions
Commits
  • 9aca407 v6.15.2
  • 5e33d33 [Dev Deps] update @ljharb/eslint-config
  • 21f80b3 [Fix] stringify: skip null/undefined entries in arrayFormat: 'comma' + `e...
  • a0a81ea [Fix] stringify: use configured delimiter after charsetSentinel
  • e3062f7 [Fix] stringify: apply formatter to encoded key under strictNullHandling
  • 0c180a4 [Fix] stringify: skip null/undefined filter-array entries instead of crashi...
  • 3a8b94a [Tests] add regression tests for keys containing percent-encoded bracket text
  • 96755ab [readme] fix grammar
  • a419ce5 [Fix] parse: handle nested bracket groups and add regression tests
  • 3f5e1c5 v6.15.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [qs](https://github.com/ljharb/qs) from 6.14.1 to 6.15.2.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.14.1...v6.15.2)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.15.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 23, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@robotlearning123

Copy link
Copy Markdown
Member

Reviewed by execution (fresh worktrees at head 33f3860 vs base e704b49).

VERDICT: SHIP — merge-safe, strictly reduces qs advisory count (3 → 2). Follow-up below.

Scope check: diff vs merge-base ce7da5b touches exactly 1 file: package-lock.json (+6/−13). Delivered version = 6.15.2, matches title. Consumers are transitive (express@5.2.1 requires qs ^6.14.0, body-parser@2.2.2 requires qs ^6.14.1) — both ranges accept the bump. Lockfile version-field sync 0.1.0 → 0.2.0 just aligns the lock with the already-0.2.0 manifest. npm ci exit 0, dry-run integrity clean, npm ls qs → 6.15.2.

Tests/baseline-delta: head 57/57 pass = base 57/57 pass (no delta). typecheck/lint/build exit 0 at head. GitHub checks 8/9 SUCCESS; the one FAILURE (claude-review) is pre-existing and PR-independent — that workflow has failed on 15/15 recent runs including docs-only PRs (#71/#72/#73/#77) with Claude result reported subtype success with is_error:true / Internal error: directory mismatch ... tsconfig.json.

OSV advisory delta (osv.dev, package qs):

The bump clears CVE-2026-2391 (arrayLimit bypass, ≤6.14.1) and CVE-2026-8723 (qs.stringify DoS, ≤6.15.1). Honest caveats: CVE-2026-82417 (DoS via attacker-controlled isBuffer, <6.16.0) persists, and CVE-2026-82562 (array-limit bypass via bracket-key comma parsing, range >=6.14.2 <=6.15.3) is newly in range with this bump — 6.14.1 was not affected by that one. Net: 3 → 2 moderate advisories, no new vulnerable package introduced (npm audit totals identical: 19 vulnerable packages before and after).

Follow-up (clean in-range target): qs 6.16.0 (published 2026-08-29, after this PR was cut) is in-range for both consumers (^6.14.x) and clears ALL qs advisories per OSV. Recommend merging this as-is or retargeting the bump to 6.16.0; do not leave main on 6.14.1.

Staleness: not superseded — this is the only qs PR (open or closed); main still pins 6.14.1. Branch is 4 months behind main, but main's root package.json/package-lock.json are unchanged since the branch point, so the merge is clean (GitHub: MERGEABLE).

@robotlearning123

Copy link
Copy Markdown
Member

Independent review verdict: FIX-FIRST (retarget to qs 6.16.0)

Reviewer: grok lane, headless, execution-based (writer != reviewer). Run in a detached worktree at 33f3860 (origin/dependabot/npm_and_yarn/qs-6.15.2).

Finding (major) — package-lock.json:3631

The bump lands on qs 6.15.2, which still carries 2 OSV advisories; a clean in-range target exists:

version OSV advisories
6.14.1 (base) 3 — GHSA-4mjr-xmp4-gh2g (CVE-2026-82417), GHSA-q8mj-m7cp-5q26 (CVE-2026-8723), GHSA-w7fw-mjwx-w883 (CVE-2026-2391)
6.15.2 (this PR) 2 — GHSA-x5fp-wj9c-mxmx (CVE-2026-82562, fixed range >=6.14.2 <=6.15.3 — newly entered by this bump, 6.14.1 was not affected), GHSA-4mjr-xmp4-gh2g (CVE-2026-82417, >=2.2.5 <6.16.0)
6.16.0 (clean target) 0

6.16.0 satisfies both consumer ranges (express ^6.14.0, body-parser ^6.14.1). Concrete failure scenario: after merge, request parsing in the express/body-parser stack remains inside both unfixed advisory ranges, including the array-limit bypass this PR newly introduces relative to 6.14.1. Retarget the lock to 6.16.0.

Cleared by this bump (not the blocker): GHSA-q8mj-m7cp-5q26 (fixed in 6.15.2), GHSA-w7fw-mjwx-w883 (fixed in 6.14.2).

Verified green (execution receipts)

  • Scope: only package-lock.json changed (6 insertions, 13 deletions); no package.json change.
  • Tests: npm test → tests 57, pass 57, fail 0, skipped 0 (matches historical count).
  • Delivered version matches title: node_modules/qs → 6.15.2, registry integrity equals lock integrity.
  • Incidental 0.1.0 → 0.2.0 lockfile version sync is correct: package.json was already 0.2.0 at the merge-base and on main — the lock was the stale side.
  • Peer-flag churn (hono gains peer:true; express/typescript/zod/acorn lose it) does not change resolved versions — npm ls exits 0 for all affected packages.
  • Not superseded / not conflict-stale: behind main by 1 commit (which does not touch the root lock), git merge-tree → 0 conflicts, MERGEABLE, no other open qs bump; main still resolves qs 6.14.1.
  • npm audit at head: qs moderate, fixAvailable: true; total advisory count unchanged (19 at base and head) — the remaining 19 are other dependencies.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant