Skip to content

chore(deps): bump qs from 6.14.0 to 6.14.1#5619

Closed
dependabot[bot] wants to merge 1 commit intounstablefrom
dependabot/npm_and_yarn/qs-6.14.1
Closed

chore(deps): bump qs from 6.14.0 to 6.14.1#5619
dependabot[bot] wants to merge 1 commit intounstablefrom
dependabot/npm_and_yarn/qs-6.14.1

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 31, 2025

Bumps qs from 6.14.0 to 6.14.1.

Changelog

Sourced from qs's changelog.

6.14.1

  • [Fix] ensure arrayLength applies to [] notation as well
  • [Fix] parse: when a custom decoder returns null for a key, ignore that key
  • [Refactor] parse: extract key segment splitting helper
  • [meta] add threat model
  • [actions] add workflow permissions
  • [Tests] stringify: increase coverage
  • [Dev Deps] update eslint, @ljharb/eslint-config, npmignore, es-value-fixtures, for-each, object-inspect
Commits
  • 3fa11a5 v6.14.1
  • a626704 [Dev Deps] update npmignore
  • 3086902 [Fix] ensure arrayLength applies to [] notation as well
  • fc7930e [Dev Deps] update eslint, @ljharb/eslint-config
  • 0b06aac [Dev Deps] update @ljharb/eslint-config
  • 64951f6 [Refactor] parse: extract key segment splitting helper
  • e1bd259 [Dev Deps] update @ljharb/eslint-config
  • f4b3d39 [eslint] add eslint 9 optional peer dep
  • 6e94d95 [Dev Deps] update eslint, @ljharb/eslint-config, npmignore
  • 973dc3c [actions] add workflow permissions
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [qs](https://github.com/ljharb/qs) from 6.14.0 to 6.14.1.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.14.0...v6.14.1)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.14.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Dec 31, 2025
@rtibbles rtibbles requested a review from rtibblesbot February 11, 2026 02:02
Copy link

@rtibblesbot rtibblesbot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency Update Review

Package: qs 6.14.0 → 6.14.1 (specifier: ^6.11.2^6.14.1)
Semver risk: Patch
Dependency type: Production
CI status: Only one workflow ran ("Update community pull requests spreadsheet" — passed). No build or test CI checks were triggered.

Changelog Analysis

Sources consulted:

Breaking changes: None.

Bug fixes:

  • [Fix] ensure arrayLimit applies to [] notation as well
  • [Fix] parse: when a custom decoder returns null for a key, ignore that key

Other changes:

  • [Refactor] parse: extract key segment splitting helper
  • [meta] add threat model
  • [actions] add workflow permissions
  • Dev dependency updates and test coverage improvements

Compatibility Assessment

  • Project uses affected APIs: The project uses qs.stringify() with arrayFormat: 'comma' and a custom encoder in contentcuration/contentcuration/frontend/shared/client.js. It does not use arrayLimit, custom decoders, or parse() — the two bug fixes in this release do not affect this project's usage.
  • Peer dependency requirements satisfied: Yes — qs has no peer dependencies.
  • Code changes required: No.
  • Prior attempts: No previous PRs for this upgrade were reverted or closed.

Lockfile Verification

The lockfile changes are limited to qs itself (6.14.0 → 6.14.1) and its transitive consumers (express, body-parser) updating their resolved qs version. An unrelated deprecated annotation appeared on whatwg-encoding — this is normal lockfile metadata refresh. No unexpected new dependencies.

CI Note

suggestion: No build or test CI checks ran on this PR — only a spreadsheet-update workflow executed. While this patch bump is low-risk and doesn't affect the APIs used by this project, the absence of test CI means compatibility hasn't been mechanically verified. Consider triggering a CI run before merging, or verify manually that the build succeeds.

Recommendation

APPROVE — This is a low-risk patch bump with two minor bug fixes that don't affect the project's usage of qs. The lockfile changes are clean and expected. The only caveat is the lack of build/test CI coverage on this PR branch.

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Feb 13, 2026

Superseded by #5702.

@dependabot dependabot bot closed this Feb 13, 2026
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/qs-6.14.1 branch February 13, 2026 18:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant