Skip to content

build(deps-dev): bump qs from 6.12.3 to 6.15.2 - #121

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/qs-6.15.2
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/qs-6.15.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 22, 2026 •

Copy link
Copy Markdown

Bumps qs from 6.12.3 to 6.15.2.

Changelog

Sourced from qs's changelog.

6.15.2

  • [Fix] stringify: skip null/undefined entries in arrayFormat: 'comma' + encodeValuesOnly instead of crashing in encoder
  • [Fix] stringify: use configured delimiter after charsetSentinel (#555)
  • [Fix] stringify: apply formatter to encoded key under strictNullHandling (#554)
  • [Fix] stringify: skip null/undefined filter-array entries instead of crashing in encoder (#551)
  • [Fix] parse: handle nested bracket groups and add regression tests (#530)
  • [readme] fix grammar (#550)
  • [Dev Deps] update @ljharb/eslint-config
  • [Tests] add regression tests for keys containing percent-encoded bracket text

6.15.1

  • [Fix] parse: parameterLimit: Infinity with throwOnLimitExceeded: true silently drops all parameters
  • [Deps] update @ljharb/eslint-config
  • [Dev Deps] update @ljharb/eslint-config, iconv-lite
  • [Tests] increase coverage

6.15.0

  • [New] parse: add strictMerge option to wrap object/primitive conflicts in an array (#425, #122)
  • [Fix] duplicates option should not apply to bracket notation keys (#514)

6.14.2

  • [Fix] parse: mark overflow objects for indexed notation exceeding arrayLimit (#546)
  • [Fix] arrayLimit means max count, not max index, in combine/merge/parseArrayValue
  • [Fix] parse: throw on arrayLimit exceeded with indexed notation when throwOnLimitExceeded is true (#529)
  • [Fix] parse: enforce arrayLimit on comma-parsed values
  • [Fix] parse: fix error message to reflect arrayLimit as max index; remove extraneous comments (#545)
  • [Robustness] avoid .push, use void
  • [readme] document that addQueryPrefix does not add ? to empty output (#418)
  • [readme] clarify parseArrays and arrayLimit documentation (#543)
  • [readme] replace runkit CI badge with shields.io check-runs badge
  • [meta] fix changelog typo (arrayLength → arrayLimit)
  • [actions] fix rebase workflow permissions

6.14.1

  • [Fix] ensure arrayLimit applies to [] notation as well
  • [Fix] parse: when a custom decoder returns null for a key, ignore that key
  • [Refactor] parse: extract key segment splitting helper
  • [meta] add threat model
  • [actions] add workflow permissions
  • [Tests] stringify: increase coverage
  • [Dev Deps] update eslint, @ljharb/eslint-config, npmignore, es-value-fixtures, for-each, object-inspect

6.14.0

  • [New] parse: add throwOnParameterLimitExceeded option (#517)
  • [Refactor] parse: use utils.combine more
  • [patch] parse: add explicit throwOnLimitExceeded default
  • [actions] use shared action; re-add finishers
  • [meta] Fix changelog formatting bug
  • [Deps] update side-channel
  • [Dev Deps] update es-value-fixtures, has-bigints, has-proto, has-symbols

... (truncated)

Commits
  • 9aca407 v6.15.2
  • 5e33d33 [Dev Deps] update @ljharb/eslint-config
  • 21f80b3 [Fix] stringify: skip null/undefined entries in arrayFormat: 'comma' + `e...
  • a0a81ea [Fix] stringify: use configured delimiter after charsetSentinel
  • e3062f7 [Fix] stringify: apply formatter to encoded key under strictNullHandling
  • 0c180a4 [Fix] stringify: skip null/undefined filter-array entries instead of crashi...
  • 3a8b94a [Tests] add regression tests for keys containing percent-encoded bracket text
  • 96755ab [readme] fix grammar
  • a419ce5 [Fix] parse: handle nested bracket groups and add regression tests
  • 3f5e1c5 v6.15.1
  • Additional commits viewable in compare view

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels May 22, 2026
sachushaji
sachushaji previously approved these changes Jun 2, 2026
Bumps [qs](https://github.com/ljharb/qs) from 6.12.3 to 6.15.2.
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.12.3...v6.15.2)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.15.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/qs-6.15.2 branch from bf738d4 to 19fb795 Compare June 10, 2026 09:22
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking.

Ticket: SCAAS-11228
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump. Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking.

Ticket: SCAAS-11228
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0.

Ticket: SCAAS-11228
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0.

Ticket: SCAAS-11228
Signed-off-by: Sachu Abraham <sachuabraham@bitgo.com>
sachushaji added a commit that referenced this pull request Sep 3, 2026
Consolidates stale dependabot PRs #75, #101, #111, #116, #121, #145 and #151 into one bump: eslint ^9.39.4, typescript-eslint ^8.60.1, engines.node >=20.19.0, plus transitive updates (fast-uri, brace-expansion, qs, follow-redirects, diff, sha.js). Major bumps (hardhat 3, hardhat-toolbox 7) are intentionally excluded as breaking. Rebased on master with axios 1.19.0.

Ticket: SCAAS-11228
Signed-off-by: Sachu Abraham <sachuabraham@bitgo.com>
Signed-off-by: Sachu Shaji Abraham <sachuabraham@bitgo.com>
@sachushaji

Copy link
Copy Markdown
Contributor

Superseded by merged PR #152, which consolidates the non-breaking dependency updates.

@sachushaji sachushaji closed this Sep 3, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/qs-6.15.2 branch September 3, 2026 10:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant