Skip to content

fix(simple-rest): update query-string - #7602

Open
harshmaur wants to merge 1 commit into
refinedev:mainfrom
harshmaur:fix/simple-rest-decode-uri-component
Open

harshmaur wants to merge 1 commit into
refinedev:mainfrom
harshmaur:fix/simple-rest-decode-uri-component

Conversation

@harshmaur

Copy link
Copy Markdown

PR Checklist

Bugs / Features

What is the current behavior?

@refinedev/simple-rest@6.0.1 depends on query-string@^7.1.1, which installs decode-uri-component@0.2.2. That version is affected by CVE-2026-45822 / GHSA-vcc3-ghjq-m6fr.

A direct override to decode-uri-component@0.5.0 is not compatible with query-string@7. The current secure query-string release is ESM-only, while @refinedev/simple-rest supports both ESM and CommonJS consumers.

What is the new behavior?

  • Updates query-string to ^9.5.1, which uses decode-uri-component@0.5.0.
  • Uses the current default export without changing the exported stringify API.
  • Bundles the ESM-only query-string dependency graph into both simple-rest outputs, preserving CommonJS support.
  • Updates the swizzle dependency metadata and adds a patch changeset.

Fixes #7601.

Notes for reviewers

Validated with:

  • pnpm --filter @refinedev/simple-rest test — 26 tests pass
  • Dependency-aware scoped build for @refinedev/simple-rest — passes, including declarations
  • publint — passes with the existing type field suggestion
  • attw --pack . — no problems for Node 10, Node 16 CJS/ESM, or bundlers
  • Direct Node 20 CommonJS runtime check
  • Direct Node 22 CommonJS and ESM runtime checks

Advisory: GHSA-vcc3-ghjq-m6fr

@changeset-bot

changeset-bot Bot commented Sep 11, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 96a4ce5

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@refinedev/simple-rest Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@codeCraft-Ritik codeCraft-Ritik left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The validation matrix looks comprehensive—especially the direct Node 20/22 runtime checks and attw verification.

Marking this as a patch changeset is appropriate since the public API and serialization behavior remain completely unchanged

@harshmaur

Copy link
Copy Markdown
Author

@codeCraft-Ritik is there anything I need to do? If yes, let me know.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] simple-rest pulls vulnerable decode-uri-component version

2 participants