Skip to content

Bump qs and firebase-functions in /functions - #60

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/functions/multi-0fc86330f8
Open

Bump qs and firebase-functions in /functions#60
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/functions/multi-0fc86330f8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps qs to 6.16.0 and updates ancestor dependency firebase-functions. These dependencies need to be updated together.

Updates qs from 6.15.2 to 6.16.0

Changelog

Sourced from qs's changelog.

6.16.0

  • [New] stringify: add a depth option to bound recursion depth (default Infinity)
  • [Fix] stringify: serialize Date values when a filter is provided
  • [Fix] parse: enforce arrayLimit on comma groups under []= when throwOnLimitExceeded is set
  • [Fix] parse: flatten a collection appended to an overflowed array (#571)
  • [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or drop own keys) on an empty array with own properties
  • [Fix] stringify: encode dots in a top-level key with a primitive value when encodeDotInKeys is set (#562)
  • [Docs] threat model: clarify stringify deep-nesting DoS is caller-bounded
  • [Docs] clarify arrayLimit is a representation threshold, not an element-count cap
  • [Tests] parse: remove a test that pinned []= comma groups escaping arrayLimit
  • [Tests] stringify: pin current encodeDotInKeys separator-dot behavior
  • [Dev Deps] update @ljharb/eslint-config, eslint
  • [Dev Deps] update eslint, evalmd

6.15.3

  • [Fix] parse: enforce throwOnLimitExceeded for cumulative array growth via combine/merge
  • [Fix] utils: respect encoding of surrogate pairs across chunks (#559)
  • [Robustness] parse: throw the arrayLimit error before splitting oversized comma values
  • [Robustness] utils.merge / utils.assign: avoid invoking __proto__ setter when copying own properties
  • [Robustness] utils: enforce arrayLimit consistently across merge's array paths
  • [Perf] utils: make compact O(n) via a side-channel visited-set instead of Array.indexOf
  • [Deps] update side-channel
  • [Dev Deps] update eslint, mock-property, tape
  • [Tests] parse: characterize current lenient handling of unbalanced bracket keys (#558)
Commits
  • bb9379e v6.16.0
  • 62fd254 [Fix] stringify: serialize Date values when a filter is provided
  • 8859c37 [Fix] parse: enforce arrayLimit on comma groups under []= when `throwOn...
  • 8079adc [Tests] parse: remove a test that pinned []= comma groups escaping `array...
  • d56f48c [Fix] parse: flatten a collection appended to an overflowed array
  • e83d321 [Fix] utils: isBuffer: do not invoke a non-callable constructor.isBuffer
  • 7e87a07 [Dev Deps] update @ljharb/eslint-config, eslint
  • 9a76af2 [Dev Deps] update eslint, evalmd
  • 3a890d4 [Dev Deps] update eslint, evalmd
  • b433a9b [Fix] stringify: do not let allowEmptyArrays skip cycle detection (or dro...
  • Additional commits viewable in compare view

Updates firebase-functions from 3.24.1 to 7.3.2

Release notes

Sourced from firebase-functions's releases.

v7.3.2

  • chore: update dependencies to close CVEs (#1936)
  • Fix an issue with npm labeling in the deployment pipeline. (#1937)
  • chore: improve release script (#1932)

v7.3.2-rc.1

  • chore: update dependencies to close CVEs (#1936)
  • Fix an issue with npm labeling in the deployment pipeline. (#1937)
  • chore: improve release script (#1932)

v7.3.2-rc.0

  • Internal maintenance updates and chore improvements.

v7.3.1-rc.0

  • Internal maintenance updates and chore improvements.

v7.3.0

  • Bringing in lifecycle triggers into docgen. (#1931)
  • fix: Remove false warning when using Expression in cors option (#1802)
  • feat: Add requiresRole developer API for declarative security support and automatic Manifest extraction (#1908)
  • Validate literal timeoutSeconds values per v2 trigger type (0-540s for events, 0-3600s for HTTPS/callable, 0-1800s for task queues, 0-7s for identity functions) so misconfigured values fail at function-definition or manifest-extraction time instead of at deploy time. (#1877)
  • feat: Add requiresAPI function to allow declaring Google Cloud API dependencies in code. (#1900)
  • fix(v1): Call onInit for schedule.onRun functions (#1801)
  • feat: Add support to declare lifecycle hooks in functions. (#1915)
  • fix(cors): Fix issue using Params to set CORS allowed hosts (#1903)
  • fix(v2): Fix event data unpacking for auth event triggers (#1923)
  • feat: Add "v2/lifecycle" and "lifecycle" import paths for lifecycle hooks (#1926)
  • chore: revamp deploy pipeline to be stateless. Changes must now include relnotes (#1929)
  • chore: move the last encrypted keys into Google Cloud Secrets Manager (#1929)

v7.2.5

Internal fixes

v7.2.4

-Internal Improvements #1864

v7.2.3

  • Accept BooleanParams in CallableOptions (#1854)
  • rotate the npmrc key to robot account (#1857)

v7.2.2

  • Allow v2 auth blocking functions to use run.app or cloudfunctions.net URLs (#1831)

v7.2.1

  • Fix issue where v1 firestore paths would not handle literals with leading or trailing slashes (#1829)
  • transformed string exprssions (currenlty an internal tool) now propagate across interpolated strings (#1829)

V7.2.0

  • All V1 configuration (e.g. pubsub topics) can be set with params. (#1820)
  • String expressions can now be used in string interpolation with the expr tag. (#1820) E.g.

... (truncated)

Commits
  • 565db02 fix: rename task timeout kind and also apply it to scheduler (#1934)
  • d2315bb chore(deps): resolve pipeline deprecations and upgrade dependencies (#1936)
  • 17ebe7c feat: default npm distribution tag to next for prereleases (#1937)
  • c2cd3f7 fix: dynamically increment prerelease versions in publish.sh (#1932)
  • ce42106 Adding lifecycle events in docgen (#1931)
  • 923b3a9 fix: resolve BASH_REMATCH overwriting in changelog.sh (#1930)
  • 642d901 fix: resolve Cloud Build invalid argument errors for substitutions (#1929)
  • 58aadd2 Revamp deploy pipeline to be stateless (#1925)
  • 66a9235 chore: suppress new auth triggers and internal pubsub types from docgen (#1927)
  • 85fdeb0 Add "v2/lifecycle" import path (#1926)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [qs](https://github.com/ljharb/qs) to 6.16.0 and updates ancestor dependency [firebase-functions](https://github.com/firebase/firebase-functions). These dependencies need to be updated together.


Updates `qs` from 6.15.2 to 6.16.0
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.15.2...v6.16.0)

Updates `firebase-functions` from 3.24.1 to 7.3.2
- [Release notes](https://github.com/firebase/firebase-functions/releases)
- [Commits](firebase/firebase-functions@v3.24.1...v7.3.2)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.16.0
  dependency-type: indirect
- dependency-name: firebase-functions
  dependency-version: 7.3.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants