Skip to content

fix: bump undici to 6.28.1 to clear npm audit - #171

Merged
ChiragAgg5k merged 1 commit into
29.xfrom
fix/undici-audit
Oct 6, 2026
Merged

ChiragAgg5k merged 1 commit into
29.xfrom
fix/undici-audit

Conversation

@ChiragAgg5k

Copy link
Copy Markdown
Member

The 29.1.0 publish failed at npm audit --audit-level=high --omit=dev: undici <=6.28.0 is high severity through GHSA-3wwx-pv8p-q78v, GHSA-r53p-7pc4-xj5r and GHSA-rfgv-xxqx-mfg5, all fixed in 6.28.1.

  • package.json: undici ^6.27.0 → ^6.28.1, so installs cannot resolve a vulnerable 6.x
  • package-lock.json: only the undici entry (version, resolved, integrity) and the root range change

Locally: npm ci accepts the lockfile, npm audit --audit-level=high --omit=dev reports 0 vulnerabilities, npm run build passes. 29.1.0 never reached npm, so after this merges the 29.1.0 tag and release are re-pointed to the fixed 29.x and published. main (30.0.0-rc.2) has the same undici range and will need the same bump.

… and GHSA-rfgv-xxqx-mfg5

npm audit --audit-level=high fails on undici <=6.28.0, so the 29.1.0 publish stopped before npm publish.
@ChiragAgg5k
ChiragAgg5k merged commit d702656 into 29.x Oct 6, 2026
2 checks passed
@ChiragAgg5k
ChiragAgg5k deleted the fix/undici-audit branch October 6, 2026 15:15
@hansi-codes

hansi-codes Bot commented Oct 6, 2026

Copy link
Copy Markdown

🟢 Tier S · Ready to merge

The manifest and lockfile agree, and inspection of the SDK's undici usage revealed no concrete compatibility issue with this patch update.

Raises the minimum undici version to 6.28.1 within the existing 6.x range to address the reported security advisories. The lockfile pins the updated version and retains the same Node.js engine requirement.

Verdict New comments Fixed Still open
✅ Approved 0 0 0
📂 Walkthrough · 2
File Change
package.json Updates the undici dependency range from ^6.27.0 to ^6.28.1.
package-lock.json Updates the root dependency range and undici's locked version, tarball URL, and integrity hash.

Reviewed 27a6576 · Details · Comment @hansi-codes review to re-run, or mention @hansi-codes with a question.

@hansi-codes hansi-codes Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Tier S · Looks good to merge. Summary

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant