Repository navigation
chore(deps): bump undici from 6.28.0 to 6.29.0 - #14
Conversation
Bumps [undici](https://github.com/nodejs/undici) from 6.28.0 to 6.29.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v6.28.0...v6.29.0) --- updated-dependencies: - dependency-name: undici dependency-version: 6.29.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Security triage: Tier B — the committed
|
| check | conclusion |
|---|---|
build |
success |
test |
success |
Analyze (javascript-typescript) |
success |
CodeQL |
success |
check-dist |
failure |
[code]smith |
skipped |
check-dist runs npm ci && npm run package (ncc build src/index.ts -o dist) and fails if the rebuilt dist/ differs from what is committed. Because undici is bundled into that output, changing its resolved version changes the bundle — and Dependabot updated the lockfile without re-running npm run package. The action would otherwise keep shipping the old undici from the stale bundle no matter what the lockfile says, which is the part that matters here.
undici is also on this routine's sensitive list, so it is never an auto-merge candidate regardless.
check-dist.yml uses paths-ignore: ['**.md'], so a lockfile-only diff does trigger it.
Breaking-change check
Read the 6.28.1 notes, which carry the fix for this advisory — a WebSocket subprotocol TypeError, an unhandled zlib error on malformed permessage-deflate payloads, and a retry-interceptor response-splitting issue — with no breaking changes. This PR goes one minor further, to 6.29.0; I did not read 6.29.0's own notes, so treat the range 6.28.1 -> 6.29.0 as unreviewed.
Verification
npm audit --package-lock-onlyreproduces it:moderate undici >=6.25.0 <6.28.1.npm ls undici --package-lock-only --allfor the path above.grep -c undici dist/index.js-> 117, confirming the bundle carries it.git diff --name-only:package-lock.jsononly.- I did not run
npm run allagainst this branch.
What a human should still check
- Run
npm run packageon this branch and commit the rebuiltdist/. Without it the merge updates the lockfile but leaves the shipped bundle on 6.28.0, so the alert would close while the vulnerable code still runs. - Decide whether 6.29.0 is wanted or whether 6.28.1 — the exact patched version — is the smaller move. 6.29.0's release notes have not been reviewed here.
- Worth noting for the repo generally: any dependency bundled into
dist/needs the same rebuild step, so Dependabot PRs here will keep failingcheck-distuntil something rebuilds the bundle for them.
Generated by Claude Code
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BYnmK3bCdA1HgXhiJWX5zE
Bumps undici from 6.28.0 to 6.29.0.
Release notes
Sourced from undici's releases.
Commits
e1d0501Bumped v6.29.0 (#5888)57ac4detest: synchronize the issue-3356 body timeout (#5834)6d44174Backport upgrade diagnostics lifecycle fixes to v6.x (#5833)2a91fc8fix(retry): settle exposed body on terminal failure (#5778)ffc8aa0Bumped v6.28.1 (#5773)3866a3bperf(h1): drop idle-socket timer floor with a ref'd setImmediate (#5707) (#5770)ce31bc8fix(retry): validate resumed response framing2af0faffix(websocket): reject unrequested subprotocols07c60d9fix(websocket): destroy inflater after decompression limitbd90fffperf: reduce EventSourceStream parser allocations (#5032) (#5647)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.