Skip to content

chore(deps): bump undici from 6.28.0 to 6.29.0 - #14

Merged
twk3 merged 2 commits into
mainfrom
dependabot/npm_and_yarn/undici-6.29.0
Sep 29, 2026
Merged

twk3 merged 2 commits into
mainfrom
dependabot/npm_and_yarn/undici-6.29.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026 •

Copy link
Copy Markdown

Bumps undici from 6.28.0 to 6.29.0.

Release notes

Sourced from undici's releases.

v6.29.0

What's Changed

Full Changelog: nodejs/undici@v6.28.1...v6.29.0

v6.28.1

⚠️ Security fixes

High severity

  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 2af0faf8.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 07c60d9c.

Low severity

  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by ce31bc82.

What's Changed

Full Changelog: nodejs/undici@v6.28.0...v6.28.1

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Bumps [undici](https://github.com/nodejs/undici) from 6.28.0 to 6.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.28.0...v6.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 2071fbf9-fd75-4c51-a903-847988d1602c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown

Security triage: Tier B — the committed dist/ was not rebuilt

What and why

undici 6.28.0 -> 6.29.0 (moderate; via @actions/http-client <- @actions/core)

  • CVE-2026-85024 / GHSA-3wwx-pv8p-q78v, CVSS 5.9 — Vanta alert 46, range >= 6.25.0, < 6.28.1
  • Vanta fixedVersion 6.28.1; remediateByDate 2026-11-28 — 60 days remaining. 6.29.0 satisfies that floor, so this does close the finding.

Exposure

Runtime, and it ships. npm ls undici:

cancel-run-gh-action@1.1.0
`-- @actions/core@2.0.3          <- dependencies
  `-- @actions/http-client@3.0.2
    `-- undici@6.28.0

@actions/core is the one dependencies entry, and undici is bundled into the committed dist/index.js (117 references) — which is what actually executes when a workflow references this action. So the vulnerable code runs in consumers' CI.

The fix

Mechanism: lockfile-upgrade. package-lock.json only, one stanza, no manifest edit.

Why this is Tier B

check-dist concluded failure on head 365404b, and it is this PR's failure, not inherited:

check conclusion
build success
test success
Analyze (javascript-typescript) success
CodeQL success
check-dist failure
[code]smith skipped

check-dist runs npm ci && npm run package (ncc build src/index.ts -o dist) and fails if the rebuilt dist/ differs from what is committed. Because undici is bundled into that output, changing its resolved version changes the bundle — and Dependabot updated the lockfile without re-running npm run package. The action would otherwise keep shipping the old undici from the stale bundle no matter what the lockfile says, which is the part that matters here.

undici is also on this routine's sensitive list, so it is never an auto-merge candidate regardless.

check-dist.yml uses paths-ignore: ['**.md'], so a lockfile-only diff does trigger it.

Breaking-change check

Read the 6.28.1 notes, which carry the fix for this advisory — a WebSocket subprotocol TypeError, an unhandled zlib error on malformed permessage-deflate payloads, and a retry-interceptor response-splitting issue — with no breaking changes. This PR goes one minor further, to 6.29.0; I did not read 6.29.0's own notes, so treat the range 6.28.1 -> 6.29.0 as unreviewed.

Verification

  • npm audit --package-lock-only reproduces it: moderate undici >=6.25.0 <6.28.1.
  • npm ls undici --package-lock-only --all for the path above.
  • grep -c undici dist/index.js -> 117, confirming the bundle carries it.
  • git diff --name-only: package-lock.json only.
  • I did not run npm run all against this branch.

What a human should still check

  1. Run npm run package on this branch and commit the rebuilt dist/. Without it the merge updates the lockfile but leaves the shipped bundle on 6.28.0, so the alert would close while the vulnerable code still runs.
  2. Decide whether 6.29.0 is wanted or whether 6.28.1 — the exact patched version — is the smaller move. 6.29.0's release notes have not been reviewed here.
  3. Worth noting for the repo generally: any dependency bundled into dist/ needs the same rebuild step, so Dependabot PRs here will keep failing check-dist until something rebuilds the bundle for them.

Generated by Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BYnmK3bCdA1HgXhiJWX5zE
@twk3
twk3 merged commit 4e23465 into main Sep 29, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/undici-6.29.0 branch September 29, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants