Skip to content

fix(nodejs): bump undici floor to 6.29.0 to clear high-severity audit - #123

Merged
JeanExtreme002 merged 1 commit into
mainfrom
fix/node-undici-audit
Oct 9, 2026
Merged

JeanExtreme002 merged 1 commit into
mainfrom
fix/node-undici-audit

Conversation

@JeanExtreme002

Copy link
Copy Markdown
Owner

Why

The scheduled Node.js Package workflow has been failing on main (runs 36807633400 and 37722094748) at the enforced npm audit --omit=dev --audit-level=high step. The lockfile pins undici 6.28.0, which is flagged by three high-severity advisories:

What

Bump the undici floor from ^6.28.0 to ^6.29.0 and refresh the lockfile. All three advisories are patched from 6.28.1, and 6.29.0 keeps engines.node >=18.17, so the package's own engines range and the 18.x matrix leg are untouched. Going to undici 7.x would have required dropping Node 18.

Verification

Locally on Node 22:

  • npm audit --omit=dev --audit-level=high: 0 vulnerabilities
  • npm run lint, npm run test:types, npm run test:offline: all passing (94 offline tests)

The scheduled Node.js Package run fails at the enforced npm audit step
because undici 6.28.0 is affected by GHSA-3wwx-pv8p-q78v,
GHSA-r53p-7pc4-xj5r and GHSA-rfgv-xxqx-mfg5. All three are fixed in
6.28.1+, and 6.29.0 still supports Node >=18.17, so the engines range
and the 18.x matrix leg are unchanged.
@JeanExtreme002
JeanExtreme002 merged commit cca3384 into main Oct 9, 2026
5 checks passed
@github-actions
github-actions Bot deleted the fix/node-undici-audit branch October 9, 2026 15:28
JeanExtreme002 added a commit that referenced this pull request Oct 9, 2026
Patch release so the published npm manifest carries the undici ^6.29.0
floor from #123. Python and Go move with it because verify-versions
refuses a release whose three declared versions disagree.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant