Skip to content

Commit 87f7e12

Browse files
fix: update undici override to ^6.24.1 to resolve all security advisories
Updates the undici override from ^6.23.0 to ^6.24.1, resolving: - CVE-2026-2229: Unhandled Exception in WebSocket (server_max_window_bits) - CVE-2026-1528: Malicious WebSocket 64-bit length overflow - CVE-2026-1526: Unbounded Memory Consumption (permessage-deflate) - CVE-2026-1525: HTTP Request/Response Smuggling - CVE-2026-1527: CRLF Injection via upgrade option Keeps @actions/github at v6.0.1 to avoid ESM-only breakage from v9.0.0. Co-Authored-By: David Konigsberg <davidakonigsberg@gmail.com>
1 parent fed7ad1 commit 87f7e12

2 files changed

Lines changed: 4 additions & 4 deletions

File tree

package-lock.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,6 @@
3535
"vitest": "^4.0.18"
3636
},
3737
"overrides": {
38-
"undici": "^6.23.0"
38+
"undici": "^6.24.1"
3939
}
4040
}

0 commit comments

Comments
 (0)