Skip to content

fix(web): bump undici override to ^7.29.1 - #919

Open
FenjuFu wants to merge 1 commit into
iflytek:mainfrom
FenjuFu:fix/undici-7.29.1
Open

FenjuFu wants to merge 1 commit into
iflytek:mainfrom
FenjuFu:fix/undici-7.29.1

Conversation

@FenjuFu

@FenjuFu FenjuFu commented Oct 3, 2026

Copy link
Copy Markdown
Member

Summary

Resolves the open Dependabot alerts for undici in web/pnpm-lock.yaml (#63 high, #65/#70 medium, #66/#69/#71 low). All of them are fixed in undici 7.29.1.

undici is only pulled in transitively through jsdom (test environment), so the fix just raises the existing pnpm override floor:

- "undici@<7.29.0": "^7.29.0"
+ "undici@<7.29.1": "^7.29.1"

The lockfile was regenerated with the pinned pnpm@10.33.0; the only resolution change is undici 7.29.0 → 7.30.0.

Verification

  • pnpm install --frozen-lockfile succeeds
  • pnpm test: 900/901 pass. The one failure (landing-quick-start-locale.test.ts) is a local Windows artifact: with core.autocrlf=true the checked-out skill.md.template has CRLF line endings, while the test compares against \n-joined lines. It's unrelated to this change and should pass on CI (Linux, LF checkout).

Resolve Dependabot alerts iflytek#63, iflytek#65, iflytek#66, iflytek#69, iflytek#70 and iflytek#71 for the
transitive undici dependency (via jsdom) by raising the pnpm override
floor from 7.29.0 to the patched 7.29.1. The lockfile now resolves
undici@7.30.0.

Signed-off-by: FenjuFu <92919259+FenjuFu@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant