Skip to content

deps: bump undici from 8.10.0 to 8.11.2 in /frontend in the security-minor-patch group across 1 directory - #90

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/security-minor-patch-3e61689c5c
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/security-minor-patch-3e61689c5c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the security-minor-patch group with 1 update in the /frontend directory: undici.

Updates undici from 8.10.0 to 8.11.2

Release notes

Sourced from undici's releases.

v8.11.2

What's Changed

New Contributors

Full Changelog: nodejs/undici@v8.11.1...v8.11.2

v8.11.1

What's Changed

Full Changelog: nodejs/undici@v8.11.0...v8.11.1

v8.11.0

What's Changed

... (truncated)

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Devin Review

Bumps the security-minor-patch group with 1 update in the /frontend directory: [undici](https://github.com/nodejs/undici).


Updates `undici` from 8.10.0 to 8.11.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v8.10.0...v8.11.2)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 8.11.2
  dependency-type: indirect
  dependency-group: security-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: npm. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 30, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@CherylSnowVeil CherylSnowVeil left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed the current revision (ca1caee). This is an initial review — no previous reviews or comments from this account on the PR.

What this PR does

Single-file diff: frontend/package-lock.json, bumping undici 8.10.0 → 8.11.2. undici is a transitive dev dependency pulled in by jsdom (^8.9.0, satisfied by 8.11.2), so no package.json change is needed and this does not touch the version-locked vite/@sveltejs/vite-plugin-svelte/vitest toolchain.

Verification

  • Lockfile integrity: resolved URL and integrity (sha512-u4UB2/IrKdU6lFxumHmmo1a3fCQO5tzQllRorfoRS63txhrB7xTpSn1PftwC4qEHkOaqP95fCWW4lJzwErwzhQ==) match the published npm registry tarball for undici@8.11.2.
  • Minimal diff is complete: undici has no runtime dependencies in either 8.10.0 or 8.11.2, so no other lockfile entries needed updating.
  • Engines: node >=22.19.0 in both versions — no engine-requirement regression; already satisfied by the Playwright base image's Node LTS.
  • Security rationale is real: 8.10.0 is covered by two advisories — GHSA-vp8m-p9jh-q5pm (high: cross-origin cache poisoning via missing origin isolation in interceptors) and GHSA-3wwx-pv8p-q78v (medium: DoS via WebSocket permessage-deflate decompression), both patched at 8.10.2. This bump clears both and would otherwise trip the npm audit --audit-level=high step in test-security.

Findings

No actionable findings — the change is correct, minimal, and verified against the registry.

Non-blocking observation (repo config, not this PR's code): Dependabot's own comment notes the npm label referenced in dependabot.yml doesn't exist in this repo, so labeling fails silently on Dependabot PRs. Worth creating the label or removing it from the config at some point.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant