deps: bump undici from 8.10.0 to 8.11.2 in /frontend in the security-minor-patch group across 1 directory - #90
Conversation
Bumps the security-minor-patch group with 1 update in the /frontend directory: [undici](https://github.com/nodejs/undici). Updates `undici` from 8.10.0 to 8.11.2 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v8.10.0...v8.11.2) --- updated-dependencies: - dependency-name: undici dependency-version: 8.11.2 dependency-type: indirect dependency-group: security-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
CherylSnowVeil
left a comment
There was a problem hiding this comment.
Reviewed the current revision (ca1caee). This is an initial review — no previous reviews or comments from this account on the PR.
What this PR does
Single-file diff: frontend/package-lock.json, bumping undici 8.10.0 → 8.11.2. undici is a transitive dev dependency pulled in by jsdom (^8.9.0, satisfied by 8.11.2), so no package.json change is needed and this does not touch the version-locked vite/@sveltejs/vite-plugin-svelte/vitest toolchain.
Verification
- Lockfile integrity:
resolvedURL andintegrity(sha512-u4UB2/IrKdU6lFxumHmmo1a3fCQO5tzQllRorfoRS63txhrB7xTpSn1PftwC4qEHkOaqP95fCWW4lJzwErwzhQ==) match the published npm registry tarball for undici@8.11.2. - Minimal diff is complete: undici has no runtime dependencies in either 8.10.0 or 8.11.2, so no other lockfile entries needed updating.
- Engines:
node >=22.19.0in both versions — no engine-requirement regression; already satisfied by the Playwright base image's Node LTS. - Security rationale is real: 8.10.0 is covered by two advisories — GHSA-vp8m-p9jh-q5pm (high: cross-origin cache poisoning via missing origin isolation in interceptors) and GHSA-3wwx-pv8p-q78v (medium: DoS via WebSocket permessage-deflate decompression), both patched at 8.10.2. This bump clears both and would otherwise trip the
npm audit --audit-level=highstep intest-security.
Findings
No actionable findings — the change is correct, minimal, and verified against the registry.
Non-blocking observation (repo config, not this PR's code): Dependabot's own comment notes the npm label referenced in dependabot.yml doesn't exist in this repo, so labeling fails silently on Dependabot PRs. Worth creating the label or removing it from the config at some point.
Bumps the security-minor-patch group with 1 update in the /frontend directory: undici.
Updates
undicifrom 8.10.0 to 8.11.2Release notes
Sourced from undici's releases.
... (truncated)
Commits
7e016adBumped v8.11.2 (#5886)fcdd5a6fix: skip reconnecting for aborted requests (#5846)dd28c5cfix: close rejected HTTP/2 WebSocket handshake streams (#5873)5e0a2f8Bumped v8.11.1 (#5871)2b72898test: cover native fetch gzip decoding through the legacy bridge (#5874)636bf51docs: warn about buffering response bodies (#5872)8145595fix hang on 3xx response with large body (#5850)f3cbe48fix websocketstream bugs (#5863)1d4ea0aRevert "fix: preserve HTTP/2 for legacy fetch consumers" (#5860)77d7b3fdeslopify websocket test (#5851)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.