Skip to content

[Snyk] Security upgrade undici from 7.26.0 to 7.29.0 - #15246

Open
posit-snyk-bot wants to merge 2 commits into
mainfrom
snyk-fix-df1ee007d83df9ff27dc4a7cd93d5bef
Open

[Snyk] Security upgrade undici from 7.26.0 to 7.29.0#15246
posit-snyk-bot wants to merge 2 commits into
mainfrom
snyk-fix-df1ee007d83df9ff27dc4a7cd93d5bef

Conversation

@posit-snyk-bot

Copy link
Copy Markdown
Contributor

snyk-top-banner

Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Information Exposure
SNYK-JS-UNDICI-18426521
  159  
high severity Interpretation Conflict
SNYK-JS-UNDICI-18426065
  111  

Breaking Change Risk

Merge Risk: Low

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@posit-snyk-bot

Copy link
Copy Markdown
Contributor Author

Merge Risk: Low

This is a minor version upgrade that includes bug fixes and performance improvements. No breaking changes are documented in the release notes for the versions between 7.26.0 and 7.29.0.

Key Changes:

  • v7.29.0: Fixes an issue with header validation (CRLF injection), preserves response trailers during decompression, and handles frozen globalThis when setting a global dispatcher.
  • v7.28.0: Includes a security fix for GHSA-hm92-r4w5-c3mj.

No mandatory migration steps are required.

Source: GitHub Releases

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

@github-actions

Copy link
Copy Markdown

E2E Tests 🚀
This PR will run tests tagged with: @:critical

Note

No feature tags detected. If this PR needs feature coverage, add the tag above and retrigger the workflow.

readme  valid tags

@juliasilge

Copy link
Copy Markdown
Member

We will get this as part of an upstream merge, I believe. Is that correct, @timtmok?

@timtmok

timtmok commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

@juliasilge We would get this from upstream but they haven't updated to this version yet. It's low enough of a risk to get this in sooner than later.

@juliasilge
juliasilge requested a review from timtmok July 31, 2026 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants