Skip to content

[dependabot-agent] Fix undici vulnerabilities via npm override - #10896

Merged
pelikhan merged 1 commit into
mainfrom
dependabot-agent/undici-security-override-20260913203825
Sep 13, 2026
Merged

pelikhan merged 1 commit into
mainfrom
dependabot-agent/undici-security-override-20260913203825

Conversation

@cao-githubnext-gh-aw-cao-write

Copy link
Copy Markdown
Contributor
What changed
  • Package/ecosystem: npm (root package.json)
  • Manifest(s): package.json, package-lock.json
  • Old version: undici transitively resolved to 5.29.0/mixed sub-6.28.1 versions across @actions/artifact, @actions/github, @actions/http-client, @github/local-action
  • New version: undici pinned to ^6.28.1 everywhere via a top-level npm overrides entry (no direct dependency version change)
  • Update type: security (transitive override, no direct package version bump)
Why now

npm audit reports 5 vulnerabilities (4 moderate, 1 high) rooted in transitive undici copies pulled in below 6.28.0 by @actions/artifact, @actions/github, @actions/http-client, and @github/local-action (all devDependencies used only for local Action testing/tooling). The highest-severity issue (CVSS 7.5) is an unbounded WebSocket permessage-deflate memory-consumption DoS (GHSA-vxpw-j846-p89q), plus several HTTP smuggling/CRLF/cookie-injection issues fixed between undici@6.24.0–6.28.0.

A prior PR (#10838) applied this identical fix but was closed without merging, so the vulnerability remains unresolved on main. Re-verified with a fresh npm audit before recreating this change.

Risk assessment
  • Runtime/dev/build/CI scope: dev-only. undici is not a direct dependency; it is pulled in transitively by @actions/artifact, @actions/github, @actions/http-client, and @github/local-action, all devDependencies used for local Action testing/tooling, not the Astro docs build or dashboard runtime.
  • Direct/transitive: transitive (2–3 levels deep); fixed via a top-level overrides pin rather than bumping any direct dependency, avoiding the @github/local-action@5.2.0 major-version downgrade that npm audit fix --force would otherwise force.
  • Reachability: no source files import undici directly; it is only exercised via the GitHub Actions SDK HTTP clients used in dev/test tooling.
Validation
  • Commands run: npm install (clean install with the override), npm audit --json (0 vulnerabilities after, vs 5 before), npm run typecheck:cao (passed, no errors), npm run test:unit (350/357 pass; the 4 failures/3 cancellations were verified present identically on unpatched main before this change — unrelated pre-existing issues: activity/cao.mjs default-location tests, telemetry cache-absent tests, CAO policy resolve-policy worker-identity check, and a clean-room compilation settings test)
  • Result: npm audit now reports 0 vulnerabilities (was 4 moderate + 1 high); all undici copies in package-lock.json resolve to 6.28.1.
  • Remaining gaps: did not run npm run compile / npm run docs:build (no .md workflow source or docs content changed by this PR) or the dashboard site's own test suite (unaffected — separate dashboard/site/package.json, already audited clean with 0 vulnerabilities in this run).
Control Plane

Toolchain: Node/npm as pinned by CI (no engines field declared in package.json; used the preinstalled npm in the workflow runner). Registry preflight: npm registry fully reachable, no auth issues. No breaking changes — this is an overrides pin only, no direct dependency version bump, no API surface change. Risk: low. Confidence: high (clean install, 0 audit findings, typecheck clean, no test regressions beyond pre-existing baseline failures verified on main).

Rollback: revert this commit (removes the overrides block from package.json and restores package-lock.json); no other files are affected.

Smart-Dependabot-Merge-Candidate: yes

Reviewer checklist
  • CI passes
  • CODEOWNERS or service owners reviewed
  • Security-sensitive areas approved, if applicable
  • Deployment/canary owner confirms runtime health, if needed
Rollback guidance
  • Revert this PR to restore the previous transitive undici resolution.
  • package.json and package-lock.json must be reverted together (lockfile was regenerated from the override).

Generated by :dependabot: Dependabot / Release Trains · copilot · auto · 143.4 AIC · ⌖ 14.4 AIC · ⊞ 18.5K · ◷

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pelikhan
pelikhan marked this pull request as ready for review September 13, 2026 20:44
@pelikhan
pelikhan merged commit 97fa162 into main Sep 13, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant