[dependabot-agent] Fix undici vulnerabilities via npm override - #10896
Merged
pelikhan merged 1 commit intoSep 13, 2026
Merged
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
package.json)package.json,package-lock.jsonundicitransitively resolved to5.29.0/mixed sub-6.28.1 versions across@actions/artifact,@actions/github,@actions/http-client,@github/local-actionundicipinned to^6.28.1everywhere via a top-level npmoverridesentry (no direct dependency version change)Why now
npm auditreports 5 vulnerabilities (4 moderate, 1 high) rooted in transitiveundicicopies pulled in below6.28.0by@actions/artifact,@actions/github,@actions/http-client, and@github/local-action(all devDependencies used only for local Action testing/tooling). The highest-severity issue (CVSS 7.5) is an unbounded WebSocket permessage-deflate memory-consumption DoS (GHSA-vxpw-j846-p89q), plus several HTTP smuggling/CRLF/cookie-injection issues fixed betweenundici@6.24.0–6.28.0.A prior PR (#10838) applied this identical fix but was closed without merging, so the vulnerability remains unresolved on
main. Re-verified with a freshnpm auditbefore recreating this change.Risk assessment
undiciis not a direct dependency; it is pulled in transitively by@actions/artifact,@actions/github,@actions/http-client, and@github/local-action, all devDependencies used for local Action testing/tooling, not the Astro docs build or dashboard runtime.overridespin rather than bumping any direct dependency, avoiding the@github/local-action@5.2.0major-version downgrade thatnpm audit fix --forcewould otherwise force.undicidirectly; it is only exercised via the GitHub Actions SDK HTTP clients used in dev/test tooling.Validation
npm install(clean install with the override),npm audit --json(0 vulnerabilities after, vs 5 before),npm run typecheck:cao(passed, no errors),npm run test:unit(350/357 pass; the 4 failures/3 cancellations were verified present identically on unpatchedmainbefore this change — unrelated pre-existing issues:activity/cao.mjsdefault-location tests, telemetry cache-absent tests, CAO policyresolve-policyworker-identity check, and a clean-room compilation settings test)npm auditnow reports 0 vulnerabilities (was 4 moderate + 1 high); allundicicopies inpackage-lock.jsonresolve to6.28.1.npm run compile/npm run docs:build(no.mdworkflow source or docs content changed by this PR) or the dashboard site's own test suite (unaffected — separatedashboard/site/package.json, already audited clean with 0 vulnerabilities in this run).Control Plane
Toolchain: Node/npm as pinned by CI (no
enginesfield declared inpackage.json; used the preinstalled npm in the workflow runner). Registry preflight: npm registry fully reachable, no auth issues. No breaking changes — this is anoverridespin only, no direct dependency version bump, no API surface change. Risk: low. Confidence: high (clean install, 0 audit findings, typecheck clean, no test regressions beyond pre-existing baseline failures verified on main).Rollback: revert this commit (removes the
overridesblock frompackage.jsonand restorespackage-lock.json); no other files are affected.Smart-Dependabot-Merge-Candidate: yes
Reviewer checklist
Rollback guidance
undiciresolution.package.jsonandpackage-lock.jsonmust be reverted together (lockfile was regenerated from the override).