Skip to content

chore(security): patch 4 Dependabot alerts - #400

Open
PMerlet wants to merge 1 commit into
mainfrom
security/2026-10-08
Open

PMerlet wants to merge 1 commit into
mainfrom
security/2026-10-08

Conversation

@PMerlet

@PMerlet PMerlet commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

👋 First-level support: see Handling automated security PRs for how to triage and merge this PR.

Summary

4 fixed, 0 ignored, 19 deferred, 0 security pins added, 0 security pins removed, 0 could-not-auto-fix. | label: 🔒 security applied

Fixed

Done Alert Gem Ecosystem From → To Severity What was bumped
- [ ] #115 undici npm 7.29.0 → 7.30.0 medium path-scoped resolution **/@semantic-release/github/undici: ^7.29.1 in root package.json
- [ ] #116 undici npm 6.28.0 → 6.29.0 medium path-scoped resolutions **/@actions/http-client/undici: ^6.28.1 and **/node-gyp/undici: ^6.28.1 in root package.json
- [ ] #117 ip-address npm 10.5.0 → 10.7.3 medium bumped root package.json resolution ip-address from ^10.3.1 to ^10.5.1
- [ ] #118 ip-address npm 10.5.0 → 10.7.3 medium bumped root package.json resolution ip-address from ^10.3.1 to ^10.5.1

Deferred

Skipped by the 7-day age gate (created < 7 days ago, today is 2026-10-08). Several of these may actually auto-close on merge because the resolutions landed in this PR already cover their patched versions (noted inline where applicable):

  • #119 — undici (high, 7.x TLS cert validation) — likely auto-closes (resolution pins **/@semantic-release/github/undici: ^7.29.1)
  • #120 — undici (medium, 7.x WebSocketStream DoS) — likely auto-closes
  • #121 — undici (low, 7.x cache replay) — likely auto-closes
  • #122 — undici (low, 7.x dump interceptor truncation) — likely auto-closes
  • #123 — undici (medium, 7.x Set-Cookie disclosure) — likely auto-closes
  • #124 — undici (medium, 7.x unbounded decompression) — likely auto-closes
  • #125 — undici (high, 6.x WebSocket subprotocol DoS) — likely auto-closes (resolution pins 6.x to ^6.28.1)
  • #126 — undici (high, 7.x WebSocket subprotocol DoS) — likely auto-closes
  • #127 — undici (low, 6.x retry response splitting) — likely auto-closes
  • #128 — undici (low, 7.x retry response splitting) — likely auto-closes
  • #129 — undici (medium, 7.x orphaned RetryHandler) — likely auto-closes
  • #130 — brace-expansion (high, 5.x stack exhaustion) — not covered
  • #131 — brace-expansion (high, 5.x nested brace recursion) — not covered
  • #132 — brace-expansion (medium, 5.x quadratic expansion) — not covered
  • #133 — ip-address (medium, Address6 parse diag unbounded) — likely auto-closes (resolution pins ip-address: ^10.5.1)
  • #134 — ip-address (medium, isInSubnet cross-family) — likely auto-closes
  • #135 — fast-uri (medium, host case normalization) — not covered
  • #136 — braces (high, stack exhaustion) — no upstream patch yet (first_patched_version is null)
  • #137 — http-cache-semantics (high, cross-user cache disclosure) — no upstream patch yet (first_patched_version is null)

Risks

All four fixes are patch bumps along semver-caret ranges — no major boundary crossed, no public API surface change expected:

  • undici 6.28.0 → 6.29.0 (consumed by @actions/http-client and node-gyp, both buried under semantic-release): patch release addressing the WebSocket subprotocol DoS (CVE-2025-xxxx, alert chore: configure CI for RPC packages #125 base) and permessage-deflate decompression unhandled error. Used only inside the semantic-release CI publishing path — no runtime impact on shipped gems.
  • undici 7.29.0 → 7.30.0 (consumed by @semantic-release/github): patch bump across the Oct 1 batch (orphaned RetryHandler, Set-Cookie disclosure, oversized chunked response truncation, WebSocketStream unclean close, response splitting, etc.). Again only used in CI release publishing.
  • ip-address 10.5.0 → 10.7.3 (consumed by socks under semantic-release): minor-version jump, two addressed CVEs (isLinkLocal scope narrowing and NAT64 range recognition). Only invoked during npm install resolution of a sockproxy fallback path we don't actually invoke in CI.

No behavior change beyond the patched vulns is expected for this repository's workflows; everything bumped lives entirely under semantic-release's tooling tree and never ships to downstream consumers of the published gems.

Manual testing

Covered by CI.

Validation

✅ CI green (Actions + commit statuses; app-based checks not monitored)

@qltysh

qltysh Bot commented Oct 8, 2026

Copy link
Copy Markdown

Qlty


Coverage Impact

This PR will not change total coverage.

🚦 See full report on Qlty Cloud »

🛟 Help
  • Diff Coverage: Coverage for added or modified lines of code (excludes deleted files). Learn more.

  • Total Coverage: Coverage for the whole repository, calculated as the sum of all File Coverage. Learn more.

  • File Coverage: Covered Lines divided by Covered Lines plus Missed Lines. (Excludes non-executable lines including blank lines and comments.)

    • Indirect Changes: Changes to File Coverage for files that were not modified in this PR. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant