Skip to content

chore(deps): bump undici from 7.25.0 to 7.29.0 - #410

Merged
Sun-sunshine06 merged 12 commits into
mainfrom
dependabot/npm_and_yarn/undici-7.29.0
Sep 23, 2026
Merged

Sun-sunshine06 merged 12 commits into
mainfrom
dependabot/npm_and_yarn/undici-7.29.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026 •

Copy link
Copy Markdown
Contributor

Updates the desktop runtime dependency undici from 7.25.0 to 7.29.0 and regenerates the lockfile against current main, preserving the separately merged Vite, tsx, and yaml upgrades.

The original lockfile refresh introduced nanoid 3.3.17, which is affected by GHSA-2v37-7h3g-55p8. All nanoid resolutions now use patched 3.3.19, including the existing PostCSS dependency. This remains a within-major upgrade of existing MIT-licensed packages; no new runtime dependency is added.

Validation: frozen-lockfile installation and local lint, typecheck, and full tests passed during preparation. The final merged lockfile is checked again by PR CI, dependency review, CodeQL, and Linux packaging smoke before completion.

dependabot Bot added 3 commits May 24, 2026 22:09
Bumps [yaml](https://github.com/eemeli/yaml) from 2.8.4 to 2.9.0.
- [Release notes](https://github.com/eemeli/yaml/releases)
- [Commits](eemeli/yaml@v2.8.4...v2.9.0)

---
updated-dependencies:
- dependency-name: yaml
  dependency-version: 2.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.3.2 to 7.3.5.
- [Release notes](https://github.com/vitejs/vite/releases)
- [Changelog](https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite/commits/v7.3.5/packages/vite)

---
updated-dependencies:
- dependency-name: vite
  dependency-version: 7.3.5
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 7.25.0 to 7.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.25.0...v7.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.29.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added area:build Turbo/Vite/Biome/tsconfig toolchain chore Routine maintenance / non-feature work labels Aug 4, 2026
@github-actions github-actions Bot added the area:desktop apps/desktop (Electron shell, renderer) label Aug 4, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

  • None. This is a straightforward, security-motivated dependency bump and the lockfile change is internally consistent (apps/desktop/package.json:29, pnpm-lock.yaml undici@7.29.0).

Notes supporting that assessment:

  • undici stays a runtime dependency of apps/desktop (apps/desktop/package.json), is MIT-licensed, and is already within the ^7.25.0 range — this is a within-major bump from 7.25.0 to 7.29.0, not a new dependency, so the ≤ 30 prod-dependency constraint and the permissive-license constraint are unaffected.
  • The bump clears the advisories listed in the PR body (7.28.0 for the 7-advisory batch; 7.29.0 for the Cache-Control / cookie / retry fixes), which is the intended effect.
  • undici@7.29.0 declares engines.node: >=20.18.1 (pnpm-lock.yaml), compatible with the repo's pinned Node 22 (.nvmrc / engines).
  • The @mariozechner/pi-* snapshots now resolve to the same undici: 7.29.0, so pnpm simply deduped to the single bumped version; no duplicate-version drift was introduced.

Summary

  • Review mode: initial
  • The diff is limited to apps/desktop/package.json and pnpm-lock.yaml; no source, workflow, packaging, or release-path files changed, so the release/distribution checks do not apply to this PR.
  • No correctness, security, data-loss, or project-constraint findings. The change is well-scoped and consistent between manifest and lockfile.
  • Residual observation (not a blocker, and not filed as a finding): the regenerated lockfile also pulls in unrelated in-range transitive updates to build/dev tooling — e.g. lightningcss 1.32.0 → 1.33.0, postcss 8.5.15 → 8.5.25, nanoid 3.3.12 → 3.3.17, picomatch 4.0.4 → 4.0.5, tinyglobby 0.2.16 → 0.2.17, and @babel/runtime/@babel/code-frame 7.29.x. These are devDependencies-only build tools, all within existing semver ranges, and are a normal side effect of Dependabot regenerating the pnpm lockfile, so they do not block merge. If maintainers want to keep security bumps reviewable in isolation, they can rebase/regenerate on a fresh main, but that is optional.
  • No changeset: this is a dependency security bump with no user-visible behavior change surfaced in app code, so a changeset is not expected here.

Testing

  • Not run (automation). Recommended: let CI run pnpm install --frozen-lockfile, pnpm lint && pnpm typecheck && pnpm test, and the desktop build; a green run is sufficient given there is no source change.

Open-CoDesign Bot

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

  • [Minor] The regenerated lockfile now records the pinned @xmldom/xmldom@0.8.13 as deprecated — its lockfile entry gains deprecated: this version has critical issues, please update to the latest version (pnpm-lock.yaml, @xmldom/xmldom@0.8.13 entry, added in this diff), while the root override "@xmldom/xmldom@<0.8.13": "0.8.13" (package.json) still forces every lower range onto exactly that version. The undici bump does not cause this, but the refreshed registry metadata surfaces it, and the pin blocks moving to a fixed release.
    Suggested fix: handle in a follow-up issue rather than this PR — verify the current upstream @xmldom/xmldom release line and raise the override floor/target to the fixed version, then regenerate the lockfile.

Summary

  • Review mode: follow-up after new commits
  • The PR's own diff is unchanged in scope and correct: apps/desktop/package.json:28 bumps undici ^7.25.0 → ^7.29.0, and pnpm-lock.yaml resolves undici@7.29.0 consistently for the apps/desktop importer and the @mariozechner/pi-* snapshots (no duplicate undici versions).
  • The interdiff since the previous bot review contains substantial changes that are not part of this PR (Atlas Cloud provider onboarding, README updates, CodeQL workflow pin updates, tsx bump) — i.e. the head now sits on top of newer main commits. Those lines are not attributable to this PR and were not reviewed as PR content.
  • Nothing new changes the previous assessment for the bump itself: it is a within-major security update, undici remains a single MIT-licensed prod dependency of apps/desktop, and undici@7.29.0 declares engines.node: >=20.18.1, compatible with the repo's Node 22 pin. The ≤ 30 prod-dependency budget and permissive-license constraints are unaffected.
  • Residual observation (not a finding, unchanged from the previous review): the regenerated lockfile still carries unrelated in-range transitive updates to dev/build tooling — lightningcss 1.32.0 → 1.33.0 (both versions present), postcss 8.5.15 → 8.5.28, nanoid, picomatch, tinyglobby, @babel/runtime/@babel/code-frame 7.29.7. These are devDependencies-only and a normal Dependabot lockfile-regeneration side effect; regenerating on a fresh main is optional and non-blocking.
  • Aside from the @xmldom/xmldom deprecation note above, this PR is ready to merge once CI is green. No changeset is expected for a dependency security bump with no user-visible behavior change.

Testing

  • Not run (automation). Recommended: let CI run pnpm install --frozen-lockfile, pnpm lint && pnpm typecheck && pnpm test, and the desktop build; a green run is sufficient since no source files changed.

Open-CoDesign Bot

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

  • [Minor] The new commits add dependency changes the PR title/body do not cover. This PR is titled and described as undici 7.25.0 → 7.29.0, but the manifest diff also raises vite ^7.3.2 → ^7.3.5 (apps/desktop/package.json:64) and repins yaml 2.8.4 → 2.9.0 (packages/shared/package.json:20). yaml is a shipped prod dependency of @open-codesign/shared and is exact-pinned, so that is a deliberate prod change, not a lockfile-only refresh — someone approving “undici 7.25.0 → 7.29.0” would not expect it, and Dependabot will not update the description for you.
    Suggested fix / next action: either edit the PR title/body to list all three upgrades (a comment noting they came from the same lockfile regeneration is also fine), or revert those two manifest lines and let the Vite/YAML updates land in their own PR. Both are within-major upgrades of packages already in the tree and add no new prod dependency, so this is scope hygiene rather than a safety concern.

Questions

  • Are the vite and yaml bumps intentional parts of this PR, or an artifact of the branch being refreshed against newer main? If intentional, please update the PR body so the review record matches what is being approved.

Summary

  • Review mode: follow-up after new commits
  • No blockers. The advertised change is correct and internally consistent: undici resolves to a single 7.29.0 in pnpm-lock.yaml, both in the apps/desktop importer and in the @mariozechner/pi-ai / pi-coding-agent snapshots, and the lockfile records undici@7.29.0 engines.node: >=20.18.1, compatible with the repo’s Node 22 pin. It is a within-major security update with no new prod dependency, so the ≤ 30 prod-dependency budget and permissive-license constraints are unaffected. No release/packaging or workflow files are touched.
  • The previous review’s @xmldom/xmldom@0.8.13 deprecation note is unchanged by the new commits, so it stays a follow-up item and not a blocker: the refreshed lockfile still records deprecated: this version has critical issues, please update to the latest version for the version forced by the root @xmldom/xmldom@<0.8.13 override in package.json, which prevents moving to a fixed release until the override is raised.
  • Residual observations (no action needed): the regenerated lockfile carries the usual in-range transitive churn introduced by these commits — rollup 4.60.2 → 4.62.0, @types/estree 1.0.9 added, plus the earlier lightningcss/postcss/nanoid/picomatch/tinyglobby moves — all dev/build-only. After this PR the lockfile holds two yaml copies (2.9.0 for packages/shared, 2.8.4 via the pi transitive snapshots); expected with an exact pin and negligible size cost.
  • The PR diff is limited to three files; anything outside them (other changes visible between review commits) is not attributable to this PR and was not reviewed as PR content.

Testing

  • Not run (automation). A green CI run (pnpm install --frozen-lockfile, pnpm lint && pnpm typecheck && pnpm test, desktop build) is sufficient for the undici bump. Because yaml is exact-pinned in a shipped package, also worth confirming the packages/shared YAML parsing tests pass at 2.9.0 (e.g. pnpm --filter @open-codesign/shared test) and running pnpm why yaml to confirm the duplicate copy is the pi transitive one.

Open-CoDesign Bot

@Sun-sunshine06
Sun-sunshine06 enabled auto-merge (squash) September 23, 2026 10:02

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Findings

No Blocker, Major, or Minor findings in the current diff.

Summary

  • Review mode: follow-up after new commits
  • The current PR diff against main is limited to the advertised change: apps/desktop/package.json:28 (undici ^7.25.0 → ^7.29.0) plus the matching lockfile resolution at pnpm-lock.yaml:70 (undici@7.29.0, engines.node: >=20.18.1).
  • The previous review's scope-hygiene item no longer applies: the vite/yaml manifest bumps it flagged are not part of the current diff, so the PR now matches its title/body. Resolved — no further action needed there.
  • The advertised security update is correct and internally consistent: undici resolves to a single 7.29.0 in the apps/desktop importer and in the @mariozechner/pi-ai / pi-coding-agent snapshots. engines.node >=20.18.1 is satisfied by the repo's Node 22 pin (package.json engines: >=22). It is a within-major security bump of an existing MIT-licensed prod dependency, adds no new dependency, and touches no release/packaging/workflow files, so the ≤30 prod-dependency and permissive-license constraints are unaffected.
  • Residual observations (no action needed): the lockfile refresh carries the usual in-range, dev/build-only transitive churn — lightningcss 1.32.0 → 1.33.0, postcss 8.5.15 → 8.5.28, nanoid 3.3.12 → 3.3.19, picomatch 4.0.4 → 4.0.7, @napi-rs/wasm-runtime 1.1.5 → 1.2.4, @tybys/wasm-util 0.10.2 → 0.10.4. The diff between the previous review commit and this head also contains unrelated main changes (Requesty proxy preset in packages/shared/src/proxy-presets.ts and .changeset/requesty-proxy-preset.md); those are not part of this PR's diff vs main and were not reviewed as PR content.

Questions

  • None.

Testing

  • Not run (automation). A green CI run (pnpm install --frozen-lockfile, pnpm lint && pnpm typecheck && pnpm test, desktop build) is sufficient for this bump. Optional: pnpm why undici to confirm the single 7.29.0 resolution.

Open-CoDesign Bot

@Sun-sunshine06
Sun-sunshine06 merged commit c871fdb into main Sep 23, 2026
7 checks passed
@Sun-sunshine06
Sun-sunshine06 deleted the dependabot/npm_and_yarn/undici-7.29.0 branch September 23, 2026 10:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area:build Turbo/Vite/Biome/tsconfig toolchain area:desktop apps/desktop (Electron shell, renderer) chore Routine maintenance / non-feature work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant