chore(deps): bump undici from 7.25.0 to 7.29.0 - #410
Merged
Merged
Conversation
Bumps [yaml](https://github.com/eemeli/yaml) from 2.8.4 to 2.9.0. - [Release notes](https://github.com/eemeli/yaml/releases) - [Commits](eemeli/yaml@v2.8.4...v2.9.0) --- updated-dependencies: - dependency-name: yaml dependency-version: 2.9.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.3.2 to 7.3.5. - [Release notes](https://github.com/vitejs/vite/releases) - [Changelog](https://github.com/vitejs/vite/blob/v7.3.5/packages/vite/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite/commits/v7.3.5/packages/vite) --- updated-dependencies: - dependency-name: vite dependency-version: 7.3.5 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [undici](https://github.com/nodejs/undici) from 7.25.0 to 7.29.0. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.25.0...v7.29.0) --- updated-dependencies: - dependency-name: undici dependency-version: 7.29.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
There was a problem hiding this comment.
Findings
- None. This is a straightforward, security-motivated dependency bump and the lockfile change is internally consistent (
apps/desktop/package.json:29,pnpm-lock.yamlundici@7.29.0).
Notes supporting that assessment:
undicistays a runtime dependency ofapps/desktop(apps/desktop/package.json), is MIT-licensed, and is already within the^7.25.0range — this is a within-major bump from7.25.0to7.29.0, not a new dependency, so the ≤ 30 prod-dependency constraint and the permissive-license constraint are unaffected.- The bump clears the advisories listed in the PR body (7.28.0 for the 7-advisory batch; 7.29.0 for the Cache-Control / cookie / retry fixes), which is the intended effect.
undici@7.29.0declaresengines.node: >=20.18.1(pnpm-lock.yaml), compatible with the repo's pinned Node 22 (.nvmrc/engines).- The
@mariozechner/pi-*snapshots now resolve to the sameundici: 7.29.0, so pnpm simply deduped to the single bumped version; no duplicate-version drift was introduced.
Summary
- Review mode: initial
- The diff is limited to
apps/desktop/package.jsonandpnpm-lock.yaml; no source, workflow, packaging, or release-path files changed, so the release/distribution checks do not apply to this PR. - No correctness, security, data-loss, or project-constraint findings. The change is well-scoped and consistent between manifest and lockfile.
- Residual observation (not a blocker, and not filed as a finding): the regenerated lockfile also pulls in unrelated in-range transitive updates to build/dev tooling — e.g.
lightningcss1.32.0 → 1.33.0,postcss8.5.15 → 8.5.25,nanoid3.3.12 → 3.3.17,picomatch4.0.4 → 4.0.5,tinyglobby0.2.16 → 0.2.17, and@babel/runtime/@babel/code-frame7.29.x. These aredevDependencies-only build tools, all within existing semver ranges, and are a normal side effect of Dependabot regenerating the pnpm lockfile, so they do not block merge. If maintainers want to keep security bumps reviewable in isolation, they can rebase/regenerate on a freshmain, but that is optional. - No changeset: this is a dependency security bump with no user-visible behavior change surfaced in app code, so a changeset is not expected here.
Testing
- Not run (automation). Recommended: let CI run
pnpm install --frozen-lockfile,pnpm lint && pnpm typecheck && pnpm test, and the desktop build; a green run is sufficient given there is no source change.
Open-CoDesign Bot
Contributor
There was a problem hiding this comment.
Findings
- [Minor] The regenerated lockfile now records the pinned
@xmldom/xmldom@0.8.13as deprecated — its lockfile entry gainsdeprecated: this version has critical issues, please update to the latest version(pnpm-lock.yaml,@xmldom/xmldom@0.8.13entry, added in this diff), while the root override"@xmldom/xmldom@<0.8.13": "0.8.13"(package.json) still forces every lower range onto exactly that version. The undici bump does not cause this, but the refreshed registry metadata surfaces it, and the pin blocks moving to a fixed release.
Suggested fix: handle in a follow-up issue rather than this PR — verify the current upstream@xmldom/xmldomrelease line and raise the override floor/target to the fixed version, then regenerate the lockfile.
Summary
- Review mode: follow-up after new commits
- The PR's own diff is unchanged in scope and correct:
apps/desktop/package.json:28bumpsundici^7.25.0→^7.29.0, andpnpm-lock.yamlresolvesundici@7.29.0consistently for theapps/desktopimporter and the@mariozechner/pi-*snapshots (no duplicate undici versions). - The interdiff since the previous bot review contains substantial changes that are not part of this PR (Atlas Cloud provider onboarding, README updates, CodeQL workflow pin updates,
tsxbump) — i.e. the head now sits on top of newermaincommits. Those lines are not attributable to this PR and were not reviewed as PR content. - Nothing new changes the previous assessment for the bump itself: it is a within-major security update,
undiciremains a single MIT-licensed prod dependency ofapps/desktop, andundici@7.29.0declaresengines.node: >=20.18.1, compatible with the repo's Node 22 pin. The ≤ 30 prod-dependency budget and permissive-license constraints are unaffected. - Residual observation (not a finding, unchanged from the previous review): the regenerated lockfile still carries unrelated in-range transitive updates to dev/build tooling —
lightningcss1.32.0 → 1.33.0 (both versions present),postcss8.5.15 → 8.5.28,nanoid,picomatch,tinyglobby,@babel/runtime/@babel/code-frame7.29.7. These are devDependencies-only and a normal Dependabot lockfile-regeneration side effect; regenerating on a freshmainis optional and non-blocking. - Aside from the
@xmldom/xmldomdeprecation note above, this PR is ready to merge once CI is green. No changeset is expected for a dependency security bump with no user-visible behavior change.
Testing
- Not run (automation). Recommended: let CI run
pnpm install --frozen-lockfile,pnpm lint && pnpm typecheck && pnpm test, and the desktop build; a green run is sufficient since no source files changed.
Open-CoDesign Bot
Contributor
There was a problem hiding this comment.
Findings
- [Minor] The new commits add dependency changes the PR title/body do not cover. This PR is titled and described as
undici7.25.0→7.29.0, but the manifest diff also raisesvite^7.3.2→^7.3.5(apps/desktop/package.json:64) and repinsyaml2.8.4→2.9.0(packages/shared/package.json:20).yamlis a shipped prod dependency of@open-codesign/sharedand is exact-pinned, so that is a deliberate prod change, not a lockfile-only refresh — someone approving “undici 7.25.0 → 7.29.0” would not expect it, and Dependabot will not update the description for you.
Suggested fix / next action: either edit the PR title/body to list all three upgrades (a comment noting they came from the same lockfile regeneration is also fine), or revert those two manifest lines and let the Vite/YAML updates land in their own PR. Both are within-major upgrades of packages already in the tree and add no new prod dependency, so this is scope hygiene rather than a safety concern.
Questions
- Are the
viteandyamlbumps intentional parts of this PR, or an artifact of the branch being refreshed against newermain? If intentional, please update the PR body so the review record matches what is being approved.
Summary
- Review mode: follow-up after new commits
- No blockers. The advertised change is correct and internally consistent:
undiciresolves to a single7.29.0inpnpm-lock.yaml, both in theapps/desktopimporter and in the@mariozechner/pi-ai/pi-coding-agentsnapshots, and the lockfile recordsundici@7.29.0engines.node: >=20.18.1, compatible with the repo’s Node 22 pin. It is a within-major security update with no new prod dependency, so the ≤ 30 prod-dependency budget and permissive-license constraints are unaffected. No release/packaging or workflow files are touched. - The previous review’s
@xmldom/xmldom@0.8.13deprecation note is unchanged by the new commits, so it stays a follow-up item and not a blocker: the refreshed lockfile still recordsdeprecated: this version has critical issues, please update to the latest versionfor the version forced by the root@xmldom/xmldom@<0.8.13override inpackage.json, which prevents moving to a fixed release until the override is raised. - Residual observations (no action needed): the regenerated lockfile carries the usual in-range transitive churn introduced by these commits —
rollup4.60.2 → 4.62.0,@types/estree1.0.9 added, plus the earlierlightningcss/postcss/nanoid/picomatch/tinyglobbymoves — all dev/build-only. After this PR the lockfile holds twoyamlcopies (2.9.0forpackages/shared,2.8.4via the pi transitive snapshots); expected with an exact pin and negligible size cost. - The PR diff is limited to three files; anything outside them (other changes visible between review commits) is not attributable to this PR and was not reviewed as PR content.
Testing
- Not run (automation). A green CI run (
pnpm install --frozen-lockfile,pnpm lint && pnpm typecheck && pnpm test, desktop build) is sufficient for theundicibump. Becauseyamlis exact-pinned in a shipped package, also worth confirming thepackages/sharedYAML parsing tests pass at 2.9.0 (e.g.pnpm --filter @open-codesign/shared test) and runningpnpm why yamlto confirm the duplicate copy is the pi transitive one.
Open-CoDesign Bot
Sun-sunshine06
enabled auto-merge (squash)
September 23, 2026 10:02
Contributor
There was a problem hiding this comment.
Findings
No Blocker, Major, or Minor findings in the current diff.
Summary
- Review mode: follow-up after new commits
- The current PR diff against
mainis limited to the advertised change:apps/desktop/package.json:28(undici^7.25.0→^7.29.0) plus the matching lockfile resolution atpnpm-lock.yaml:70(undici@7.29.0,engines.node: >=20.18.1). - The previous review's scope-hygiene item no longer applies: the
vite/yamlmanifest bumps it flagged are not part of the current diff, so the PR now matches its title/body. Resolved — no further action needed there. - The advertised security update is correct and internally consistent:
undiciresolves to a single7.29.0in theapps/desktopimporter and in the@mariozechner/pi-ai/pi-coding-agentsnapshots.engines.node >=20.18.1is satisfied by the repo's Node 22 pin (package.jsonengines: >=22). It is a within-major security bump of an existing MIT-licensed prod dependency, adds no new dependency, and touches no release/packaging/workflow files, so the ≤30 prod-dependency and permissive-license constraints are unaffected. - Residual observations (no action needed): the lockfile refresh carries the usual in-range, dev/build-only transitive churn —
lightningcss1.32.0 → 1.33.0,postcss8.5.15 → 8.5.28,nanoid3.3.12 → 3.3.19,picomatch4.0.4 → 4.0.7,@napi-rs/wasm-runtime1.1.5 → 1.2.4,@tybys/wasm-util0.10.2 → 0.10.4. The diff between the previous review commit and this head also contains unrelatedmainchanges (Requesty proxy preset inpackages/shared/src/proxy-presets.tsand.changeset/requesty-proxy-preset.md); those are not part of this PR's diff vsmainand were not reviewed as PR content.
Questions
- None.
Testing
- Not run (automation). A green CI run (
pnpm install --frozen-lockfile,pnpm lint && pnpm typecheck && pnpm test, desktop build) is sufficient for this bump. Optional:pnpm why undicito confirm the single7.29.0resolution.
Open-CoDesign Bot
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the desktop runtime dependency undici from 7.25.0 to 7.29.0 and regenerates the lockfile against current main, preserving the separately merged Vite, tsx, and yaml upgrades.
The original lockfile refresh introduced nanoid 3.3.17, which is affected by GHSA-2v37-7h3g-55p8. All nanoid resolutions now use patched 3.3.19, including the existing PostCSS dependency. This remains a within-major upgrade of existing MIT-licensed packages; no new runtime dependency is added.
Validation: frozen-lockfile installation and local lint, typecheck, and full tests passed during preparation. The final merged lockfile is checked again by PR CI, dependency review, CodeQL, and Linux packaging smoke before completion.