Skip to content

fix(deps): pin Undici 6 and 7 to aged advisory patches - #135

Draft
RecursiveIntell wants to merge 1 commit into
mainfrom
codex/undici-advisory-patches-20261006
Draft

RecursiveIntell wants to merge 1 commit into
mainfrom
codex/undici-advisory-patches-20261006

Conversation

@RecursiveIntell

@RecursiveIntell RecursiveIntell commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

The root lock contains affected Undici 6.28.0 and 7.29.0. Pin the existing majors to 6.28.1 and 7.29.1, update the TUI's exact production pin, and regenerate only their corresponding root-lock records.

Exactly three files change: package.json, ui-tui/package.json, and package-lock.json. The lock retains all 1,492 package entries; only the TUI workspace pin and three installed Undici records change. Development/optional flags, engines, provider/profile/semantic interfaces, release aging, exceptions and install-script authorization remain unchanged. Both patch releases were published September 4 and satisfy the existing 14-day policy. Official registry metadata.

The TUI conditionally selects Undici WebSocket when a global WebSocket is unavailable, and gateway/sidecar constructors pass no requested subprotocol. Runtime fallback selection, triggering peer access and compression negotiation remain unverified. This update does not change Node/Electron's embedded WebSocket or Photon’s standalone lock.

Official advisories applicable to both existing majors: unrequested subprotocol, compressed-frame errors, retry response framing. Additional major7 advisory coverage: retry-body resources, compressed responses, shared-cache cookies, dump truncation, BalancedPool TLS, unsafe-method caching, WebSocketStream close handling. These are ten advisory records, not ten established Ares exploits.

Validation:

  • Independent exact-diff source review accepted the three-file patch with source-only limits.
  • Canonical npm 12 targeted lock-only resolution and byte-identical offline replay.
  • 60 captured offline artifact invariants and 12 patch replay operations, including byte-exact rollback and identical composition with PR fix(desktop): align Electron pins with 41.10.6 advisory fixes #132 in either order.
  • The local source stage performed no dependency installation, script/build execution or actual network canary. Running Ares and the frozen package remain untouched; later qualification ran only in hosted disposable CI.

Exact source base: commit e3e8a39d9427354eeba014c21c9c916078fb0cdb, tree ca7eceddd67275ad5ac0171af5545fad5a04eed0.
Reviewed forward patch SHA256: f74e691afe9aaa63c655781f3593b6c574aad510950c346a6c4a59ef73d5b4de.
Validated rollback patch SHA256: 92b8e5d281d257f0ab12797f4c3f7fba1a24751274de4a037986d81652a0a876.

Rollback: revert this focused source commit to restore the exact three base files; recheck reverse-patch applicability after any integration/rebase. Running installations are outside this source rollback.

Hosted qualification on exact head 4d9b9634f4e6589ea557a6049e9b0ce714f24bb5 completed: CI, including the TUI check and semantic lockfile check, and Nix flake check succeeded. The Docker workflow concluded successfully with its build/publish jobs skipped; no Docker build qualification is claimed. Across 41 check runs: 25 success, 1 neutral OSV, 15 skipped, with no failures or active checks.

The candidate SARIF artifact has 110 raw rows, 70 GHSA-preferred advisory keys and 90 deduplicated advisory/package/version/lock-path occurrences. It reports zero Undici findings in the root lock and ten in the unchanged Photon standalone lock. ZIP SHA256: 9ddc5699d78afb4c3772f721e5312c462e12b0ae32d44ca40b5ceb49a2816c83. This is a candidate-only snapshot, without an exact-base comparison against the same advisory database; aggregate counts and the warning-only/neutral scanner status do not certify blanket closure. Other locks retain findings.

Existing GatewayClient tests mock Undici; their passing covers application compatibility rather than library security mechanisms. Native embedded WebSocket and live runtime behavior were not exercised. Keep this focused source repair in draft for the publication owner's review.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 4d9b963 — fix(deps): pin Undici 6 and 7 to aged advisory patches

⚠️ Action required

package-lock.json · View job

Locked npm dependency versions changed.

package-lock.json

Package Before After
undici (nested under @electron/get) 7.29.0 7.29.1
undici (nested under jsdom) 7.29.0 7.29.1
undici 6.28.0 6.28.1

How to fix:

Add the ci-reviewed label after verifying the version changes are expected.


⚠️ Warnings

OSV vulnerability scan · View job

110 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.


debug info

CI timings

CI timings · View report · View job

Wall time 5m13s vs 6m49s (-23.5%). 14 job(s) slower, 5 faster,

  • JS & TS checks / apps/desktop / check:lint: +58.0s
  • JS & TS checks / apps/desktop / check:test:ui:shard-2of3: +56.0s
  • JS & TS checks / apps/desktop / check:test:ui:shard-3of3: -55.0s
  • JS & TS checks / apps/desktop / check:test:desktop:all: +51.0s
  • JS & TS checks / apps/bootstrap-installer / check: +51.0s

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant