Repository navigation
fix(deps): pin Undici 6 and 7 to aged advisory patches - #135
Draft
RecursiveIntell wants to merge 1 commit into
Draft
RecursiveIntell wants to merge 1 commit into
RecursiveIntell wants to merge 1 commit into
Conversation
૮ >ﻌ< ა ci reviewran on 4d9b963 — fix(deps): pin Undici 6 and 7 to aged advisory patches
|
| Package | Before | After |
|---|---|---|
| undici (nested under @electron/get) | 7.29.0 |
7.29.1 |
| undici (nested under jsdom) | 7.29.0 |
7.29.1 |
| undici | 6.28.0 |
6.28.1 |
How to fix:
Add the ci-reviewed label after verifying the version changes are expected.
⚠️ Warnings
OSV vulnerability scan · View job
110 known vulnerabilities found in pinned dependencies.
- CVE-2026-103923 in package-lock.json
- CVE-2026-103923 in website/package-lock.json
- CVE-2026-104851 in uv.lock
- CVE-2026-84947 in plugins/platforms/photon/sidecar/package-lock.json
- CVE-2026-101917 in uv.lock
- CVE-2026-84933 in plugins/platforms/photon/sidecar/package-lock.json
- CVE-2026-103261 in uv.lock
- CVE-2026-85024 in plugins/platforms/photon/sidecar/package-lock.json
- CVE-2026-84890 in plugins/platforms/photon/sidecar/package-lock.json
- CVE-2026-101918 in uv.lock
- CVE-2026-104874 in uv.lock
- CVE-2026-84394 in package-lock.json
- CVE-2026-84394 in website/package-lock.json
- CVE-2026-104848 in website/package-lock.json
- CVE-2026-64847 in uv.lock
- GHSA-6688-9rhm-gjv2 in package-lock.json
- GHSA-6688-9rhm-gjv2 in website/package-lock.json
- CVE-2026-93749 in package-lock.json
- CVE-2026-93749 in website/package-lock.json
- CVE-2026-92599 in package-lock.json
How to fix:
Review the findings in the Security tab. Update the affected dependencies if a patched version is available.
debug info
CI timings
CI timings · View report · View job
Wall time 5m13s vs 6m49s (-23.5%). 14 job(s) slower, 5 faster,
- JS & TS checks / apps/desktop / check:lint: +58.0s
- JS & TS checks / apps/desktop / check:test:ui:shard-2of3: +56.0s
- JS & TS checks / apps/desktop / check:test:ui:shard-3of3: -55.0s
- JS & TS checks / apps/desktop / check:test:desktop:all: +51.0s
- JS & TS checks / apps/bootstrap-installer / check: +51.0s
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The root lock contains affected Undici 6.28.0 and 7.29.0. Pin the existing majors to 6.28.1 and 7.29.1, update the TUI's exact production pin, and regenerate only their corresponding root-lock records.
Exactly three files change:
package.json,ui-tui/package.json, andpackage-lock.json. The lock retains all 1,492 package entries; only the TUI workspace pin and three installed Undici records change. Development/optional flags, engines, provider/profile/semantic interfaces, release aging, exceptions and install-script authorization remain unchanged. Both patch releases were published September 4 and satisfy the existing 14-day policy. Official registry metadata.The TUI conditionally selects Undici WebSocket when a global WebSocket is unavailable, and gateway/sidecar constructors pass no requested subprotocol. Runtime fallback selection, triggering peer access and compression negotiation remain unverified. This update does not change Node/Electron's embedded WebSocket or Photon’s standalone lock.
Official advisories applicable to both existing majors: unrequested subprotocol, compressed-frame errors, retry response framing. Additional major7 advisory coverage: retry-body resources, compressed responses, shared-cache cookies, dump truncation, BalancedPool TLS, unsafe-method caching, WebSocketStream close handling. These are ten advisory records, not ten established Ares exploits.
Validation:
Exact source base: commit
e3e8a39d9427354eeba014c21c9c916078fb0cdb, treeca7eceddd67275ad5ac0171af5545fad5a04eed0.Reviewed forward patch SHA256:
f74e691afe9aaa63c655781f3593b6c574aad510950c346a6c4a59ef73d5b4de.Validated rollback patch SHA256:
92b8e5d281d257f0ab12797f4c3f7fba1a24751274de4a037986d81652a0a876.Rollback: revert this focused source commit to restore the exact three base files; recheck reverse-patch applicability after any integration/rebase. Running installations are outside this source rollback.
Hosted qualification on exact head
4d9b9634f4e6589ea557a6049e9b0ce714f24bb5completed: CI, including the TUI check and semantic lockfile check, and Nix flake check succeeded. The Docker workflow concluded successfully with its build/publish jobs skipped; no Docker build qualification is claimed. Across 41 check runs: 25 success, 1 neutral OSV, 15 skipped, with no failures or active checks.The candidate SARIF artifact has 110 raw rows, 70 GHSA-preferred advisory keys and 90 deduplicated advisory/package/version/lock-path occurrences. It reports zero Undici findings in the root lock and ten in the unchanged Photon standalone lock. ZIP SHA256:
9ddc5699d78afb4c3772f721e5312c462e12b0ae32d44ca40b5ceb49a2816c83. This is a candidate-only snapshot, without an exact-base comparison against the same advisory database; aggregate counts and the warning-only/neutral scanner status do not certify blanket closure. Other locks retain findings.Existing GatewayClient tests mock Undici; their passing covers application compatibility rather than library security mechanisms. Native embedded WebSocket and live runtime behavior were not exercised. Keep this focused source repair in draft for the publication owner's review.