Skip to content

Dependabot reports CVE-2025-22150 for undici <5.28.5 #1939

@MikeMcC399

Description

@MikeMcC399

Dependabot is reporting CVE-2025-22150 for undici <5.28.5.

It would be helpful if actions/toolkit updated to a patched undici version, such as 5.28.5 to force installation of a non-vulnerable version of undici.

The following shows usage in this repo:

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions