Skip to content

fix(deps): update undici to 5.28.5#1348

Merged
jennifer-shehane merged 1 commit into
cypress-io:masterfrom
MikeMcC399:update/undici
Jan 23, 2025
Merged

fix(deps): update undici to 5.28.5#1348
jennifer-shehane merged 1 commit into
cypress-io:masterfrom
MikeMcC399:update/undici

Conversation

@MikeMcC399

@MikeMcC399 MikeMcC399 commented Jan 22, 2025

Copy link
Copy Markdown
Collaborator

Issue

Dependabot reports the vulnerability CVE-2025-22150 with Moderate severity in the transient dependency undici@5.28.4.

$ npm ls undici
@cypress/github-action
└─┬ @actions/cache@4.0.0
  └─┬ @actions/http-client@2.2.3
    └── undici@5.28.4

Change

Update to undici@5.28.5 by removing undici@5.28.4 from package-lock.json, deleting node_modules and running npm install.

This resolves the moderate severity vulnerability CVE-2025-22150.

Related

@MikeMcC399 MikeMcC399 added bug Something isn't working type: dependencies labels Jan 22, 2025
@MikeMcC399 MikeMcC399 self-assigned this Jan 22, 2025
@cypress-app-bot

Copy link
Copy Markdown
Collaborator

@MikeMcC399 MikeMcC399 marked this pull request as ready for review January 22, 2025 09:37
@jennifer-shehane jennifer-shehane merged commit 433264a into cypress-io:master Jan 23, 2025
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 6.7.10 🎉

The release is available on:

Your semantic-release bot 📦🚀

@MikeMcC399 MikeMcC399 deleted the update/undici branch January 23, 2025 15:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants