From 3da53a7ba41b6265c8aed19dde50ac885c4f129e Mon Sep 17 00:00:00 2001 From: fro-bot <80104189+fro-bot@users.noreply.github.com> Date: Wed, 30 Sep 2026 05:03:22 +0000 Subject: [PATCH] fix(security): exclude vulnerable undici releases --- pnpm-lock.yaml | 10 +++++----- pnpm-workspace.yaml | 4 +++- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 2626a5c23..2f47e635d 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -14,7 +14,7 @@ overrides: picomatch: '>=4.0.4' postcss: '>=8.5.18' qs: '>=6.15.2' - undici: '>=8.9.0' + undici: '>=8.10.2' vite: '>=8.0.16' yaml: '>=2.8.3' @@ -2583,8 +2583,8 @@ packages: undici-types@8.9.0: resolution: {integrity: sha512-KTDyRTYX8sWmKXAikPHHSyc63CRPETMctyjKFupcC6OBLXT3xsN0e9aF7m+mIXutFWpUXuedtowG7iLOzp0kQg==} - undici@8.10.0: - resolution: {integrity: sha512-HvltHd7avK13QIw/oLe4qoOLyoVSoafqJ2jYOrtMRBkbYT31eiBQ8O0ehRKZiEZCMEyLFQNIADpgCWC5fALvYQ==} + undici@8.10.2: + resolution: {integrity: sha512-/y4/bH9YNU5hi9NIrpOuvGXFcxrj3CMrV+/AYpowAYTpHn8gX/XPFjNy766FPoYY0miQhdW977JFWKGNhBdwyQ==} engines: {node: '>=22.19.0'} unicode-segmenter@0.14.5: @@ -4219,7 +4219,7 @@ snapshots: package-json: 10.0.1 semver: 7.8.5 synckit: 0.11.12 - undici: 8.10.0 + undici: 8.10.2 transitivePeerDependencies: - '@eslint/json' @@ -5463,7 +5463,7 @@ snapshots: undici-types@8.9.0: {} - undici@8.10.0: {} + undici@8.10.2: {} unicode-segmenter@0.14.5: {} diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 5b7ae34fd..7f71e5ccb 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -18,7 +18,9 @@ overrides: picomatch: '>=4.0.4' postcss: '>=8.5.18' qs: '>=6.15.2' - undici: '>=8.9.0' + # GHSA-w293-vg96-wgc3, GHSA-vp8m-p9jh-q5pm, and GHSA-rfgv-xxqx-mfg5 affect <8.10.2. + # Remove this floor only when all parent ranges exclude the affected versions. + undici: '>=8.10.2' vite: '>=8.0.16' yaml: '>=2.8.3'