diff --git a/.changeset/good-mugs-tease.md b/.changeset/good-mugs-tease.md new file mode 100644 index 000000000000..e81ddceaeb36 --- /dev/null +++ b/.changeset/good-mugs-tease.md @@ -0,0 +1,5 @@ +--- +"wrangler": patch +--- + +fix: bump undici to v5.5.1 (CVE patch) diff --git a/package-lock.json b/package-lock.json index 8adfdb58c7ba..defff8701e9f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -20736,7 +20736,7 @@ "timeago.js": "^4.0.2", "tmp-promise": "^3.0.3", "ts-dedent": "^2.2.0", - "undici": "^5.3.0", + "undici": "^5.5.1", "update-check": "^1.5.4", "ws": "^8.5.0", "yargs": "^17.4.1" @@ -21178,6 +21178,15 @@ "url": "https://github.com/chalk/supports-color?sponsor=1" } }, + "packages/wrangler/node_modules/undici": { + "version": "5.5.1", + "resolved": "https://registry.npmjs.org/undici/-/undici-5.5.1.tgz", + "integrity": "sha512-MEvryPLf18HvlCbLSzCW0U00IMftKGI5udnjrQbC5D4P0Hodwffhv+iGfWuJwg16Y/TK11ZFK8i+BPVW2z/eAw==", + "dev": true, + "engines": { + "node": ">=12.18" + } + }, "packages/wrangler/node_modules/ws": { "version": "8.5.0", "resolved": "https://registry.npmjs.org/ws/-/ws-8.5.0.tgz", @@ -35601,7 +35610,7 @@ "timeago.js": "^4.0.2", "tmp-promise": "^3.0.3", "ts-dedent": "^2.2.0", - "undici": "^5.3.0", + "undici": "^5.5.1", "update-check": "^1.5.4", "ws": "^8.5.0", "xxhash-wasm": "^1.0.1", @@ -35814,6 +35823,12 @@ "integrity": "sha512-XC6g/Kgux+rJXmwokjm9ECpD6k/smUoS5LKlUCcsYr4IY3rW0XyAympon2RmxGrlnZURMpg5T18gWDP9CsHXFA==", "dev": true }, + "undici": { + "version": "5.5.1", + "resolved": "https://registry.npmjs.org/undici/-/undici-5.5.1.tgz", + "integrity": "sha512-MEvryPLf18HvlCbLSzCW0U00IMftKGI5udnjrQbC5D4P0Hodwffhv+iGfWuJwg16Y/TK11ZFK8i+BPVW2z/eAw==", + "dev": true + }, "ws": { "version": "8.5.0", "resolved": "https://registry.npmjs.org/ws/-/ws-8.5.0.tgz", diff --git a/packages/wrangler/package.json b/packages/wrangler/package.json index 99897bc8422a..f815d0cb671d 100644 --- a/packages/wrangler/package.json +++ b/packages/wrangler/package.json @@ -99,7 +99,7 @@ "timeago.js": "^4.0.2", "tmp-promise": "^3.0.3", "ts-dedent": "^2.2.0", - "undici": "^5.3.0", + "undici": "^5.5.1", "update-check": "^1.5.4", "ws": "^8.5.0", "yargs": "^17.4.1"