From 6b445c476eeb63b5b1aaeb57d7285f4f9a32c4d4 Mon Sep 17 00:00:00 2001 From: Peter Bacon Darwin Date: Wed, 15 May 2024 14:17:22 +0100 Subject: [PATCH] chore: bump undici to 5.28.4 --- .changeset/lovely-needles-destroy.md | 8 +++++ .../playground-preview-worker/package.json | 2 +- packages/vitest-pool-workers/package.json | 2 +- packages/workers-playground/package.json | 2 +- packages/wrangler/package.json | 2 +- pnpm-lock.yaml | 31 ++++++++++++------- 6 files changed, 32 insertions(+), 15 deletions(-) create mode 100644 .changeset/lovely-needles-destroy.md diff --git a/.changeset/lovely-needles-destroy.md b/.changeset/lovely-needles-destroy.md new file mode 100644 index 0000000000..1b9b86073b --- /dev/null +++ b/.changeset/lovely-needles-destroy.md @@ -0,0 +1,8 @@ +--- +"playground-preview-worker": patch +"@cloudflare/vitest-pool-workers": patch +"workers-playground": patch +"wrangler": patch +--- + +fix: update undici to the latest version to avoid a potential vulnerability diff --git a/packages/playground-preview-worker/package.json b/packages/playground-preview-worker/package.json index 0ee4f99ddc..4f4ec244f7 100644 --- a/packages/playground-preview-worker/package.json +++ b/packages/playground-preview-worker/package.json @@ -24,7 +24,7 @@ "itty-router": "^4.0.13", "promjs": "^0.4.2", "toucan-js": "^3.2.2", - "undici": "5.28.3", + "undici": "5.28.4", "wrangler": "^3.32.0" } } diff --git a/packages/vitest-pool-workers/package.json b/packages/vitest-pool-workers/package.json index e910388c33..44ee7d3b57 100644 --- a/packages/vitest-pool-workers/package.json +++ b/packages/vitest-pool-workers/package.json @@ -59,7 +59,7 @@ "@types/semver": "^7.5.1", "capnp-ts": "^0.7.0", "capnpc-ts": "^0.7.0", - "undici": "5.28.3" + "undici": "5.28.4" }, "dependencies": { "birpc": "0.2.14", diff --git a/packages/workers-playground/package.json b/packages/workers-playground/package.json index 239e7caabb..cd7fa59375 100644 --- a/packages/workers-playground/package.json +++ b/packages/workers-playground/package.json @@ -61,7 +61,7 @@ "eslint-plugin-react-refresh": "^0.4.1", "tsx": "^3.12.8", "typescript": "^5.0.2", - "undici": "5.28.3", + "undici": "5.28.4", "vite-plugin-rewrite-all": "^1.0.1", "wrangler": "workspace:^" } diff --git a/packages/wrangler/package.json b/packages/wrangler/package.json index aa91f2a269..ee938b426a 100644 --- a/packages/wrangler/package.json +++ b/packages/wrangler/package.json @@ -192,7 +192,7 @@ "timeago.js": "^4.0.2", "ts-dedent": "^2.2.0", "ts-json-schema-generator": "^1.5.0", - "undici": "5.28.3", + "undici": "5.28.4", "update-check": "^1.5.4", "ws": "^8.5.0", "xdg-app-paths": "^8.3.0", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index 1f3859a1a8..669d380144 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -1221,8 +1221,8 @@ importers: specifier: ^3.2.2 version: 3.2.2(patch_hash=dxprwy4mawdnq3drjhp7shhm2m) undici: - specifier: 5.28.3 - version: 5.28.3 + specifier: 5.28.4 + version: 5.28.4 wrangler: specifier: ^3.32.0 version: link:../wrangler @@ -1365,8 +1365,8 @@ importers: specifier: ^0.7.0 version: 0.7.0 undici: - specifier: 5.28.3 - version: 5.28.3 + specifier: 5.28.4 + version: 5.28.4 packages/workers-playground: dependencies: @@ -1513,8 +1513,8 @@ importers: specifier: ^5.0.2 version: 5.0.3 undici: - specifier: 5.28.3 - version: 5.28.3 + specifier: 5.28.4 + version: 5.28.4 vite-plugin-rewrite-all: specifier: ^1.0.1 version: 1.0.1(vite@4.5.3) @@ -1826,8 +1826,8 @@ importers: specifier: ^1.5.0 version: 1.5.0 undici: - specifier: 5.28.3 - version: 5.28.3 + specifier: 5.28.4 + version: 5.28.4 update-check: specifier: ^1.5.4 version: 1.5.4 @@ -5545,6 +5545,11 @@ packages: resolution: {integrity: sha512-+KpH+QxZU7O4675t3mnkQKcZZg56u+K/Ct2K+N2AZYNVK8kyeo/bI18tI8aPm3tvNNRyTWfj6s5tnGNlcbQRsA==} engines: {node: '>=14'} + /@fastify/busboy@2.1.1: + resolution: {integrity: sha512-vBZP4NlzfOlerQTnba4aqZoMhE/a9HY7HRqoOPaETQcSQuWEIyZMHGfVu6w9wGtGK5fED5qRs2DteVCjOH60sA==} + engines: {node: '>=14'} + dev: true + /@gar/promisify@1.1.3: resolution: {integrity: sha512-k2Ty1JcVojjJFwrg/ThKi2ujJ7XNLYaFGNB/bWT9wGR+oSMJHMa5w+CUq6p/pVrKeNNgA7pCqEcjSnHVoqJQFw==} dev: true @@ -17307,6 +17312,10 @@ packages: /picocolors@1.0.0: resolution: {integrity: sha512-1fygroTLlHu66zi26VoTDv8yRgm0Fccecssto+MhsZ0D/DGW2sm8E8AjW7NU5VVTRt5GxbeZ5qBuJr+HyLYkjQ==} + /picocolors@1.0.1: + resolution: {integrity: sha512-anP1Z8qwhkbmu7MFP5iTt+wQKXgwzf7zTyGlcdzabySa9vd0Xt392U0rVmz9poOaBj0uHJKyyo9/upk0HrEQew==} + dev: true + /picomatch@2.3.1: resolution: {integrity: sha512-JU3teHTNjmE2VCGFzuY8EXzCDVwEqB2a8fsIvwaStHhAWJEeVd1o1QD80CU6+ZdEXXSLbSsuLwJjkCBWqRQUVA==} engines: {node: '>=8.6'} @@ -17506,7 +17515,7 @@ packages: engines: {node: ^10 || ^12 || >=14} dependencies: nanoid: 3.3.7 - picocolors: 1.0.0 + picocolors: 1.0.1 source-map-js: 1.2.0 dev: true @@ -20121,7 +20130,7 @@ packages: resolution: {integrity: sha512-wh1pHJHnUeQV5Xa8/kyQhO7WFa8M34l026L5P/+2TYiakvGy5Rdc8jWZVyG7ieht/0WgJLEd3kcU5gKx+6GC8w==} engines: {node: '>=14.0'} dependencies: - '@fastify/busboy': 2.1.0 + '@fastify/busboy': 2.1.1 dev: true /undici@5.28.3: @@ -20134,7 +20143,7 @@ packages: resolution: {integrity: sha512-72RFADWFqKmUb2hmmvNODKL3p9hcB6Gt2DOQMis1SEBaV6a4MH8soBvzg+95CYhCKPFedut2JY9bMfrDl9D23g==} engines: {node: '>=14.0'} dependencies: - '@fastify/busboy': 2.1.0 + '@fastify/busboy': 2.1.1 dev: true /unicode-canonical-property-names-ecmascript@2.0.0: