Repository navigation
deps: bump undici to 8.11.2 and ip-address to 10.7.2 (Dependabot #228, #224, #225) - #15056
Merged
Merged
Conversation
…#224, #225) - undici >= 8.10.2: unhandled error in WebSocket permessage-deflate decompression could crash the process (DoS). undici is a runtime dependency (proxyFetch, proxyDispatcher, SOCKS connector, video bridge). - ip-address >= 10.5.1: Address6.isLinkLocal() matched fe80::/64 instead of fe80::/10, and no classifier recognised the NAT64 local-use range 64:ff9b:1::/48 — both let an SSRF / trust check treat a local address as public. Bumped the override to ^10.7.2 (the version the opencode-plugin-v2 lock already uses) and the Dockerfile's patched npm-bundled copy from the still-vulnerable 10.5.0 to 10.7.2. Lockfile regenerated with --package-lock-only; no other version moved.
Owner
Author
|
Validation on 192.168.0.113, run on a clean
|
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves Dependabot alerts #228 (undici), #224 and #225 (ip-address). Supersedes #15028, which bumps only undici.
undici
^8.10.0→^8.11.2(runtime)In
< 8.10.2, an unhandled error in WebSocket permessage-deflate decompression can crash the process (DoS). undici is a runtime dependency here:proxyFetch,proxyDispatcher, the SOCKS connector,proxyFallback, the video bridge and the proxy test routes.ip-address override
^10.3.1→^10.7.2(runtime, transitive viasocks)Both
<= 10.5.0advisories let a trust or SSRF check treat a local address as public:Address6.isLinkLocal()matchedfe80::/64instead offe80::/10;64:ff9b:1::/48.10.7.2is the version the@omniroute/opencode-plugin-v2lock already uses. TheDockerfileoverlay that patches npm's own bundled copy usedip-address@10.5.0, which is still vulnerable, and now uses10.7.2. The CVE note above that overlay is updated to match.Scope and validation
package-lock.jsonwas regenerated with--package-lock-only, and no other version moved. The diff is those two packages.npm ciof this branch, the proxyFetch, proxy-dispatcher, SOCKS and proxy-fallback suites, the SSRF-guard suites,check-deps,typecheck:coreandcheck:open-sse-typecheck. Results are in the comment below.