Skip to content

fix(deps): bump undici to ^6.24.0 (#2, #14, #15, #16, #17, #18)#11

Closed
ibuildthings-instrumentl wants to merge 1 commit intodevfrom
fix/dependabot-undici
Closed

fix(deps): bump undici to ^6.24.0 (#2, #14, #15, #16, #17, #18)#11
ibuildthings-instrumentl wants to merge 1 commit intodevfrom
fix/dependabot-undici

Conversation

@ibuildthings-instrumentl
Copy link
Copy Markdown
Collaborator

Summary

Test plan

  • bun install succeeds
  • Lockfile resolves undici to patched version
  • No runtime regressions in dependent packages

Generated with Claude Code

#18)

Fixes 6 vulnerabilities: WebSocket memory/exception issues, CRLF injection, 64-bit length overflow, HTTP smuggling, unbounded decompression. Transitive from discord.js and @discordjs/rest.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@ibuildthings-instrumentl
Copy link
Copy Markdown
Collaborator Author

Closing to recreate on top of latest dev (avoid merge conflicts)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant