Skip to content

fix(deps): bump undici to >=6.24.0 (Dependabot #2, #14-18)#17

Merged
ibuildthings-instrumentl merged 1 commit intodevfrom
fix/dep-undici
Apr 20, 2026
Merged

fix(deps): bump undici to >=6.24.0 (Dependabot #2, #14-18)#17
ibuildthings-instrumentl merged 1 commit intodevfrom
fix/dep-undici

Conversation

@ibuildthings-instrumentl
Copy link
Copy Markdown
Collaborator

Summary

Test plan

  • bun install succeeds
  • Lockfile resolves undici to patched version

Fixes 6 vulnerabilities: WebSocket memory/exception issues, CRLF injection,
64-bit length overflow, HTTP smuggling, unbounded decompression.
Transitive from discord.js and @discordjs/rest.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant