Skip to content

Bump undici to 8.11.2 to clear GHSA-vp8m-p9jh-q5pm - #14

Merged
simon--poole merged 1 commit into
masterfrom
fix-undici-cve-2026-85152
Sep 30, 2026
Merged

simon--poole merged 1 commit into
masterfrom
fix-undici-cve-2026-85152

Conversation

@simon--poole

Copy link
Copy Markdown
Contributor

Fixes Dependabot alert #71 (CVE-2026-85152 / GHSA-vp8m-p9jh-q5pm: undici cross-origin cache poisoning, affects >= 8.10.0, < 8.10.2).

Summary

  • undici is a dev-only transitive dependency (jsdom@^30 → undici@^8.9.0). It is not part of the published package's runtime dependencies.
  • Ran npm update, which refreshes package-lock.json within the existing semver ranges. No ranges in package.json changed.
    • undici 8.10.0 → 8.11.2 (also clears 10 other undici advisories)
    • brace-expansion 5.0.9 → 5.0.12 (via c8, clears GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p)
    • Other dev deps got patch/minor bumps (e.g. jsdom 30.1.1, playwright 1.63.0, @swc/core 1.16.12). fsevents dropped out because Playwright 1.63 no longer lists it as an optional dependency.
  • Updated the allowScripts pin from @swc/core@1.16.0 to @swc/core@1.16.12 so the existing install-script policy still applies.

Manifests checked

Manifest Before After
package-lock.json 2 high (undici 8.10.0, brace-expansion 5.0.9) 0 vulnerabilities
demo/package-lock.json 0 vulnerabilities (no undici) 0 vulnerabilities (unchanged)

npm audit --omit=dev (root): 0 vulnerabilities.

Verification (local, Node 26.7.0 / npm 11.19.0)

  • npm ci (clean): OK
  • npm test (build + oxlint + oxfmt check + ava/c8): 102 passed
  • npm run test:browser (Playwright/Chromium): 10 passed
  • npm run demo:build: OK

The React 18/19 matrix runs in CI.

Release / deployment

No release needed. The change only touches dev dependencies and the lockfile, and the published tarball (dist, src, docs) and its space-router runtime dependency are unchanged. It can go out with the next normal release.

Remaining

  • npm outdated still lists typescript 7.0.2 and oxfmt 0.71.0. Both are major/0.x bumps outside the current ranges, with no associated advisories, so they're left out of this PR.

🤖 Generated with Claude Code

npm update refreshes the lockfile within existing semver ranges, moving
the dev-only transitive undici (via jsdom) from 8.10.0 to 8.11.2 and
brace-expansion (via c8) from 5.0.9 to 5.0.12. Update the @swc/core
allowScripts pin to match the refreshed 1.16.12.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: medium. Approved. Cursor Bugbot passed with no findings; Cursor Security Agent was not running. No reviewers were assigned.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver - Risk Based

@simon--poole
simon--poole merged commit 23af33f into master Sep 30, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant