Repository navigation
Bump undici to 8.11.2 to clear GHSA-vp8m-p9jh-q5pm - #14
Merged
Merged
Conversation
npm update refreshes the lockfile within existing semver ranges, moving the dev-only transitive undici (via jsdom) from 8.10.0 to 8.11.2 and brace-expansion (via c8) from 5.0.9 to 5.0.12. Update the @swc/core allowScripts pin to match the refreshed 1.16.12. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Fixes Dependabot alert #71 (CVE-2026-85152 / GHSA-vp8m-p9jh-q5pm: undici cross-origin cache poisoning, affects
>= 8.10.0, < 8.10.2).Summary
undiciis a dev-only transitive dependency (jsdom@^30→undici@^8.9.0). It is not part of the published package's runtime dependencies.npm update, which refreshespackage-lock.jsonwithin the existing semver ranges. No ranges inpackage.jsonchanged.undici8.10.0 → 8.11.2 (also clears 10 other undici advisories)brace-expansion5.0.9 → 5.0.12 (viac8, clears GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p)jsdom30.1.1,playwright1.63.0,@swc/core1.16.12).fseventsdropped out because Playwright 1.63 no longer lists it as an optional dependency.allowScriptspin from@swc/core@1.16.0to@swc/core@1.16.12so the existing install-script policy still applies.Manifests checked
package-lock.jsondemo/package-lock.jsonnpm audit --omit=dev(root): 0 vulnerabilities.Verification (local, Node 26.7.0 / npm 11.19.0)
npm ci(clean): OKnpm test(build + oxlint + oxfmt check + ava/c8): 102 passednpm run test:browser(Playwright/Chromium): 10 passednpm run demo:build: OKThe React 18/19 matrix runs in CI.
Release / deployment
No release needed. The change only touches dev dependencies and the lockfile, and the published tarball (
dist,src, docs) and itsspace-routerruntime dependency are unchanged. It can go out with the next normal release.Remaining
npm outdatedstill liststypescript7.0.2 andoxfmt0.71.0. Both are major/0.x bumps outside the current ranges, with no associated advisories, so they're left out of this PR.🤖 Generated with Claude Code