Skip to content

chore: override undici to ^7.29.0 and ip-address to ^10.3.1 - #293

Merged
xyos merged 1 commit into
mainfrom
fix/override-undici-ip-address-main
Aug 7, 2026
Merged

chore: override undici to ^7.29.0 and ip-address to ^10.3.1#293
xyos merged 1 commit into
mainfrom
fix/override-undici-ip-address-main

Conversation

@xyos

@xyos xyos commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Issue

Description of Changes

Bumps npm dependency override versions flagged by the nightly Security Scan (Amazon Inspector, code-editor-sagemaker-server target) and regenerates the affected package-lock overrides + OSS attribution.

  • undici: ^7.28.0 -> ^7.29.0
  • ip-address: ^10.1.1 -> ^10.3.1

The downstream finding-override-{axios,form-data,github-copilot,tar,ws}.diff patches are refreshed only for diff-context drift in the shared root overrides block; their own override versions are unchanged.

brace-expansion (in build-tools/oss-attribution/oss-attribution-generator) is NOT included here: the ^5.0.8 -> ^5.0.9 bump on main is already covered by open Dependabot PR #292.

Testing

  • ./scripts/prepare-src.sh code-editor-sagemaker-server applies the full patch series cleanly after the rebase-heal.
  • Package-lock overrides regenerated for all four targets (per scripts/update-package-locks.sh flow) and unified OSS attribution regenerated, both inside the code-editor-ubuntu container.
  • Verified resolved versions with jq in all 8 lockfiles (4 series, root + remote/): undici 7.29.0 and ip-address 10.4.0 (>= 10.3.1) everywhere.
  • LICENSE-THIRD-PARTY diff is exactly the two version lines (ip-address 10.2.0 -> 10.4.0, undici 7.28.0 -> 7.29.0).

Screenshots/Videos

N/A

Additional Notes

Override-only change; no source/behavior changes. Patch headers keep the deterministic @generator metadata (scripts/patches/apply-override.sh) so they can be regenerated on upstream bumps.

Backporting

The same fix is being raised as separate PRs against 1.0, 1.1, and 1.2. Those PRs additionally include the brace-expansion ^5.0.9 build-tool bump, since Dependabot #292 targets main only.


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Bumps the undici and ip-address dependency override versions flagged by the nightly Security Scan and regenerates the affected package-lock overrides and OSS attribution. Downstream finding-override patches (axios, form-data, github-copilot, tar, ws) are refreshed only for context drift in the shared overrides block; their own override versions are unchanged.
@xyos
xyos requested a review from a team as a code owner August 7, 2026 14:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants