Skip to content

fix(deps): move bundled undici to 6.29.0 for GHSA-rfgv-xxqx-mfg5 - #251

Merged
mbeacom merged 1 commit into
mainfrom
fix/undici-ghsa-rfgv
Sep 30, 2026
Merged

mbeacom merged 1 commit into
mainfrom
fix/undici-ghsa-rfgv

Conversation

@mbeacom

@mbeacom mbeacom commented Sep 30, 2026

Copy link
Copy Markdown
Owner

What and why

GHSA-rfgv-xxqx-mfg5 (published 2026-09-29, high) affects undici >= 6.7.0 < 6.28.1: a denial of service via an unrequested WebSocket subprotocol. undici@6.27.0 reaches us through @actions/github and @actions/http-client (^6.23.0) and is bundled into both Actions. The required audit check now fails on every PR (#248, #249, #250).

  • bun.lock: one line. undici 6.27.0 → 6.29.0. It is inside the existing ^6.23.0 range, was published 2026-09-25 (clears the 3-day minimumReleaseAge), and its integrity hash matches the npm registry's. Letting Bun re-resolve the lockfile would have moved a dozen unrelated @octokit/@types packages, so I edited only this entry and let --frozen-lockfile validate it.
  • packages/ci/dist: regenerated under linux/amd64 oven/bun:1.3.14 (the current pin). The diff is undici's own code.

Checklist

  • Commits are DCO signed off.
  • No recorded decision changes.
  • Schema: n/a
  • packages/ci/dist regenerated under linux/amd64 bun 1.3.14.
  • Tests: none added; this is a dependency patch. audit:gate goes from FAILED (1 high) to PASSED. The packages/ci and scripts suites pass under Bun 1.3.14 (1,219 tests, 0 failures).
  • Both bundles run under Node. index.js exits early outside a pull_request event. queue-action.js loads the corpus and reaches the GitHub API through the new undici (401 with a fake token, as before).

Notes for reviewers

Merge this first. It unblocks the required audit check on #248, #249 and #250. After it lands I'll rebase #249 (the Bun 1.4.2 bump) and regenerate its bundles under 1.4.2 so they include this undici. Then I'll rebase #250.

GHSA-rfgv-xxqx-mfg5, published 2026-09-29, rates undici >= 6.7.0 < 6.28.1
high: a denial of service via an unrequested WebSocket subprotocol.
6.27.0 reached this repository through @actions/github and
@actions/http-client (^6.23.0), which are bundled into both Actions. The
required `audit` check has failed on every pull request since.

The change is one line of bun.lock: undici 6.27.0 -> 6.29.0, inside the
existing ^6.23.0 range, published 2026-09-25, so it clears the 3-day
minimumReleaseAge. The integrity hash matches the npm registry's.
Re-resolving the lockfile instead would have moved a dozen unrelated
@octokit and @types packages, so this edits only that entry and relies on
--frozen-lockfile to validate it.

packages/ci/dist is regenerated under linux/amd64 oven/bun:1.3.14, the
current pin; the diff is undici's own code. The packages/ci and scripts
suites pass (1,219 tests), and both bundles run under Node: index.js exits
early outside a pull_request event, and queue-action.js reaches the
GitHub API through the new undici.

Signed-off-by: Mark Beacom <m@beacom.dev>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 23:37

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.

@github-actions

Copy link
Copy Markdown

Decisions governing this change

  • 0030 — Keep extension surfaces that carry a dependency tree outside this repository
    • via path: packages/ci/**
  • 0035 — Execute the gates that certify a pull request from the default branch
    • via path: packages/ci/**
  • 0036 — Expose the governing-decisions Action through one root Marketplace entry point
    • via path: packages/ci/dist/index.js
  • 0041 — Regenerate committed artifacts on Dependabot pull requests with default-branch scripts behind a maintainer label
    • via path: packages/ci/dist/**

@mbeacom mbeacom added the gate-change-acknowledged A maintainer has seen and accepted this PR's change to the CI gate surface (ADR-0035) label Sep 30, 2026
@mbeacom mbeacom self-assigned this Sep 30, 2026
@mbeacom
mbeacom merged commit 94fe8f1 into main Sep 30, 2026
20 of 21 checks passed
@mbeacom
mbeacom deleted the fix/undici-ghsa-rfgv branch September 30, 2026 23:43
@mbeacom mbeacom mentioned this pull request Oct 1, 2026
4 of 6 tasks
mbeacom added a commit that referenced this pull request Oct 1, 2026
* chore(release): prepare v0.16.0

Moves the lockstep surface to 0.16.0: the four public packages,
CLI_VERSION, SERVER_INFO and server.json, bun.lock's workspace entries,
and every documented pin (README, ci.mdx, badges.mdx, quickstart, the
site hero, RELEASING.md, the bug-report template).

The CHANGELOG's Unreleased section becomes 0.16.0, with what it was
missing:
- Security: the Action bundles' undici 6.29.0 (GHSA-rfgv-xxqx-mfg5,
  #251). It is the main reason to release now, since published v0
  consumers still run 6.27.0.
- Added: acceptAdrSource, a new @adrkit/core runtime export, which the
  release policy requires calling out.
- Changed: adr queue --format defaults to auto (only a terminal sees a
  difference), and the Bun 1.4.2 toolchain move, which shrinks the
  Action bundles by dropping unused zod locales and helpers.

The docs also catch up with adr accept, which adrkit.dev has described
since #250 merged but npm doesn't ship yet: the AGENTS.md status line
and the CLI README command lists name it, the CLI README and root README
gain a short queue-and-accept section with the terminal view, and the
container section lists accept among the commands that write.

The Action bundles rebuild byte-identical under linux/amd64 Bun 1.4.2,
and release:pack prepares all five packages for v0.16.0.

Signed-off-by: Mark Beacom <m@beacom.dev>

* docs(readme): name adr accept in the project status table

The queue row now says the shipped workflow includes ratifying from
the queue, not only reporting it.

Signed-off-by: Mark Beacom <m@beacom.dev>

* docs(changelog): don't claim the bundles' other dependencies are unchanged

The 0.16.0 Changed entry said every other bundled dependency was
unchanged, which contradicts the undici update under Security in the
same release. It now says that, apart from zod's dropped locales and
helpers and that undici update, the bundles contain the same modules as
0.15.0. I checked that against both bundles at v0.15.0 and on main.

Signed-off-by: Mark Beacom <m@beacom.dev>

---------

Signed-off-by: Mark Beacom <m@beacom.dev>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gate-change-acknowledged A maintainer has seen and accepted this PR's change to the CI gate surface (ADR-0035)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants