fix(deps): move bundled undici to 6.29.0 for GHSA-rfgv-xxqx-mfg5 - #251
Merged
Merged
Conversation
GHSA-rfgv-xxqx-mfg5, published 2026-09-29, rates undici >= 6.7.0 < 6.28.1 high: a denial of service via an unrequested WebSocket subprotocol. 6.27.0 reached this repository through @actions/github and @actions/http-client (^6.23.0), which are bundled into both Actions. The required `audit` check has failed on every pull request since. The change is one line of bun.lock: undici 6.27.0 -> 6.29.0, inside the existing ^6.23.0 range, published 2026-09-25, so it clears the 3-day minimumReleaseAge. The integrity hash matches the npm registry's. Re-resolving the lockfile instead would have moved a dozen unrelated @octokit and @types packages, so this edits only that entry and relies on --frozen-lockfile to validate it. packages/ci/dist is regenerated under linux/amd64 oven/bun:1.3.14, the current pin; the diff is undici's own code. The packages/ci and scripts suites pass (1,219 tests), and both bundles run under Node: index.js exits early outside a pull_request event, and queue-action.js reaches the GitHub API through the new undici. Signed-off-by: Mark Beacom <m@beacom.dev>
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.
Decisions governing this change
|
4 of 6 tasks
mbeacom
added a commit
that referenced
this pull request
Oct 1, 2026
* chore(release): prepare v0.16.0 Moves the lockstep surface to 0.16.0: the four public packages, CLI_VERSION, SERVER_INFO and server.json, bun.lock's workspace entries, and every documented pin (README, ci.mdx, badges.mdx, quickstart, the site hero, RELEASING.md, the bug-report template). The CHANGELOG's Unreleased section becomes 0.16.0, with what it was missing: - Security: the Action bundles' undici 6.29.0 (GHSA-rfgv-xxqx-mfg5, #251). It is the main reason to release now, since published v0 consumers still run 6.27.0. - Added: acceptAdrSource, a new @adrkit/core runtime export, which the release policy requires calling out. - Changed: adr queue --format defaults to auto (only a terminal sees a difference), and the Bun 1.4.2 toolchain move, which shrinks the Action bundles by dropping unused zod locales and helpers. The docs also catch up with adr accept, which adrkit.dev has described since #250 merged but npm doesn't ship yet: the AGENTS.md status line and the CLI README command lists name it, the CLI README and root README gain a short queue-and-accept section with the terminal view, and the container section lists accept among the commands that write. The Action bundles rebuild byte-identical under linux/amd64 Bun 1.4.2, and release:pack prepares all five packages for v0.16.0. Signed-off-by: Mark Beacom <m@beacom.dev> * docs(readme): name adr accept in the project status table The queue row now says the shipped workflow includes ratifying from the queue, not only reporting it. Signed-off-by: Mark Beacom <m@beacom.dev> * docs(changelog): don't claim the bundles' other dependencies are unchanged The 0.16.0 Changed entry said every other bundled dependency was unchanged, which contradicts the undici update under Security in the same release. It now says that, apart from zod's dropped locales and helpers and that undici update, the bundles contain the same modules as 0.15.0. I checked that against both bundles at v0.15.0 and on main. Signed-off-by: Mark Beacom <m@beacom.dev> --------- Signed-off-by: Mark Beacom <m@beacom.dev>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
GHSA-rfgv-xxqx-mfg5 (published 2026-09-29, high) affects
undici>= 6.7.0 < 6.28.1: a denial of service via an unrequested WebSocket subprotocol.undici@6.27.0reaches us through@actions/githuband@actions/http-client(^6.23.0) and is bundled into both Actions. The requiredauditcheck now fails on every PR (#248, #249, #250).bun.lock: one line.undici6.27.0 → 6.29.0. It is inside the existing^6.23.0range, was published 2026-09-25 (clears the 3-dayminimumReleaseAge), and its integrity hash matches the npm registry's. Letting Bun re-resolve the lockfile would have moved a dozen unrelated@octokit/@typespackages, so I edited only this entry and let--frozen-lockfilevalidate it.packages/ci/dist: regenerated under linux/amd64oven/bun:1.3.14(the current pin). The diff isundici's own code.Checklist
packages/ci/distregenerated under linux/amd64 bun 1.3.14.audit:gategoes from FAILED (1 high) to PASSED. Thepackages/ciandscriptssuites pass under Bun 1.3.14 (1,219 tests, 0 failures).index.jsexits early outside apull_requestevent.queue-action.jsloads the corpus and reaches the GitHub API through the newundici(401 with a fake token, as before).Notes for reviewers
Merge this first. It unblocks the required
auditcheck on #248, #249 and #250. After it lands I'll rebase #249 (the Bun 1.4.2 bump) and regenerate its bundles under 1.4.2 so they include thisundici. Then I'll rebase #250.