Skip to content

v0.15.9 — Security: undici 7.29.0

Choose a tag to compare

@hoornet hoornet released this 09 Aug 10:39
· 38 commits to main since this release

Security refresh.

Security

  • undici 7.28.0 → 7.29.0, clearing five advisories published that week: one high (cross-user information disclosure and a parse-time crash via degenerate private cache directives) and four moderate (CRLF injection via blob-like body type, cookie attribute injection, cache-control whitespace disclosure, retry-interceptor response desynchronization). undici is the HTTP client used for all Home Assistant API calls.

Lockfile-only change — the ^7.28.0 range already covered it. npm audit reports 0 vulnerabilities.

Upgrade: no configuration changes required.