v0.15.9 — Security: undici 7.29.0
Security refresh.
Security
- undici 7.28.0 → 7.29.0, clearing five advisories published that week: one high (cross-user information disclosure and a parse-time crash via degenerate private cache directives) and four moderate (CRLF injection via blob-like body type, cookie attribute injection, cache-control whitespace disclosure, retry-interceptor response desynchronization). undici is the HTTP client used for all Home Assistant API calls.
Lockfile-only change — the ^7.28.0 range already covered it. npm audit reports 0 vulnerabilities.
Upgrade: no configuration changes required.