Skip to content

[security]: upgrade vulnerable undici dependency #168

Description

@pitimon

Security finding

Current npm audit --json reports the direct production dependency undici as high severity with a fix available.

Current vulnerable range in the lockfile: 7.0.0 - 7.28.0.

Affected advisories include:

Later advisories require at least 7.29.0 for remediation.

Expected

  • Upgrade undici to a non-vulnerable release supported by the project runtime.
  • Run focused outbound/proxy/redirect/body-limit tests and full ci:local.
  • Confirm npm audit no longer reports the vulnerability.

This dependency finding pre-existed PR #162 and was not introduced by the Goose fix.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions