Skip to content

Security: fix Dependabot alert #15 for undici (GHSA-phc3-fgpg-7m6h) #32

@slashdevcorpse

Description

@slashdevcorpse

Dependabot Alert

Summary

Undici has Unbounded Memory Consumption in its DeduplicationHandler via Response Buffering that leads to DoS

Remediation

  • Update the dependency graph so undici resolves outside the vulnerable range.
  • Regenerate pnpm-lock.yaml.
  • Run the app test/build checks and package dry run.
  • Confirm GitHub Dependabot marks alert Polish public README for Codex CLI alpha #15 resolved after merge.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependabot-alertGitHub Dependabot security alert trackingdependenciesPull requests that update a dependency filesecuritySecurity advisories and vulnerability remediation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions