Skip to content

chore(deps-dev): bump undici from 7.28.0 to 7.29.0 in /web-client - #30

Open
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/web-client/undici-7.29.0
Open

chore(deps-dev): bump undici from 7.28.0 to 7.29.0 in /web-client#30
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/web-client/undici-7.29.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown

Bumps undici from 7.28.0 to 7.29.0.

Release notes

Sourced from undici's releases.

v7.29.0

⚠️ Security fixes

High severity

  • GHSA-4cwx-7wf7-3272: malformed qualified private Cache-Control directives could cause cross-user information disclosure in shared caches or a parse-time crash. The cache parser now treats empty qualified directives conservatively and safely handles mixed qualified and unqualified directives. Fixed by 9f10f1e9, with regression coverage in 466e99d1.

Medium severity

  • GHSA-m8rv-5g2x-5cg5: a malicious type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content-type header. Undici now coerces and validates the value before adding it to the request. Fixed by 33928bc2.
  • GHSA-jr45-8vmc-qm54: optional whitespace around = in qualified no-cache and private directives could bypass shared-cache restrictions and disclose authenticated data across users. Cache-Control parsing now normalizes these forms and applies conservative cache decisions. Fixed by 98011a86.
  • GHSA-8xcm-r25x-g524: the retry interceptor could expose a stale Content-Length after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose Content-Length is inconsistent with Content-Range. Fixed by 1b5a5312, with corrected fixtures in 4a9dafb1.
  • GHSA-v3r7-h72x-cjcm: unsanitized domain and unparsed values passed to setCookie() could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by 3bf91ddb.

Full Changelog: nodejs/undici@v7.28.0...v7.29.0

Commits
  • 9e38fc1 Bumped v7.29.0 (#5590)
  • d887e34 fix: validate coerced header values for CRLF (#5579)
  • 33928bc fix: validate blob body content type
  • 98011a8 fix(cache): harden cache directive parsing
  • 4a9dafb test(retry): correct broken content-range fixtures in retry-handler.js
  • 1b5a531 fix(retry): reject partial content length mismatch
  • 466e99d test: cover crash on mixed unqualified and qualified private cache directives
  • 9f10f1e fix: handle empty qualified private cache directive
  • 3bf91dd fix: harden cookie domain, path, and unparsed attribute validation
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 4, 2026
Recorded retroactively for the same reason as the preceding commits.

Adds developer-docs/infra/kubernetes.md (chart, Tiltfile, ctlptl and
Makefile internals, mirroring terraform.md) and
developer-docs/infra/kubernetes-tools.md (optional non-IPA community
CLIs -- k9s, kubectx/kubens, kftray, stern -- install links only, not
checked by `make doctor`). Adds builder guides
guides/kubernetes-local-development.md and
guides/kubernetes-path-to-production.md. Both guides, plus
infra/k8s/README.md, carry a Future Work section recording the
deferred cloud-cluster path: CFN/TF cluster provisioning, ECR wiring,
IRSA role creation, a CodePipeline helm upgrade --install stage, Local
IRSA, and ingress templates. None of that was built this round.
Agent-context CLAUDE.md files were added across
infra/containers/rest-k8s/, infra/k8s/, the chart itself, and eks/.
Bumps [undici](https://github.com/nodejs/undici) from 7.28.0 to 7.29.0.
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.28.0...v7.29.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.29.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web-client/undici-7.29.0 branch from 9274736 to 653379e Compare August 7, 2026 18:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant