Skip to content

upgrading undici to 6.23.0#155

Open
kp2099 wants to merge 1 commit intomainfrom
karthik/undici_upgrade
Open

upgrading undici to 6.23.0#155
kp2099 wants to merge 1 commit intomainfrom
karthik/undici_upgrade

Conversation

@kp2099
Copy link
Contributor

@kp2099 kp2099 commented Feb 19, 2026

undici is a transitive dependency pulled in by @hashicorp/github-actions-core, @actions/http-client, and @actions/core. Since @hashicorp/github-actions-core has no release beyond v1.0.0 and its internal dependencies still pin undici@^5.25.4 (which has a known security vulnerability), i added a direct override in package.json to force all instances of undici to 6.23.0, which contains the security patch.

@kp2099 kp2099 requested a review from a team as a code owner February 19, 2026 06:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments