Skip to content

chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security]#3432

Merged
mkurapov merged 1 commit into
mainfrom
renovate-npm-undici>=6.0.0-vulnerability
Oct 30, 2025
Merged

chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security]#3432
mkurapov merged 1 commit into
mainfrom
renovate-npm-undici>=6.0.0-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 15, 2025

This PR contains the following updates:

Package Change Age Confidence
undici@>=6.0.0 (source) ^6.21.1 -> ^6.21.2 age confidence

GitHub Vulnerability Alerts

CVE-2025-47279

Impact

Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak.

Patches

This has been patched in https://github.com/nodejs/undici/pull/4088.

Workarounds

If a webhook fails, avoid keep calling it repeatedly.

References

Reported as: https://github.com/nodejs/undici/issues/3895


Release Notes

nodejs/undici (undici@>=6.0.0)

v6.21.2

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.21.1...v6.21.2


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency label May 15, 2025
@netlify
Copy link
Copy Markdown

netlify Bot commented May 15, 2025

Deploy Preview for brilliant-pasca-3e80ec canceled.

Name Link
🔨 Latest commit 2e7530f
🔍 Latest deploy log https://app.netlify.com/projects/brilliant-pasca-3e80ec/deploys/69011346c6c064000815f0e2

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 15, 2025

🚀 Performance Test Results

Test Configuration:

  • VUs: 4
  • Duration: 1m0s

Test Metrics:

  • Requests/s: 44.69
  • Iterations/s: 14.91
  • Failed Requests: 0.00% (0 of 2691)
📜 Logs

> performance@1.0.0 run-tests:testenv /home/runner/work/rafiki/rafiki/test/performance
> ./scripts/run-tests.sh -e test "-k" "-q" "--vus" "4" "--duration" "1m"

Cloud Nine GraphQL API is up: http://localhost:3101/graphql
Cloud Nine Wallet Address is up: http://localhost:3100/
Happy Life Bank Address is up: http://localhost:4100/
cloud-nine-wallet-test-backend already set
cloud-nine-wallet-test-auth already set
happy-life-bank-test-backend already set
happy-life-bank-test-auth already set
     data_received..................: 971 kB 16 kB/s
     data_sent......................: 2.1 MB 34 kB/s
     http_req_blocked...............: avg=7.87µs   min=2.13µs   med=5.03µs   max=3.98ms   p(90)=6.06µs   p(95)=6.61µs  
     http_req_connecting............: avg=422ns    min=0s       med=0s       max=526.3µs  p(90)=0s       p(95)=0s      
     http_req_duration..............: avg=88.86ms  min=14.42ms  med=71.7ms   max=544.6ms  p(90)=153.34ms p(95)=172.88ms
       { expected_response:true }...: avg=88.86ms  min=14.42ms  med=71.7ms   max=544.6ms  p(90)=153.34ms p(95)=172.88ms
     http_req_failed................: 0.00%  ✓ 0         ✗ 2691
     http_req_receiving.............: avg=83.6µs   min=27.08µs  med=73.87µs  max=1.35ms   p(90)=108.12µs p(95)=136.87µs
     http_req_sending...............: avg=35.38µs  min=8.97µs   med=26.35µs  max=2.06ms   p(90)=38.25µs  p(95)=52.08µs 
     http_req_tls_handshaking.......: avg=0s       min=0s       med=0s       max=0s       p(90)=0s       p(95)=0s      
     http_req_waiting...............: avg=88.74ms  min=14.03ms  med=71.61ms  max=544.48ms p(90)=153.24ms p(95)=172.76ms
     http_reqs......................: 2691   44.690043/s
     iteration_duration.............: avg=267.86ms min=168.29ms med=249.21ms max=1.15s    p(90)=330.65ms p(95)=362.3ms 
     iterations.....................: 898    14.913288/s
     vus............................: 4      min=4       max=4 
     vus_max........................: 4      min=4       max=4 

@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] May 19, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch 2 times, most recently from 6940acd to 3ec9b2d Compare May 20, 2025 00:06
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] May 20, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 3ec9b2d to 23148f9 Compare May 28, 2025 13:58
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] May 28, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 23148f9 to aea5dce Compare May 28, 2025 18:45
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] May 28, 2025
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] May 28, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch 2 times, most recently from 53e8534 to c2642ef Compare May 29, 2025 02:40
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] May 29, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from c2642ef to 8b1c8bc Compare June 4, 2025 08:10
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jun 4, 2025
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jun 4, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch 2 times, most recently from 9a03252 to 93b5f3f Compare June 6, 2025 02:04
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jun 6, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 93b5f3f to e5e1809 Compare June 6, 2025 23:38
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jun 6, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from e5e1809 to 1c2fa2f Compare June 9, 2025 11:56
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jun 9, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 1c2fa2f to 031b7d2 Compare June 9, 2025 15:04
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jun 9, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 031b7d2 to 85c3890 Compare June 9, 2025 19:24
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jun 9, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 85c3890 to e7ff9f7 Compare June 9, 2025 22:36
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jun 17, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from dfe63db to 9cd6213 Compare June 17, 2025 22:46
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jun 17, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 9cd6213 to 2022720 Compare June 18, 2025 11:30
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jun 18, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 2022720 to 9e727e7 Compare June 18, 2025 16:56
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jun 18, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 9e727e7 to d205a7e Compare June 22, 2025 15:05
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jun 22, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from d205a7e to 7c82b4f Compare June 22, 2025 18:05
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jun 22, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 7c82b4f to fd5cc7d Compare July 2, 2025 10:20
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jul 2, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from fd5cc7d to 0b8b6b2 Compare July 2, 2025 10:29
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jul 2, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 0b8b6b2 to a68f2c0 Compare July 2, 2025 15:43
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jul 2, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from a68f2c0 to 5f48080 Compare July 3, 2025 03:44
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jul 3, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 5f48080 to 3d234cc Compare July 6, 2025 12:38
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jul 6, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 3d234cc to f4dd559 Compare July 6, 2025 16:40
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jul 6, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from f4dd559 to 5c53906 Compare July 8, 2025 11:07
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] Jul 8, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from 5c53906 to a4bfe3c Compare July 8, 2025 11:36
@renovate renovate Bot changed the title chore(deps): update dependency undici@>=6.0.0 to ^6.21.3 [security] chore(deps): update dependency undici@>=6.0.0 to ^6.21.2 [security] Jul 8, 2025
@renovate renovate Bot force-pushed the renovate-npm-undici>=6.0.0-vulnerability branch from a4bfe3c to 78a9be1 Compare July 8, 2025 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant