Skip to content

[Snyk] Upgrade undici from 5.25.4 to 7.12.0#8

Open
snyk-io[bot] wants to merge 1 commit intomainfrom
snyk-upgrade-42a7481db29cbcd593f787bea0433fb7
Open

[Snyk] Upgrade undici from 5.25.4 to 7.12.0#8
snyk-io[bot] wants to merge 1 commit intomainfrom
snyk-upgrade-42a7481db29cbcd593f787bea0433fb7

Conversation

@snyk-io
Copy link
Copy Markdown

@snyk-io snyk-io Bot commented Aug 8, 2025

snyk-top-banner

Snyk has created this PR to upgrade undici from 5.25.4 to 7.12.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


⚠️ Warning: This PR contains major version upgrade(s), and may be a breaking change.

  • The recommended version is 89 versions ahead of your current version.

  • The recommended version was released 21 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Insecure Randomness
SNYK-JS-UNDICI-8641354
76 Proof of Concept
low severity Missing Release of Memory after Effective Lifetime
SNYK-JS-UNDICI-10176064
76 Proof of Concept
low severity Information Exposure
SNYK-JS-UNDICI-5962466
76 No Known Exploit
low severity Permissive Cross-domain Policy with Untrusted Domains
SNYK-JS-UNDICI-6252336
76 No Known Exploit
low severity Improper Access Control
SNYK-JS-UNDICI-6564963
76 No Known Exploit
low severity Improper Authorization
SNYK-JS-UNDICI-6564964
76 No Known Exploit
Release notes
Package name: undici

@semanticdiff-com
Copy link
Copy Markdown

semanticdiff-com Bot commented Aug 8, 2025

Review changes with  SemanticDiff

Changed Files
File Status
  packages/http-client/package.json  0% smaller

@snyk-io
Copy link
Copy Markdown
Author

snyk-io Bot commented Aug 8, 2025

🎉 Snyk checks have passed. No issues have been found so far.

security/snyk check is complete. No issues have been found. (View Details)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants