Skip to content

chore: override undici to ^7.29.1 for CVE fixes - #307

Merged
aderende merged 1 commit into
mainfrom
fix/cve-undici-7.29.1-main
Oct 6, 2026
Merged

aderende merged 1 commit into
mainfrom
fix/cve-undici-7.29.1-main

Conversation

@aderende

@aderende aderende commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Issue

Description of Changes

Backport of #305 to main. Bumps the undici override from ^7.29.0 to ^7.29.1 to resolve: CVE-2026-13697, CVE-2026-84961, CVE-2026-14643, CVE-2026-19534, CVE-2026-84933, CVE-2026-85014. 7.29.1 is the 7.x fix; @vscode/proxy-agent requires undici ^7.2.0, so 8.x is not an option.

Unlike #305, this also updates:

  • the undici lines in patches that apply after finding-override-undici.diff (otherwise they no longer apply)
  • the lock files for all four series, not only sagemaker

Testing

Applied the package.json hunks of every patch in all four *.series files (sagemaker, web-server, web-embedded, web-embedded-with-terminal) against the upstream package.json / remote/package.json at the pinned third-party-src commit with patch -F0: all apply cleanly and produce undici@^7.29.1. Lock files validated as JSON; 7.29.1 integrity matches npm view undici@7.29.1 dist.integrity. Full build runs via build-targets.

Screenshots/Videos

N/A — dependency version bump, no user-visible change.

Additional Notes

Stopgap override; remove when upstream Code-OSS updates undici to >= 7.29.1.

Backporting

Siblings: #305 (1.2) and #310 (1.2 follow-up).


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@aderende
aderende requested a review from a team as a code owner October 6, 2026 12:17
@aderende
aderende added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 2808080 Oct 6, 2026
3 checks passed
@aderende
aderende deleted the fix/cve-undici-7.29.1-main branch October 6, 2026 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants