Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 15, 2025

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Package Change Age Confidence
undici@>=5.0.0 (source) ^5.28.5 -> ^6.21.2 age confidence

GitHub Vulnerability Alerts

CVE-2025-47279

Impact

Applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they can force the application to call the webhook repeatedly, then they can cause a memory leak.

Patches

This has been patched in https://github.com/nodejs/undici/pull/4088.

Workarounds

If a webhook fails, avoid keep calling it repeatedly.

References

Reported as: https://github.com/nodejs/undici/issues/3895


Release Notes

nodejs/undici (undici@>=5.0.0)

v6.21.2

Compare Source

What's Changed
New Contributors

Full Changelog: nodejs/undici@v6.21.1...v6.21.2

v6.21.1

Compare Source

⚠️ Security Release ⚠️

Fixes CVE CVE-2025-22150 GHSA-c76h-2ccp-4975 (embargoed until 22-01-2025).

What's Changed

Full Changelog: nodejs/undici@v6.21.0...v6.21.1

v6.21.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.20.1...v6.21.0

v6.20.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.20.0...v6.20.1

v6.20.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.19.8...v6.20.0

v6.19.8

Compare Source

Full Changelog: nodejs/undici@v6.19.7...v6.19.8

v6.19.7

Compare Source

Full Changelog: nodejs/undici@v6.19.6...v6.19.7

v6.19.6

Compare Source

Full Changelog: nodejs/undici@v6.19.5...v6.19.6

v6.19.5

Compare Source

Full Changelog: nodejs/undici@v6.19.4...v6.19.5

v6.19.4

Compare Source

Full Changelog: nodejs/undici@v6.19.3...v6.19.4

v6.19.3

Compare Source

Full Changelog: nodejs/undici@v6.19.2...v6.19.3

v6.19.2

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.19.1...v6.19.2

v6.19.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.19.0...v6.19.1

v6.19.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.18.2...v6.19.0

v6.18.2

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.18.1...v6.18.2

v6.18.1

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.18.0...v6.18.1

v6.18.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.17.0...v6.18.0

v6.17.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.16.1...v6.17.0

v6.16.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.16.0...v6.16.1

v6.16.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.15.0...v6.16.0

v6.15.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.14.1...v6.15.0

v6.14.1

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.14.0...v6.14.1

v6.14.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.13.0...v6.14.0

v6.13.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.12.0...v6.13.0

v6.12.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.11.1...v6.12.0

v6.11.1

Compare Source

⚠️ Security Release ⚠️

What's Changed

Full Changelog: nodejs/undici@v6.11.0...v6.11.1

v6.11.0

Compare Source

What's Changed

Full Changelog: nodejs/undici@v6.10.2...v6.11.0

v6.10.2

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.10.0...v6.10.2

v6.10.1

Compare Source

Full Changelog: nodejs/undici@v6.10.0...v6.10.1

v6.10.0

Compare Source

What's Changed

New Contributors

Full Changelog: nodejs/undici@v6.9.0...v6.10.0

v6.9.0

Compare Source

What's Changed


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency label May 15, 2025
Copy link

netlify bot commented May 15, 2025

Deploy Preview for brilliant-pasca-3e80ec canceled.

Name Link
🔨 Latest commit 507a2e9
🔍 Latest deploy log https://app.netlify.com/projects/brilliant-pasca-3e80ec/deploys/68d5c326d7bf5700085695b5

Copy link

github-actions bot commented May 15, 2025

🚀 Performance Test Results

Test Configuration:

  • VUs: 4
  • Duration: 1m0s

Test Metrics:

  • Requests/s: 41.88
  • Iterations/s: 13.98
  • Failed Requests: 0.00% (0 of 2517)
📜 Logs

> [email protected] run-tests:testenv /home/runner/work/rafiki/rafiki/test/performance
> ./scripts/run-tests.sh -e test "-k" "-q" "--vus" "4" "--duration" "1m"

Cloud Nine GraphQL API is up: http://localhost:3101/graphql
Cloud Nine Wallet Address is up: http://localhost:3100/
Happy Life Bank Address is up: http://localhost:4100/
cloud-nine-wallet-test-backend already set
cloud-nine-wallet-test-auth already set
happy-life-bank-test-backend already set
happy-life-bank-test-auth already set
     data_received..................: 909 kB 15 kB/s
     data_sent......................: 1.9 MB 32 kB/s
     http_req_blocked...............: avg=8.01µs   min=2.35µs   med=5.24µs   max=3.06ms   p(90)=6.45µs   p(95)=7µs     
     http_req_connecting............: avg=546ns    min=0s       med=0s       max=738.21µs p(90)=0s       p(95)=0s      
     http_req_duration..............: avg=94.86ms  min=7.42ms   med=76.91ms  max=554.08ms p(90)=165.28ms p(95)=185.52ms
       { expected_response:true }...: avg=94.86ms  min=7.42ms   med=76.91ms  max=554.08ms p(90)=165.28ms p(95)=185.52ms
     http_req_failed................: 0.00%  ✓ 0         ✗ 2517
     http_req_receiving.............: avg=85.67µs  min=27.79µs  med=79.01µs  max=2.51ms   p(90)=110.89µs p(95)=131.38µs
     http_req_sending...............: avg=35.06µs  min=10.18µs  med=27.83µs  max=2.47ms   p(90)=39.97µs  p(95)=53.38µs 
     http_req_tls_handshaking.......: avg=0s       min=0s       med=0s       max=0s       p(90)=0s       p(95)=0s      
     http_req_waiting...............: avg=94.74ms  min=7.28ms   med=76.79ms  max=553.99ms p(90)=165.17ms p(95)=185.37ms
     http_reqs......................: 2517   41.879974/s
     iteration_duration.............: avg=285.89ms min=179.62ms med=272.68ms max=1.12s    p(90)=341.04ms p(95)=388ms   
     iterations.....................: 840    13.97663/s
     vus............................: 4      min=4       max=4 
     vus_max........................: 4      min=4       max=4 

@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from 1ab9d89 to 188110b Compare May 19, 2025 18:00
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] May 19, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from 188110b to 342c16d Compare May 20, 2025 00:06
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] May 20, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] May 28, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch 2 times, most recently from 573fbd1 to 14ab84d Compare May 28, 2025 18:45
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] May 28, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] May 28, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch 2 times, most recently from 00f2fe9 to 206e9aa Compare May 29, 2025 02:41
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] May 29, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Jun 4, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch 2 times, most recently from 4a09574 to c263937 Compare June 4, 2025 11:51
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Jun 4, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from c263937 to d1055ba Compare June 6, 2025 02:04
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Jun 6, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from d1055ba to 1d7e00a Compare June 6, 2025 23:38
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Jun 6, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from 1d7e00a to 2bb744d Compare June 9, 2025 11:57
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Jun 9, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from 2bb744d to e69ee53 Compare June 9, 2025 15:05
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Jun 9, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Jun 9, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch 2 times, most recently from bb8eb47 to 6eeaf30 Compare June 9, 2025 22:36
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Aug 21, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Aug 22, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch 2 times, most recently from e5277e6 to f91e422 Compare August 22, 2025 15:37
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Aug 22, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from f91e422 to 2c15acd Compare August 31, 2025 14:35
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Aug 31, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from 2c15acd to 13d850c Compare August 31, 2025 18:02
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Aug 31, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from 13d850c to fd89c90 Compare September 5, 2025 09:42
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Sep 5, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from fd89c90 to 56b61c2 Compare September 5, 2025 10:53
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Sep 5, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from 56b61c2 to 7534e18 Compare September 5, 2025 13:12
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Sep 5, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from 7534e18 to ed3664c Compare September 5, 2025 21:32
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Sep 5, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from ed3664c to f71c795 Compare September 22, 2025 06:47
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Sep 22, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from f71c795 to aa6ab56 Compare September 22, 2025 10:01
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Sep 22, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch 2 times, most recently from 1d43768 to c052b44 Compare September 25, 2025 16:23
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Sep 25, 2025
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to v6 [security] chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] Sep 25, 2025
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from c052b44 to a94ee0f Compare September 25, 2025 16:39
@renovate renovate bot force-pushed the renovate-npm-undici>=5.0.0-vulnerability branch from a94ee0f to 507a2e9 Compare September 25, 2025 22:33
@renovate renovate bot changed the title chore(deps): update dependency undici@>=5.0.0 to ^5.29.0 [security] chore(deps): update dependency undici@>=5.0.0 to v6 [security] Sep 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants