Skip to content

fix: update vulnerable dependency (undici)#10

Merged
guptaankit015 merged 2 commits intomainfrom
fix/dependabot-vulns
Mar 24, 2026
Merged

fix: update vulnerable dependency (undici)#10
guptaankit015 merged 2 commits intomainfrom
fix/dependabot-vulns

Conversation

@guptaankit015
Copy link
Copy Markdown
Collaborator

Summary

  • Add npm overrides to force undici >= 6.24.0 to fix 5 vulnerabilities (CRLF injection, memory consumption, request smuggling, decompression chain, WebSocket validation)

Resolves Dependabot alerts #1, #2, #3, #4, #5

Made with Cursor

- Add npm overrides to force undici >= 6.24.0 (fixes CRLF injection, memory consumption, request smuggling, decompression chain, and WebSocket validation vulnerabilities)

Resolves Dependabot alerts #1, #2, #3, #4, #5

Made-with: Cursor
@guptaankit015 guptaankit015 merged commit 432e7d1 into main Mar 24, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants