This repository was archived by the owner on Sep 1, 2026. It is now read-only.
fix(sec-auto): aikido Fix 18 security issues in undici, @fastify/busboy - #5
Open
aikido-autofix[bot] wants to merge 1 commit into
Open
aikido-autofix[bot] wants to merge 1 commit into
aikido-autofix[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
AI AutoFix
These PRs will require human vetting and potentially some fixes to fully integrate with the codebase.
Upgrade undici and @fastify/busboy to fix HTTP request smuggling, decompression DoS attacks, and prototype pollution vulnerabilities.
✅ Code not affected by breaking changes.
✅ No breaking changes from the undici upgrade affect this codebase.
The analysis shows that:
Interceptors: The codebase does not use undici interceptors directly. While
kInterceptorsappears in the bundleddist/index.js(from the bundled undici dependency), the source code insrc/does not configure or use any interceptor functionality.throwOnError: Although
throwOnErrorappears in the bundled undici code indist/index.js, the application code does not pass this option when making HTTP requests. The code only uses high-level APIs from@actions/github(Octokit) which abstracts away undici-specific options.Node.js 18 support dropped: The action already uses Node.js 24 runtime (as specified in
action.yml:using: 'node24'), so dropping Node.js 18 support is not a concern.Deduplicate interceptor: The codebase does not use the deduplicate interceptor.
Third-party fetch support: The codebase does not use undici's fetch API directly; it only uses
@actions/github(Octokit) for GitHub API calls.The undici dependency is only used indirectly through
@actions/http-client(version 2.2.3), which is itself a dependency of@actions/github. The application code exclusively uses high-level GitHub API methods (octokit.rest.*,octokit.paginate) and does not configure any undici-specific options.All breaking changes by upgrading undici from version 5.29.0 to 7.29.0 (CHANGELOG)
✅ 18 CVEs resolved by this upgrade, including 1 critical 🚨 CVE
This PR will resolve the following CVEs:
undicilibrary are vulnerable to memory leaks. By making multiple fetch requests with the sameAbortSignal, undici adds event listeners without removing them, leading to excessive memory consumption.__proto__orconstructor, potentially influencing application behavior or enabling further attacks.__proto__,constructor, orprototypeinto internal objects, potentially modifying the prototype chain and influencing application behavior or enabling further attacks.__proto__orconstructor) that cause a TypeError, resulting in denial of service by crashing the Node.js process when using direct write/end operations.Content-Dispositionheaders, allowing them to be passed to applications in filename and field name values, enabling filesystem pollution, log forging, or header injection attacks.🤖 Remediation details
Fix critical and high-severity vulnerabilities in
undiciand@fastify/busboyBoth vulnerable packages (
undiciand@fastify/busboy) were transitive dependencies pulled in through the@actions/http-clientchain. Fixes required bumping two direct dependencies in the rootpackage.json(@actions/core,@actions/github) and adding aresolutionsoverride forundici, with the lockfile (yarn.lock) updated accordingly.undici
undiciwas a transitive dependency resolved at5.29.0via@actions/http-client@2.2.3, which was itself pulled in by@actions/core@^1.10.0and@actions/github@^6.0.0. The required fix floor is7.24.1, but no published version of@actions/http-client(up to the latest4.0.1) declares a range that admitsundici@7.x— the highest it reaches is^6.23.0. Because no parent-chain bump could deliverundici@7.x, aresolutionsentry ("undici": "^7.24.1") was added to the rootpackage.jsonas a last resort, resolvingundicito7.29.0across the tree. The direct dependencies@actions/coreand@actions/githubwere also bumped (to^2.0.0and^7.0.0respectively) so that@actions/http-clientresolves to3.0.2, which declaresundici@^6.23.0— aligning the parent chain as closely as possible before the resolution takes effect.@fastify/busboy
@fastify/busboywas a transitive dependency at2.1.1, pulled in byundici@5.29.0(which declared@fastify/busboy@^2.0.0). The fix was achieved indirectly:undici@7.x(resolved via theresolutionsoverride described above) dropped its dependency on@fastify/busboyentirely, eliminating the vulnerable2.1.1instance from the tree. No separate resolution or parent bump was needed for@fastify/busboyitself; the only remaining lockfile entry for it is3.2.2, a safe stale entry left from an intermediate install step.Version changes
undici5.29.07.29.0resolutionsoverride (^7.24.1); no parent chain could deliver7.x@fastify/busboy2.1.13.2.2undiciwas upgraded to7.x(which dropped the dependency)@actions/core^1.10.0^2.0.0@actions/http-clientto3.xrange (which declaresundici@^6.x)@actions/github^6.0.0^7.0.0@actions/http-clientto3.xrange (which declaresundici@^6.x)@actions/http-client2.2.33.0.2@actions/core@^2.0.0and@actions/github@^7.0.0