Skip to content

fix: resolve npm audit vulnerabilities#301

Merged
joakimen merged 1 commit intomasterfrom
fix-npm-vulnerabilities
Feb 5, 2026
Merged

fix: resolve npm audit vulnerabilities#301
joakimen merged 1 commit intomasterfrom
fix-npm-vulnerabilities

Conversation

@joakimen
Copy link
Contributor

@joakimen joakimen commented Feb 5, 2026

Summary

  • Update @actions/http-client 3.0.1 → 3.0.2 to fix undici vulnerability
  • Update undici 5.29.0 → 6.23.0 (unbounded decompression chain - GHSA-g9mf-h72j-4rw9)
  • Update npm 11.8.0 → 11.9.0 (includes tar and brace-expansion fixes)

Resolves 5 vulnerabilities (2 moderate, 3 high) reported by npm audit.

Update dependencies to fix high and moderate severity vulnerabilities:
- @actions/http-client 3.0.1 → 3.0.2 (fixes undici vulnerability)
- undici 5.29.0 → 6.23.0 (unbounded decompression chain)
- npm 11.8.0 → 11.9.0 (includes tar and brace-expansion fixes)
@joakimen joakimen merged commit f63ff0d into master Feb 5, 2026
3 checks passed
@joakimen joakimen deleted the fix-npm-vulnerabilities branch February 5, 2026 11:38
@github-actions
Copy link

github-actions bot commented Feb 5, 2026

🎉 This PR is included in version 3.17.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant