Skip to content

chore: bump the dependencies group with 2 updates - #805

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/dependencies-2d044e59e0
Closed

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/dependencies-2d044e59e0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 2 updates: actions-toolkit and undici.

Updates actions-toolkit from 8b38ee5 to cf0f68b

Commits
  • cf0f68b chore(deps-dev): bump @​commitlint/cli from 21.2.2 to 21.2.3 (#481)
  • cfe7677 chore(deps): bump undici from 6.28.0 to 6.29.0 (#482)
  • 8e7e9c1 chore(deps-dev): bump @​commitlint/config-conventional (#480)
  • 5dafb7e chore(deps-dev): bump prettier from 3.9.8 to 3.9.9 (#479)
  • fc9d67e chore(deps-dev): bump eslint from 10.10.0 to 10.11.0 (#478)
  • a8bee96 chore(deps-dev): bump prettier from 3.9.6 to 3.9.8 (#477)
  • ecd8629 chore(deps-dev): bump js-yaml from 4.3.1 to 4.3.2 (#476)
  • d6e9be1 chore(deps-dev): bump eslint from 10.9.1 to 10.10.0 (#475)
  • 76a7508 chore(deps-dev): bump globals from 17.11.0 to 17.12.0 (#474)
  • dd2bef4 chore(deps-dev): bump fast-uri from 3.1.5 to 3.1.7 (#472)
  • See full diff in compare view

Updates undici from 6.28.0 to 6.28.1

Release notes

Sourced from undici's releases.

v6.28.1

⚠️ Security fixes

High severity

  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 2af0faf8.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 07c60d9c.

Low severity

  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by ce31bc82.

What's Changed

Full Changelog: nodejs/undici@v6.28.0...v6.28.1

Commits
  • ffc8aa0 Bumped v6.28.1 (#5773)
  • 3866a3b perf(h1): drop idle-socket timer floor with a ref'd setImmediate (#5707) (#5770)
  • ce31bc8 fix(retry): validate resumed response framing
  • 2af0faf fix(websocket): reject unrequested subprotocols
  • 07c60d9 fix(websocket): destroy inflater after decompression limit
  • bd90fff perf: reduce EventSourceStream parser allocations (#5032) (#5647)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 2 updates: [actions-toolkit](https://github.com/nearform/actions-toolkit) and [undici](https://github.com/nodejs/undici).


Updates `actions-toolkit` from `8b38ee5` to `cf0f68b`
- [Commits](nearform/actions-toolkit@8b38ee5...cf0f68b)

Updates `undici` from 6.28.0 to 6.28.1
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.28.0...v6.28.1)

---
updated-dependencies:
- dependency-name: actions-toolkit
  dependency-version: cf0f68b486dc78d881650771fef56fec0609e14b
  dependency-type: direct:production
  dependency-group: dependencies
- dependency-name: undici
  dependency-version: 6.28.1
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 1, 2026
@Tony133

Tony133 commented Oct 1, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 1, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/dependencies-2d044e59e0 branch October 1, 2026 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant