Skip to content

Fix: Undici version bump to address CVE Fix#110

Merged
mohanmanikanta2299 merged 2 commits into
mainfrom
fix/SECVULN-47080
Jun 24, 2026
Merged

Fix: Undici version bump to address CVE Fix#110
mohanmanikanta2299 merged 2 commits into
mainfrom
fix/SECVULN-47080

Conversation

@mohanmanikanta2299

Copy link
Copy Markdown
Collaborator

This PR has been raised to bump the Undici dependency version to fix this CVE

The PR also enables dependabot to raise automated PRs for dependency bumps to avoid manual dependency updates in future.

PCI review checklist

  • I have documented a clear reason for, and description of, the change I am making.

  • If applicable, I've documented a plan to revert these changes if they require more than reverting the pull request.

  • If applicable, I've documented the impact of any changes to security controls.

    Examples of changes to security controls include using new access control methods, adding or removing logging pipelines, etc.

@mohanmanikanta2299 mohanmanikanta2299 requested a review from a team as a code owner June 23, 2026 08:47
Comment thread .github/dependabot.yml
directory: "/"
schedule:
interval: "daily"
allow:

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔥

@mohanmanikanta2299 mohanmanikanta2299 merged commit d5ede48 into main Jun 24, 2026
6 checks passed
@mohanmanikanta2299 mohanmanikanta2299 deleted the fix/SECVULN-47080 branch June 24, 2026 06:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants