Skip to content

chore(deps): bump undici from 6.27.0 to 6.28.0 in the security-production group across 1 directory - #9663

Merged
dd-octo-sts[bot] merged 1 commit into
masterfrom
dependabot/npm_and_yarn/security-production-685b0d7bcd
Aug 3, 2026
Merged

chore(deps): bump undici from 6.27.0 to 6.28.0 in the security-production group across 1 directory#9663
dd-octo-sts[bot] merged 1 commit into
masterfrom
dependabot/npm_and_yarn/security-production-685b0d7bcd

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the security-production group with 1 update in the / directory: undici.

Updates undici from 6.27.0 to 6.28.0

Release notes

Sourced from undici's releases.

v6.28.0

⚠️ Security fixes

  • GHSA-m8rv-5g2x-5cg5: a malicious type property on a duck-typed blob-like HTTP/1.1 request body could inject CRLF sequences into the generated content-type header. Undici now coerces and validates the value before adding it to the request. Fixed by 740a0b7c.
  • GHSA-8xcm-r25x-g524: the retry interceptor could expose a stale Content-Length after resuming a partial response, potentially causing downstream response desynchronization, hangs, or corruption. Undici now rejects partial responses whose Content-Length is inconsistent with Content-Range. Fixed by cba3a52a, with corrected fixtures in 4fd5a0c6.
  • GHSA-v3r7-h72x-cjcm: unsanitized domain and unparsed values passed to setCookie() could inject cookie attributes. Undici now validates cookie domains, paths, and unparsed attributes more strictly. Fixed by af748404.

GHSA-4cwx-7wf7-3272 and GHSA-jr45-8vmc-qm54 affect the cache interceptor in Undici v7 and v8; Undici v6 is not in their affected version ranges.

Full Changelog: nodejs/undici@v6.27.0...v6.28.0

Commits
  • 01a912e Bumped v6.28.0 (#5591)
  • 481ecfc Use Node 22 and npm 11 to release
  • 740a0b7 fix: validate blob body content type
  • 2698e49 fix: validate coerced header values for CRLF (#5579)
  • 4fd5a0c test(retry): correct broken content-range fixtures in retry-handler.js
  • cba3a52 fix(retry): reject partial content length mismatch
  • af74840 fix: harden cookie domain, path, and unparsed attribute validation
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the security-production group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).


Updates `undici` from 6.27.0 to 6.28.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.27.0...v6.28.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.28.0
  dependency-type: indirect
  dependency-group: security-production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependabot dependencies javascript Pull requests that update javascript code semver-patch labels Aug 3, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 3, 2026 21:06
@dependabot dependabot Bot added semver-patch dependencies javascript Pull requests that update javascript code dependabot labels Aug 3, 2026
@dd-octo-sts
dd-octo-sts Bot enabled auto-merge (squash) August 3, 2026 21:07
@dd-octo-sts

dd-octo-sts Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Overall package size

Self size: 7.76 MB
Deduped: 8.42 MB
No deduping: 8.42 MB

Dependency sizes | name | version | self size | total size | |------|---------|-----------|------------| | import-in-the-middle | 3.3.3 | 125.43 kB | 441.68 kB | | opentracing | 0.14.7 | 194.81 kB | 194.81 kB | | dc-polyfill | 0.1.11 | 25.74 kB | 25.74 kB |

🤖 This report was automatically generated by heaviest-objects-in-the-universe

@datadog-official

datadog-official Bot commented Aug 3, 2026

Copy link
Copy Markdown

Tests

🎉 All green!

🧪 All tests passed
❄️ No new flaky tests detected

🔄 Datadog retried 1 test - 1 passed on retry View in Datadog

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 48b7ba4 | Docs | Datadog PR Page | Give us feedback!

@pr-commenter

pr-commenter Bot commented Aug 3, 2026

Copy link
Copy Markdown

Benchmarks

Benchmark execution time: 2026-08-03 21:18:51

Comparing candidate commit 48b7ba4 in PR branch dependabot/npm_and_yarn/security-production-685b0d7bcd with baseline commit fd78cdb in branch master.

📊 Benchmarking dashboard

Found 0 performance improvements and 0 performance regressions! Performance is the same for 2314 metrics, 44 unstable metrics.

Explanation

This is an A/B test comparing a candidate commit's performance against that of a baseline commit. Performance changes are noted in the tables below as:

  • 🟩 = significantly better candidate vs. baseline
  • 🟥 = significantly worse candidate vs. baseline

We compute a confidence interval (CI) over the relative difference of means between metrics from the candidate and baseline commits, considering the baseline as the reference.

If the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD), the change is considered significant.

Feel free to reach out to #apm-benchmarking-platform on Slack if you have any questions.

More details about the CI and significant changes

You can imagine this CI as a range of values that is likely to contain the true difference of means between the candidate and baseline commits.

CIs of the difference of means are often centered around 0%, because often changes are not that big:

---------------------------------(------|---^--------)-------------------------------->
                              -0.6%    0%  0.3%     +1.2%
                                 |          |        |
         lower bound of the CI --'          |        |
sample mean (center of the CI) -------------'        |
         upper bound of the CI ----------------------'

As described above, a change is considered significant if the CI is entirely outside the configured SIGNIFICANT_IMPACT_THRESHOLD (or the deprecated UNCONFIDENCE_THRESHOLD).

For instance, for an execution time metric, this confidence interval indicates a significantly worse performance:

----------------------------------------|---------|---(---------^---------)---------->
                                       0%        1%  1.3%      2.2%      3.1%
                                                  |   |         |         |
       significant impact threshold --------------'   |         |         |
                      lower bound of CI --------------'         |         |
       sample mean (center of the CI) --------------------------'         |
                      upper bound of CI ----------------------------------'

Unstable benchmarks

These benchmarks have a confidence interval too wide to call a change; treat them as noise rather than signal.

scenario:appsec-appsec-enabled-24

  • unstable execution_time [-211627.240µs; +213614.974µs] or [-7.931%; +8.006%]

scenario:appsec-appsec-enabled-26

  • unstable execution_time [-235.763ms; +220.308ms] or [-9.213%; +8.609%]

scenario:appsec-appsec-enabled-with-attacks-24

  • unstable execution_time [-156.893ms; +161.814ms] or [-5.092%; +5.251%]

scenario:appsec-appsec-enabled-with-attacks-26

  • unstable execution_time [-193.199ms; +187.627ms] or [-6.634%; +6.443%]

scenario:appsec-control-20

  • unstable execution_time [-117256.794µs; +117424.027µs] or [-7.136%; +7.146%]

scenario:appsec-control-24

  • unstable execution_time [-113958.516µs; +112283.896µs] or [-9.273%; +9.137%]

scenario:appsec-control-26

  • unstable execution_time [-126.910ms; +129.905ms] or [-10.205%; +10.446%]

scenario:appsec-iast-no-vulnerability-iast-enabled-default-config-20

  • unstable execution_time [-10.462ms; +15.814ms] or [-4.132%; +6.247%]

scenario:debugger-line-probe-with-snapshot-default-24

  • unstable cpu_user_time [-1760.999ms; +577.721ms] or [-21.275%; +6.979%]
  • unstable execution_time [-1762.327ms; +608.092ms] or [-19.593%; +6.761%]
  • unstable instructions [-15.0G instructions; +4.9G instructions] or [-22.185%; +7.262%]
  • unstable throughput [-171.571op/s; +470.001op/s] or [-4.683%; +12.828%]

scenario:debugger-line-probe-with-snapshot-default-26

  • unstable cpu_user_time [-3.602s; +0.504s] or [-35.068%; +4.910%]
  • unstable execution_time [-3.703s; +0.535s] or [-33.609%; +4.854%]
  • unstable instructions [-32.0G instructions; +4.2G instructions] or [-37.007%; +4.905%]
  • unstable throughput [-111.676op/s; +718.824op/s] or [-3.605%; +23.203%]

scenario:debugger-line-probe-with-snapshot-minimal-24

  • unstable cpu_user_time [-2016.502ms; +3173.001ms] or [-24.350%; +38.315%]
  • unstable execution_time [-2021.999ms; +3199.311ms] or [-22.485%; +35.576%]
  • unstable instructions [-17.2G instructions; +27.3G instructions] or [-25.519%; +40.446%]
  • unstable max_rss_usage [-8.482MB; +13.430MB] or [-5.401%; +8.552%]
  • unstable throughput [-851.099op/s; +540.285op/s] or [-23.232%; +14.748%]

scenario:debugger-line-probe-without-snapshot-24

  • unstable cpu_user_time [-2000.416ms; +3159.175ms] or [-24.173%; +38.175%]
  • unstable execution_time [-2022.647ms; +3175.444ms] or [-22.517%; +35.350%]
  • unstable instructions [-17.1G instructions; +27.1G instructions] or [-25.309%; +40.109%]
  • unstable max_rss_usage [-8.465MB; +12.961MB] or [-5.398%; +8.265%]
  • unstable throughput [-846.287op/s; +544.183op/s] or [-23.081%; +14.842%]

scenario:debugger-line-probe-without-snapshot-26

  • unstable cpu_user_time [-3546.300ms; +3677.660ms] or [-34.327%; +35.598%]
  • unstable execution_time [-3575.435ms; +3685.991ms] or [-32.273%; +33.271%]
  • unstable instructions [-31944.1M instructions; +32717.8M instructions] or [-36.762%; +37.653%]
  • unstable max_rss_usage [-12243.854KB; +12088.654KB] or [-7.594%; +7.498%]
  • unstable throughput [-727.757op/s; +687.981op/s] or [-23.730%; +22.433%]

scenario:dogstatsd-with-tags-20

  • unstable cpu_user_time [-422.125ms; +275.495ms] or [-8.670%; +5.658%]
  • unstable execution_time [-422.687ms; +275.160ms] or [-8.550%; +5.566%]
  • unstable throughput [-96845.419op/s; +150827.804op/s] or [-5.704%; +8.884%]

scenario:plugin-claude-agent-sdk-compact-stream-scan-24

  • unstable cpu_usage_percentage [-6.774%; +3.948%]

scenario:plugin-claude-agent-sdk-compact-stream-scan-26

  • unstable cpu_usage_percentage [-6.191%; +5.614%]
  • unstable cpu_user_time [-3210.517µs; +2950.856µs] or [-5.257%; +4.831%]

scenario:plugin-graphql-long-with-depth-and-collapse-off-20

  • unstable max_rss_usage [-21.040MB; +26.120MB] or [-5.323%; +6.608%]

scenario:plugin-graphql-long-with-depth-off-20

  • unstable max_rss_usage [-6597.574KB; +8164.431KB] or [-5.122%; +6.339%]

scenario:plugin-graphql-long-with-depth-off-26

  • unstable max_rss_usage [-26.548MB; +16.771MB] or [-11.829%; +7.473%]

scenario:plugin-graphql-long-with-depth-on-max-20

  • unstable execution_time [-571.282ms; +616.092ms] or [-4.852%; +5.232%]
  • unstable throughput [-3.602op/s; +3.321op/s] or [-5.272%; +4.861%]

scenario:plugin-pg-service-26

  • unstable execution_time [-92.915ms; +40.769ms] or [-10.224%; +4.486%]

scenario:test-optimization-large-suite-20

  • unstable max_rss_usage [-3.108MB; +8.632MB] or [-3.871%; +10.751%]

@dd-octo-sts
dd-octo-sts Bot merged commit a9ef87a into master Aug 3, 2026
677 of 678 checks passed
@dd-octo-sts
dd-octo-sts Bot deleted the dependabot/npm_and_yarn/security-production-685b0d7bcd branch August 3, 2026 21:20
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Aug 4, 2026
dd-octo-sts Bot pushed a commit that referenced this pull request Aug 4, 2026
Bumps the security-production group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).


Updates `undici` from 6.27.0 to 6.28.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.27.0...v6.28.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.28.0
  dependency-type: indirect
  dependency-group: security-production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
dd-octo-sts Bot pushed a commit that referenced this pull request Aug 4, 2026
Bumps the security-production group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).


Updates `undici` from 6.27.0 to 6.28.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.27.0...v6.28.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.28.0
  dependency-type: indirect
  dependency-group: security-production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@dd-octo-sts dd-octo-sts Bot mentioned this pull request Aug 4, 2026
juan-fernandez pushed a commit that referenced this pull request Aug 5, 2026
Bumps the security-production group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).


Updates `undici` from 6.27.0 to 6.28.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.27.0...v6.28.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.28.0
  dependency-type: indirect
  dependency-group: security-production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
juan-fernandez pushed a commit that referenced this pull request Aug 5, 2026
Bumps the security-production group with 1 update in the / directory: [undici](https://github.com/nodejs/undici).


Updates `undici` from 6.27.0 to 6.28.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v6.27.0...v6.28.0)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 6.28.0
  dependency-type: indirect
  dependency-group: security-production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependabot dependencies javascript Pull requests that update javascript code semver-patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants