chore(deps): bump undici from 6.25.0 to 6.27.0 - #135
Security Analysis Passed
No security issues found
Details
Kusari Analysis Results:
✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.
Both analyses independently recommend proceeding, and the combined risk profile remains net-positive. The dependency update advances undici from 6.25.0 to 6.27.0, remediating 4 known vulnerabilities: a WebSocket denial-of-service (CVE-2026-12151, CVSS A:H) and an HTTP header injection (CVE-2026-9679, CVSS I:H), along with two lower-severity issues. The updated version carries no active advisories, scores 10/10 on maintenance and code review, and uses a permissive MIT license. The code analysis returned zero findings — no code issues, no exposed secrets, and no workflow concerns in the modified files. There are no new risks introduced by this PR, and merging it reduces the attack surface by eliminating high-severity vulnerabilities in the transitive dependency chain.
Note
View full detailed analysis result for more information on the output and the checks that were run.
@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 2810a99, performed at: 2026-06-23T21:05:33Z