Skip to content

chore(deps): bump undici from 6.25.0 to 6.27.0 - #135

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/undici-6.27.0
Open

chore(deps): bump undici from 6.25.0 to 6.27.0#135
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/undici-6.27.0

chore(deps): bump undici from 6.25.0 to 6.27.0

2810a99
Select commit
Loading
Failed to load commit list.
Kusari Inspector / Kusari Inspector succeeded Jun 23, 2026 in 49s

Security Analysis Passed

No security issues found

Details

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

Both analyses independently recommend proceeding, and the combined risk profile remains net-positive. The dependency update advances undici from 6.25.0 to 6.27.0, remediating 4 known vulnerabilities: a WebSocket denial-of-service (CVE-2026-12151, CVSS A:H) and an HTTP header injection (CVE-2026-9679, CVSS I:H), along with two lower-severity issues. The updated version carries no active advisories, scores 10/10 on maintenance and code review, and uses a permissive MIT license. The code analysis returned zero findings — no code issues, no exposed secrets, and no workflow concerns in the modified files. There are no new risks introduced by this PR, and merging it reduces the attack surface by eliminating high-severity vulnerabilities in the transitive dependency chain.

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 2810a99, performed at: 2026-06-23T21:05:33Z