Skip to content

fix(@angular-devkit/build-angular): bump undici to 7.28.0#33459

Merged
alan-agius4 merged 1 commit into
angular:20.3.xfrom
alan-agius4:security-bump-undici-20.3.x
Jun 25, 2026
Merged

fix(@angular-devkit/build-angular): bump undici to 7.28.0#33459
alan-agius4 merged 1 commit into
angular:20.3.xfrom
alan-agius4:security-bump-undici-20.3.x

Conversation

@alan-agius4

Copy link
Copy Markdown
Collaborator

Bumps undici to version 7.28.0 to resolve the GHSA-vxpw-j846-p89q security vulnerability.
Also mentions GHSA-fx2h-pf6j-xcff.

Fixes #33449

Bumps undici to version 7.28.0 to resolve the GHSA-vxpw-j846-p89q security vulnerability.
Also mentions GHSA-fx2h-pf6j-xcff.

Fixes angular#33449

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the undici dependency from version 7.13.0 to 7.28.0 in both the root package.json and the packages/angular_devkit/build_angular/package.json files. I have no feedback to provide.

@alan-agius4 alan-agius4 added action: review The PR is still awaiting reviews from at least one requested reviewer target: lts This PR is targeting a version currently in long-term support labels Jun 25, 2026
@alan-agius4 alan-agius4 requested a review from clydin June 25, 2026 06:44
@alan-agius4 alan-agius4 linked an issue Jun 25, 2026 that may be closed by this pull request
@alan-agius4 alan-agius4 added action: merge The PR is ready for merge by the caretaker and removed action: review The PR is still awaiting reviews from at least one requested reviewer labels Jun 25, 2026
@alan-agius4 alan-agius4 merged commit 4ea787c into angular:20.3.x Jun 25, 2026
34 of 35 checks passed
@alan-agius4 alan-agius4 deleted the security-bump-undici-20.3.x branch June 25, 2026 12:26
@alan-agius4

Copy link
Copy Markdown
Collaborator Author

This PR was merged into the repository. The changes were merged into the following branches:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: @angular-devkit/build-angular target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Backport undici security bump to the 21.2.x LTS branch

2 participants