Skip to content

chore: override undici to ^7.29.1 for CVE fixes - #305

Merged
skazantsev merged 1 commit into
aws:1.2from
aakashmandavilli96:fix/cve-undici-7.29.1
Oct 6, 2026
Merged

skazantsev merged 1 commit into
aws:1.2from
aakashmandavilli96:fix/cve-undici-7.29.1

Conversation

@aakashmandavilli96

@aakashmandavilli96 aakashmandavilli96 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Issue

Description of Changes

Bumps the undici dependency override from ^7.29.0 to ^7.29.1 to resolve undici advisories flagged by the security scan (6 CVEs, 2 Critical): CVE-2026-13697, CVE-2026-84961, CVE-2026-14643, CVE-2026-19534, CVE-2026-84933, CVE-2026-85014.

undici 7.29.1 is the 7.x release that backports fixes for these advisories (every advisory range is < 7.29.1). Staying on the 7.x line is deliberate: the fix also exists on undici 8.x, but 8.x is a semver-major and @vscode/proxy-agent (undici's consumer, including its latest release) requires undici ^7.2.0 and does not accept 8.x. This follows the existing override in patches/common/finding-override-undici.diff.

Changed:

  • patches/common/finding-override-undici.diff — override target ^7.29.0 → ^7.29.1 (direct, global, remote/package.json@global)
  • package-lock-overrides/sagemaker.series/package-lock.json and .../remote/package-lock.json — undici version/resolved/integrity + root dep spec
  • LICENSE-THIRD-PARTY and overrides/LICENSE-THIRD-PARTY — OSS attribution 7.29.0 → 7.29.1

The engines constraint is unchanged (node >=20.18.1). The other scan-flagged packages (tar, shell-quote, ip-address) already carry fixed versions on this branch via their existing finding-override-*.diff patches.

Testing

npm audit reports 0 vulnerabilities for undici 7.29.1, where 7.29.0 reported 10 HIGH advisories (all with range < 7.29.1). Lock-override regeneration (scripts/update-package-locks.sh) and the SageMaker unit tests should run in CI, as they require prepared code-editor-src not present in a plain clone.

Screenshots/Videos

N/A — dependency version bump, no user-visible change.

Additional Notes

Stopgap override per the patch header convention ("Remove when upstream Code-OSS updates undici to >= 7.29.1"). The pending sagemakerCodeEditorVersion 1.10.2 already on this branch carries this fix; no further version bump is included here.

Backporting

Targets the 1.2 release branch. If main also pins undici at ^7.29.0, a sibling PR to main should follow.


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@aakashmandavilli96
aakashmandavilli96 requested a review from a team as a code owner October 5, 2026 21:38
@aakashmandavilli96
aakashmandavilli96 requested a review from a team as a code owner October 5, 2026 21:47
@aakashmandavilli96 aakashmandavilli96 changed the title chore: override undici to ^7.29.1 for CVE fixes chore: override undici to ^7.29.1 for CVE fixes and bump version to 1.10.3 Oct 5, 2026
Bumps the undici dependency override from ^7.29.0 to ^7.29.1, the 7.x
release that backports fixes for the undici advisories flagged by the
Security Scan (CVE-2026-13697, CVE-2026-84961, CVE-2026-14643,
CVE-2026-19534, CVE-2026-84933, CVE-2026-85014). Staying on the 7.x
line avoids the undici 8.x major, which @vscode/proxy-agent (undici's
consumer) does not accept.

Updates the finding-override-undici patch, both sagemaker.series
package-lock overrides (root and remote), and the OSS attribution.
Engines constraint is unchanged (node >=20.18.1).
@aakashmandavilli96 aakashmandavilli96 changed the title chore: override undici to ^7.29.1 for CVE fixes and bump version to 1.10.3 chore: override undici to ^7.29.1 for CVE fixes Oct 5, 2026
@skazantsev
skazantsev added this pull request to the merge queue Oct 6, 2026
Merged via the queue into aws:1.2 with commit 59d634b Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants