Skip to content

fix: Bump undici from 7.28.0 to 7.29.1 - #10674

Merged
mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:fix/undici-7.29.1
Sep 23, 2026
Merged

mtrezza merged 1 commit into
parse-community:alphafrom
mtrezza:fix/undici-7.29.1

Conversation

@mtrezza

@mtrezza mtrezza commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Issue

undici is vulnerable in the production dependency tree, and no existing PR covers it.

@parse/push-adapter -> expo-server-sdk@6.1.0 -> undici, resolved in the lockfile to 7.28.0 with dev: false. That version carries five open Dependabot alerts on alpha:

Advisory Severity Affected Patched
GHSA-4cwx-7wf7-3272 High >= 7.0.0, < 7.29.0 7.29.0
GHSA-m8rv-5g2x-5cg5 Medium >= 7.0.0, < 7.29.0 7.29.0
GHSA-jr45-8vmc-qm54 Medium >= 7.0.0, < 7.29.0 7.29.0
GHSA-v3r7-h72x-cjcm Medium >= 7.0.0, < 7.29.0 7.29.0
GHSA-8xcm-r25x-g524 Medium >= 7.0.0, < 7.29.0 7.29.0

#10646 does not fix this. It bumps a different undici copy — the 6.x one under @actions/http-client, which is dev: true. The vulnerable production copy is a separate lockfile entry at node_modules/expo-server-sdk/node_modules/undici.

Closes #10646

Approach

Refresh the undici resolutions in package-lock.json (npm update undici). Lockfile only; package.json is untouched, since undici is not a direct dependency.

PROD  node_modules/expo-server-sdk/node_modules/undici          7.28.0 -> 7.29.1
dev   node_modules/@semantic-release/github/node_modules/undici 7.28.0 -> 7.29.1
dev   node_modules/undici                                       6.27.0 -> 6.28.1

The third line is exactly what #10646 does, so this supersedes it and additionally clears the three dev-scope < 6.28.0 advisories it was opened for.

Why not bump expo-server-sdk or @parse/push-adapter instead

Neither route fixes this:

  • expo-server-sdk@6.1.0 declares undici: "^7.2.0", and so does the latest expo-server-sdk@7.2.0. The range already admits 7.29.1; only the lockfile resolution was stale, so bumping the SDK changes nothing here.
  • @parse/push-adapter@8.5.3 (latest, vs 8.4.0 pinned here) still pins expo-server-sdk: "6.1.0" exactly — identical to 8.4.0. So a push-adapter bump does not move undici either. That upgrade is worth doing on its own merits and is proposed separately; it is deliberately not coupled to this security fix.

Worth a follow-up upstream: @parse/push-adapter pinning expo-server-sdk to an exact version is what froze this subtree. A caret range would let consumers pick up transitive fixes without waiting on a push-adapter release.

Breaking Changes

None. Both bumps stay within their existing semver ranges (^7.2.0 and ^6.23.0), and undici is not used directly by Parse Server.

Code Changes Required

None.

Notes

  • The lockfile diff is 21 insertions / 18 deletions with no packages added or removed; only these three entries change version.
  • 7.29.0 and 7.29.1 are both security releases; since alpha is on 7.28.0, the fixes from both apply.

Tasks

Summary by CodeRabbit

  • Chores
    • Updated dependency lockfile entries to newer undici patch versions.
    • Refreshed associated package download URLs and integrity metadata.
    • Added license metadata for select package entries.

@parse-github-assistant

Copy link
Copy Markdown

🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review.

Tip

  • Keep pull requests small. Large PRs will be rejected. Break complex features into smaller, incremental PRs.
  • Use Test Driven Development. Write failing tests before implementing functionality. Ensure tests pass.
  • Group code into logical blocks. Add a short comment before each block to explain its purpose.
  • We offer conceptual guidance. Coding is up to you. PRs must be merge-ready for human review.
  • Our review focuses on concept, not quality. PRs with code issues will be rejected. Use an AI agent.
  • Human review time is precious. Avoid review ping-pong. Inspect and test your AI-generated code.

Note

Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect.

Caution

Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: d2171d49-94bc-430c-9e2f-190a731fad9b

📥 Commits

Reviewing files that changed from the base of the PR and between 948cf36 and f862ff9.

📒 Files selected for processing (1)
  • package-lock.json

Included review availability: Your plan provides up to 10 included reviews per hour; 5 remain after this review.


📝 Walkthrough

Walkthrough

The lockfile updates nested and top-level undici entries from 7.28.0 to 7.29.1 and from 6.27.0 to 6.28.1. It also refreshes URLs and integrity hashes.

Changes

Undici dependency lockfile update

Layer / File(s) Summary
Update undici versions and integrity data
package-lock.json
Nested and top-level references use the updated undici versions. Resolved URLs and integrity hashes are refreshed. Three package entries also include MIT license metadata.

Priority: ⬆️ High

Estimated code review effort: 1 (Trivial) | ~5 minutes

Severity of issue fixed: High

Merge Risk: ⚪ Minimal · up to f862f

The dependency refresh is limited to lockfile resolutions and is ready to merge.

🚥 Pre-merge checks | ✅ 6 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Out of Scope Changes check ⚠️ Warning The PR also updates the production undici resolution under expo-server-sdk from 7.28.0 to 7.29.1. Issue [#10646] covers only the development update from 6.27.0 to 6.28.1. The production se… Remove the production 7.28.0 to 7.29.1 lockfile update, or link an issue that explicitly requires this production dependency update.
✅ Passed checks (6 passed)
Check name Status Explanation
Title check ✅ Passed The title begins with the required fix: prefix, uses a capitalized first word after the prefix, and accurately describes the undici version update.
Description check ✅ Passed The description includes the required Issue, Approach, and Tasks sections. It explains the security purpose, affected dependency paths, version changes, scope, and security check. The standard introdu…
Linked Issues check ✅ Passed Issue [#10646] requires undici 6.27.0 to 6.28.1. The PR summary reports this development resolution update in package-lock.json, including the lockfile metadata. The issue has no separate code…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Security Check ✅ Passed PASS. The pull request changes only package-lock.json; it introduces no executable code or new security-sensitive pattern. The production node_modules/expo-server-sdk/node_modules/undici record ch…
Engage In Review Feedback ✅ Passed The supplied current-review result reports zero actionable findings. Therefore, this pull request has no current review feedback that requires engagement, implementation, or reviewer retraction.
Full details: Out of Scope Changes check

Explanation

The PR also updates the production undici resolution under expo-server-sdk from 7.28.0 to 7.29.1. Issue [#10646] covers only the development update from 6.27.0 to 6.28.1. The production security update has no directly linked issue in the supplied scope.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@codecov

codecov Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.83%. Comparing base (ae167c4) to head (f862ff9).
⚠️ Report is 1 commits behind head on alpha.

Additional details and impacted files
@@            Coverage Diff             @@
##            alpha   #10674      +/-   ##
==========================================
+ Coverage   93.43%   93.83%   +0.40%     
==========================================
  Files         192      192              
  Lines       16882    16882              
  Branches      252      252              
==========================================
+ Hits        15773    15842      +69     
+ Misses       1083     1018      -65     
+ Partials       26       22       -4     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mtrezza
mtrezza merged commit 2f09a30 into parse-community:alpha Sep 23, 2026
41 of 43 checks passed
parseplatformorg pushed a commit that referenced this pull request Sep 23, 2026
## [9.10.1-alpha.18](9.10.1-alpha.17...9.10.1-alpha.18) (2026-09-23)

### Bug Fixes

* Bump undici from 7.28.0 to 7.29.1 ([#10674](#10674)) ([2f09a30](2f09a30))
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.10.1-alpha.18

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Sep 23, 2026
@mtrezza
mtrezza deleted the fix/undici-7.29.1 branch September 23, 2026 09:31
parseplatformorg pushed a commit that referenced this pull request Sep 24, 2026
## [9.10.1](9.10.0...9.10.1) (2026-09-24)

### Bug Fixes

* `Parse.Query.explain` runs afterFind trigger on query plan results ([#10536](#10536)) ([64d58ff](64d58ff))
* Account takeover via empty password in LDAP auth adapter ([GHSA-863r-39r9-vfcf](GHSA-863r-39r9-vfcf)) ([#10642](#10642)) ([f261957](f261957))
* Bump @parse/push-adapter from 8.4.0 to 8.5.3 ([#10676](#10676)) ([ae167c4](ae167c4))
* Bump body-parser from 2.2.2 to 2.3.0 ([#10600](#10600)) ([77e955f](77e955f))
* Bump express-rate-limit from 8.3.1 to 8.7.0 ([#10672](#10672)) ([73d8600](73d8600))
* Bump follow-redirects from 1.15.11 to 1.16.0 ([#10577](#10577)) ([d577327](d577327))
* Bump parse from 8.6.0 to 8.6.2, @parse/push-adapter from 8.5.3 to 8.5.5 and ws from 8.21.0 to 8.21.3 ([#10688](#10688)) ([11c8a40](11c8a40))
* Bump qs from 6.15.2 to 6.16.0 ([#10651](#10651)) ([25263e7](25263e7))
* Bump undici from 7.28.0 to 7.29.1 ([#10674](#10674)) ([2f09a30](2f09a30))
* Bump ws from 8.20.0 to 8.21.0 ([#10576](#10576)) ([629426f](629426f))
* Creating a session can delete another user's session ([#10582](#10582)) ([0df8779](0df8779))
* GraphQL argument and enum validation errors disclose target class names when public introspection is disabled ([GHSA-6m77-f8xr-f723](GHSA-6m77-f8xr-f723)) ([#10665](#10665)) ([fead3db](fead3db))
* GraphQL schema is disclosed by replaying an automatic persisted query when public introspection is disabled ([GHSA-gxxq-pghq-9vrc](GHSA-gxxq-pghq-9vrc)) ([#10669](#10669)) ([8d22053](8d22053))
* Install the latest Parse Server version in bootstrap.sh ([#10556](#10556)) ([997ee15](997ee15))
* LiveQuery discloses protected fields by resolving an incomplete subscriber identity ([GHSA-9jpp-xhh6-75mf](GHSA-9jpp-xhh6-75mf)) ([#10654](#10654)) ([66c507b](66c507b))
* Per-entry cache TTL is ignored by the in-memory cache adapter ([#10671](#10671)) ([1352c67](1352c67))
* Rate limit is bypassed by sending request header `X-Forwarded-For: 127.0.0.1` when Parse Server option `trustProxy` is permissive ([#10664](#10664)) ([ebd425e](ebd425e))
* Relation count query bypasses protectedFields for identity-scoped groups ([GHSA-rmhf-xv62-rm99](GHSA-rmhf-xv62-rm99)) ([#10667](#10667)) ([a32977f](a32977f))
* Server crash from unhandled promise rejection when multiple Cloud Code validator fields fail ([#10540](#10540)) ([90c2778](90c2778))
* Unauthenticated deletion of installation records via operator injection in device token deduplication ([GHSA-cc6h-c8m4-hgrx](GHSA-cc6h-c8m4-hgrx)) ([#10657](#10657)) ([ad00f82](ad00f82))
* Unverified auth provider identity accepted on password login for code-based auth adapters ([GHSA-mr43-w6c2-mvjq](GHSA-mr43-w6c2-mvjq)) ([#10662](#10662)) ([9b73e6f](9b73e6f))
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.10.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

state:released Released as stable version state:released-alpha Released as alpha version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants