Skip to content

fix: upgrade Undici to preserve TLS validation - #944

Merged
sds merged 1 commit into
mainfrom
centaur/fix-undici-tls-validation-1790916294
Oct 2, 2026
Merged

sds merged 1 commit into
mainfrom
centaur/fix-undici-tls-validation-1790916294

Conversation

@decofe

@decofe decofe commented Oct 2, 2026

Copy link
Copy Markdown
Member

Summary

Force affected transitive Undici resolutions to 8.10.2 and regenerate the lockfile, preserving the existing Undici major version. Parent tooling currently constrains affected releases, so the override prevents subsequent installs from restoring them.

Addresses GHSA-w293-vg96-wgc3 / CVE-2026-84961. The flaw drops custom TLS verification callbacks or connectors in BalancedPool. This is precautionary dependency remediation; local exploitability and deployment/release adoption are not established.

Validation

Frozen install and pnpm check:types passed. CI=true pnpm test is blocked at Vocs startup by a failed remote OpenAPI fetch.

Merging this PR patches source/dependency resolution only; consuming artifacts must still be rebuilt and rolled out.

Prompted by: @sds

Co-authored-by: Derek Cofausper <256792747+decofe@users.noreply.github.com>
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
tempo-docs Ready Ready Preview Oct 2, 2026 4:55am UTC

Request Review

@sds
sds marked this pull request as ready for review October 2, 2026 05:26
@sds
sds merged commit 28a05b3 into main Oct 2, 2026
14 checks passed
@sds
sds deleted the centaur/fix-undici-tls-validation-1790916294 branch October 2, 2026 05:26

This branch was successfully deployed

1 active deployment
Preview — 062ba595 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants