Skip to content

Conversation

olivier-thatch
Copy link

undici 5.28.x has a known security vulnerability: nodejs/undici#3895

The issue was fixed in 5.29.0 by nodejs/undici#4088

@olivier-thatch
Copy link
Author

@ptomas-figma @tomduncalf-figma I know the contributing guidelines say you're not accepting PRs, but this is a security issue. Without this fix, projects including figma/code-connect are potentially vulnerable to the undici DoS issue described in the issue linked above.

@olivier-thatch olivier-thatch changed the title Bump undici to 5.29.0 [SECURITY FIX] Bump undici to 5.29.0 May 19, 2025
@slees-figma
Copy link

Hey @olivier-thatch, thanks for the contribution! We can't accept PRs on the public repo due to our release process but I've merged your change on our side which'll be going out soon in the next release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants