Skip to content

[pull] main from release-it:main#3

Open
pull[bot] wants to merge 286 commits intosemabit:mainfrom
release-it:main
Open

[pull] main from release-it:main#3
pull[bot] wants to merge 286 commits intosemabit:mainfrom
release-it:main

Conversation

@pull
Copy link
Copy Markdown

@pull pull bot commented Jan 14, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull bot locked and limited conversation to collaborators Jan 14, 2026
@pull pull bot added the ⤵️ pull label Jan 14, 2026
Yeom-JinHo and others added 19 commits January 20, 2026 16:18
- Update tar to 7.5.4 (GHSA-8qq5-rm4j-mr97)
- Update undici to 6.23.0 (GHSA-g9mf-h72j-4rw9)
- Add glob 13.0.0 override (GHSA-5j98-mcp5-4vw2)
…bilities (#1285)

undici 6.23.0 has 5 high-severity vulnerabilities (GHSA-f269-vfmq-vjvj,
GHSA-2mjp-6q6p-2qxm, GHSA-vrm6-8vpv-qv8q, GHSA-v9p9-hfj2-hcw8,
GHSA-4992-7rv2-5pvq). All are resolved in undici v7.

The only API used from undici is the Agent class (in the GitLab plugin
for custom TLS configuration), which is unchanged in v7.

Also tightens engines.node from ^20.12.0 to ^20.18.1 to match
undici v7 requirements.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Fixes [DEP0169: Insecure `url.parse()`](https://nodejs.org/api/deprecations.html#DEP0169)

Signed-off-by: Rafael Santos <rafael@risantos.com>
Co-authored-by: TFATF <the-fast-and-the-furious-42@proton.me>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.