Force undici 7.29.0 to clear Dependabot alerts - #54
Merged
Conversation
wrangler pulls in miniflare, which pins undici at an exact 7.28.0, so version bumps of wrangler can never move it. Five open advisories (one high, four medium) are all fixed in 7.29.0, hence the override. Dev-only dependency: undici backs wrangler dev and the deploy tooling, not the deployed Worker, which uses the runtime's own fetch.
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
terminal | 82e1449 | Commit Preview URL Branch Preview URL |
Aug 10 2026, 05:10 AM |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes the five open Dependabot alerts on
main(1 high, 4 moderate), all of which areundiciadvisories fixed in 7.29.0.wranglerdepends onminiflare, which pinsundiciat an exact7.28.0, so no amount of wrangler bumping will move it. An npmoverridesentry is the only way to shift a transitively pinned version.Scope:
undiciis a dev-only dependency here. It backswrangler devand the deploy tooling; the deployed Worker uses the runtime fetch, so production was never exposed.Verified locally:
npm ciresolvesundici@7.29.0 overridden,npm run buildsucceeds,wrangler devboots and serves the site,/api/whoamireturns 200, and the/mtm/mtm.jsMatomo proxy still completes its outbound subrequest (the path that actually exercises undici).