From 2e3d75f7fd4dd26789819c5813cc9723d35cdf9d Mon Sep 17 00:00:00 2001 From: Noah Sherwin Date: Tue, 21 May 2024 20:26:06 -0700 Subject: [PATCH] fix: bump undici from 5.28.3 to 5.28.4 Fixes GHSA-m4v8-wqvr-p9f7 CVE-2024-30260 Fixes GHSA-9qxr-qj54-h672 CVE-2024-30261 --- package-lock.json | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index d1fe8524..98cffa8b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -13999,9 +13999,10 @@ } }, "node_modules/undici": { - "version": "5.28.3", - "resolved": "https://registry.npmjs.org/undici/-/undici-5.28.3.tgz", - "integrity": "sha512-3ItfzbrhDlINjaP0duwnNsKpDQk3acHI3gVJ1z4fmwMK31k5G9OVIAMLSIaP6w4FaGkaAkN6zaQO9LUvZ1t7VA==", + "version": "5.28.4", + "resolved": "https://registry.npmjs.org/undici/-/undici-5.28.4.tgz", + "integrity": "sha512-72RFADWFqKmUb2hmmvNODKL3p9hcB6Gt2DOQMis1SEBaV6a4MH8soBvzg+95CYhCKPFedut2JY9bMfrDl9D23g==", + "license": "MIT", "dependencies": { "@fastify/busboy": "^2.0.0" },