Commit d175aab
fix: override undici to ^6.24.0 to resolve GHSA-vrm6-8vpv-qv8q
Add npm overrides to force undici to ^6.24.0, fixing the WebSocket
permessage-deflate decompression bomb vulnerability (CVE-2026-1526).
This updates undici from 5.29.0 to 6.24.1 across all transitive
dependencies (@actions/core and @actions/github).
Agent-Logs-Url: https://github.com/github/webpack-bundlesize-compare-action/sessions/83dc3a69-3a72-415b-837e-dafd4cb7c840
Co-authored-by: arelia <2359538+arelia@users.noreply.github.com>1 parent a8b488d commit d175aab
2 files changed
Lines changed: 85 additions & 84 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
32 | 35 | | |
33 | 36 | | |
34 | 37 | | |
| |||
0 commit comments