Conversation
Raise the undici minimum to 6.28.1 and regenerate the package lockfile at 6.29.0. Isolate the HTTP-client release from artifact retry behavior changes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
@actions/http-client4.0.2, a dependency-only patch release. Currentmainand npmlatestare 4.0.1; 4.0.2 is not published.undiciminimum from^6.23.0to^6.28.1; regenerate the HTTP-client lockfile with npm, resolving Undici to 6.29.0.Release isolation and prerequisite
Extracts the HTTP-client dependency slice from #2498, as requested by review. Undici is on the proxy-dispatcher path and should be reviewed and released independently of artifact retry behavior. Artifact's own 6.3.0 release metadata remains with #2498; this PR prepares only HTTP-client 4.0.2. The redundant artifact-release PR #2516 is closed.
Recommended order: #2517 audit baseline maintenance → this HTTP-client release PR → #2498 artifact retry/release. #2517 is the prerequisite for repairing the repository-wide audit baseline. Its pushed head
4eb240c03b7ce94f9c302c927071cd9ae3de24ebincludes HTTP-client's lock-only Undici refresh from 6.24.0 to already-published 6.29.0. HTTP-client remains 4.0.1 withundici ^6.23.0in that audit PR: no HTTP-client dependency-floor, package-version, release-note, or source changes. That included baseline maintenance is distinct from this PR's raised minimum and 4.0.2 release metadata. Neither PR is merged, and this branch has not been rebased.After HTTP-client 4.0.2 is published, consumers can raise their HTTP-client minimum instead of adding Undici overrides. Those consumer-minimum changes remain blocked on publication and are outside this PR. #2517 uses published dependencies and does not depend on HTTP-client 4.0.2 being published.
The original dependency slice was verified at #2498 head
96a554adc0d46b0850b5f1acb63aa108753f177eagainst maindc752c75f8868e7e83761116161c952938b8ddae; #2498 has since been narrowed to artifact-only files at head2511873a0eb2f2e0182c598ddd02d6f9ec564aed. Release metadata follows #2500 and previous HTTP-client dependency-only patch releases.#2512 overlaps only with the lockfile update. This PR additionally raises the manifest's minimum and prepares the package release; it does not alter or close that PR.
Dependency floor verification
Live GitHub advisories identify 6.28.1 as the first patched Undici v6 release for GHSA-rfgv-xxqx-mfg5, GHSA-3wwx-pv8p-q78v, and GHSA-r53p-7pc4-xj5r. The npm bulk advisory endpoint returned no advisories for either 6.28.1 or 6.29.0 at validation time. The assigned
^6.28.1floor is patched; the lockfile uses newer 6.29.0. Both declare Node>=18.17.Validation
npm run build --prefix packages/http-client;npm test -- --runInBand --forceExit --testPathPattern=packages/http-client— 5 suites, 75 tests passed.npm exec --yes --package=node@20 -- sh -c 'node --version && npm run build --prefix packages/http-client && npm test -- --runInBand --forceExit --testPathPattern=packages/http-client'— 5 suites, 75 tests passed.ProxyAgentdispatcher.npm audit --prefix packages/http-client --package-lock-only --audit-level=moderate— 0 vulnerabilities../node_modules/.bin/eslint 'packages/http-client/**/*.ts';./node_modules/.bin/prettier --check 'packages/http-client/**/*.ts';git diff --check— passed.npm pack --dry-run --jsonfrompackages/http-client— version 4.0.2, 15 files; expected ESM exports and declarations present.CI status / prerequisite blocker
At this PR's unchanged head
3af00a0522a4c28679a97918f53f3329c506aaeb, all listed non-audit checks have completed successfully, including the six Node 20/24 platform matrix jobs. Repository-wide audit run failed in unchanged@actions/core:audit-moderatewith one high-severity vulnerability; the same run's@actions/http-client@4.0.2audit completed with 0 vulnerabilities.#2517 owns baseline audit remediation. Its initial CI exposed the complementary failure in unchanged HTTP-client 4.0.1; the now-included HTTP-client lock-only refresh removes that audit-ordering cycle. Its owner reports the CI-equivalent local sequence (
npm install,npm run bootstrap, root production audit, andnpm run audit-all) exits 0, with the root production audit and all nine package audits reporting zero vulnerabilities. This is local validation, not a remote CI-green claim. Verify #2517's remote checks and checks on the resulting baseline before considering this PR unblocked. No unrelated dependency changes are added here to bypass the audit blocker.No code rebase, merge, auto-merge, npm publication, or source review-thread replies performed.