Skip to content

http-client: prepare 4.0.2 undici dependency release - #2515

Closed
tunc-d wants to merge 1 commit into
actions:mainfrom
tunc-d:tunc-d-http-client-dependency-release
Closed

tunc-d wants to merge 1 commit into
actions:mainfrom
tunc-d:tunc-d-http-client-dependency-release

Conversation

@tunc-d

@tunc-d tunc-d commented Oct 1, 2026 •

Copy link
Copy Markdown

Summary

  • Prepare @actions/http-client 4.0.2, a dependency-only patch release. Current main and npm latest are 4.0.1; 4.0.2 is not published.
  • Raise the undici minimum from ^6.23.0 to ^6.28.1; regenerate the HTTP-client lockfile with npm, resolving Undici to 6.29.0.
  • Change only HTTP-client's manifest, lockfile/version metadata, and release notes. Preserve existing overrides; add none. No source/API, artifact retry, or consumer changes.

Release isolation and prerequisite

Extracts the HTTP-client dependency slice from #2498, as requested by review. Undici is on the proxy-dispatcher path and should be reviewed and released independently of artifact retry behavior. Artifact's own 6.3.0 release metadata remains with #2498; this PR prepares only HTTP-client 4.0.2. The redundant artifact-release PR #2516 is closed.

Recommended order: #2517 audit baseline maintenance → this HTTP-client release PR → #2498 artifact retry/release. #2517 is the prerequisite for repairing the repository-wide audit baseline. Its pushed head 4eb240c03b7ce94f9c302c927071cd9ae3de24eb includes HTTP-client's lock-only Undici refresh from 6.24.0 to already-published 6.29.0. HTTP-client remains 4.0.1 with undici ^6.23.0 in that audit PR: no HTTP-client dependency-floor, package-version, release-note, or source changes. That included baseline maintenance is distinct from this PR's raised minimum and 4.0.2 release metadata. Neither PR is merged, and this branch has not been rebased.

After HTTP-client 4.0.2 is published, consumers can raise their HTTP-client minimum instead of adding Undici overrides. Those consumer-minimum changes remain blocked on publication and are outside this PR. #2517 uses published dependencies and does not depend on HTTP-client 4.0.2 being published.

The original dependency slice was verified at #2498 head 96a554adc0d46b0850b5f1acb63aa108753f177e against main dc752c75f8868e7e83761116161c952938b8ddae; #2498 has since been narrowed to artifact-only files at head 2511873a0eb2f2e0182c598ddd02d6f9ec564aed. Release metadata follows #2500 and previous HTTP-client dependency-only patch releases.

#2512 overlaps only with the lockfile update. This PR additionally raises the manifest's minimum and prepares the package release; it does not alter or close that PR.

Dependency floor verification

Live GitHub advisories identify 6.28.1 as the first patched Undici v6 release for GHSA-rfgv-xxqx-mfg5, GHSA-3wwx-pv8p-q78v, and GHSA-r53p-7pc4-xj5r. The npm bulk advisory endpoint returned no advisories for either 6.28.1 or 6.29.0 at validation time. The assigned ^6.28.1 floor is patched; the lockfile uses newer 6.29.0. Both declare Node >=18.17.

Validation

  • Node 24.21.0: npm run build --prefix packages/http-client; npm test -- --runInBand --forceExit --testPathPattern=packages/http-client — 5 suites, 75 tests passed.
  • Node 20.20.2: npm exec --yes --package=node@20 -- sh -c 'node --version && npm run build --prefix packages/http-client && npm test -- --runInBand --forceExit --testPathPattern=packages/http-client' — 5 suites, 75 tests passed.
  • Proxy tests passed on both runtimes: routing, bypass, authentication/URI-encoded credentials, and the Undici ProxyAgent dispatcher.
  • npm audit --prefix packages/http-client --package-lock-only --audit-level=moderate — 0 vulnerabilities.
  • ./node_modules/.bin/eslint 'packages/http-client/**/*.ts'; ./node_modules/.bin/prettier --check 'packages/http-client/**/*.ts'; git diff --check — passed.
  • npm pack --dry-run --json from packages/http-client — version 4.0.2, 15 files; expected ESM exports and declarations present.
  • Verified consistent manifest/lockfile versions, no changed lockfile package entry except Undici, and exactly the three HTTP-client release files in the live PR diff.

CI status / prerequisite blocker

At this PR's unchanged head 3af00a0522a4c28679a97918f53f3329c506aaeb, all listed non-audit checks have completed successfully, including the six Node 20/24 platform matrix jobs. Repository-wide audit run failed in unchanged @actions/core:audit-moderate with one high-severity vulnerability; the same run's @actions/http-client@4.0.2 audit completed with 0 vulnerabilities.

#2517 owns baseline audit remediation. Its initial CI exposed the complementary failure in unchanged HTTP-client 4.0.1; the now-included HTTP-client lock-only refresh removes that audit-ordering cycle. Its owner reports the CI-equivalent local sequence (npm install, npm run bootstrap, root production audit, and npm run audit-all) exits 0, with the root production audit and all nine package audits reporting zero vulnerabilities. This is local validation, not a remote CI-green claim. Verify #2517's remote checks and checks on the resulting baseline before considering this PR unblocked. No unrelated dependency changes are added here to bypass the audit blocker.

No code rebase, merge, auto-merge, npm publication, or source review-thread replies performed.

Raise the undici minimum to 6.28.1 and regenerate the package lockfile at 6.29.0. Isolate the HTTP-client release from artifact retry behavior changes.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant