chore(deps): bump undici to 7.28.0 and nodemailer to 9.0.1#5218
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
PR SummaryLow Risk Overview
Reviewed by Cursor Bugbot for commit cde2e81. Configure here. |
Greptile SummaryThis PR updates mail and HTTP client dependencies for security fixes.
Confidence Score: 5/5This looks safe to merge.
Important Files Changed
Reviews (2): Last reviewed commit: "chore(deps): dedupe cheerio and e2b tran..." | Re-trigger Greptile |
|
@greptile |
|
@cursor review |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit cde2e81. Configure here.
Summary
undici7.25.0 → 7.28.0 to resolve 7 Dependabot alerts (3 High, 2 Moderate, 2 Low): WebSocket fragment-count DoS, SOCKS5 cross-origin routing, SOCKS5 ProxyAgent TLS bypass, shared-cache whitespace disclosure, Set-Cookie percent-decoding header injection, SameSite downgrade, keep-alive response queue poisoning.nodemailer8.0.9 → 9.0.1 to resolve 1 High alert: message-levelrawoption bypassingdisableFileAccess/disableUrlAccess(arbitrary file read + SSRF).@types/nodemailer7.0.4 → 8.0.1 to match the runtime major.Notes
Type of Change
Testing
bunx tsc --noEmitclean (0 errors)bun run lintcleanChecklist