Closed dependabot[bot] closed 7 months ago
As a (transitive) runtime dependency (evidence below) I have added this change to the changelog and added the security label (given CVE-2024-30260 and CVE-2024-30261). However, it appears to me this vulnerability has no or low impact on this project so I'm not rushing to releasing this (let me know here or in an issue if you think this should be released urgently).
$ npm ls undici --omit dev
svgo-action@4.0.8 /path/to/svgo-action
└─┬ @actions/core@1.10.1
└─┬ @actions/http-client@2.2.1
└── undici@5.28.3
Bumps undici from 5.28.3 to 5.28.4.
Release notes
Sourced from undici's releases.
Commits
fb98306
Bumped v5.28.42b39440
Merge pull request from GHSA-9qxr-qj54-h67264e3402
Merge pull request from GHSA-m4v8-wqvr-p9f7723c4e7
Revert "build(deps-dev): bump formdata-node from 4.4.1 to 6.0.3 (#2389)"0e9d54b
skip failing test due to Node.js changesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show