Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency "undici" flagged as vulnerable package by code scan #327

Open
vegardei opened this issue Jan 28, 2025 · 3 comments
Open

Dependency "undici" flagged as vulnerable package by code scan #327

vegardei opened this issue Jan 28, 2025 · 3 comments

Comments

@vegardei
Copy link

vegardei commented Jan 28, 2025

Hi,

We had to bump the referenced package "undici" to version 5.28.5 in order to pass Snyk's vulnarability tests:
https://security.snyk.io/vuln/SNYK-JS-UNDICI-8641354

It would be nice if this project also did the same.

@vegardei vegardei changed the title Flagged as vulnerable package by code scan Dependency "undici" flagged as vulnerable package by code scan Jan 28, 2025
@MrCNeale
Copy link

We have the same issue flagged by github enterprise dependabot.

@hallvictoria
Copy link
Contributor

Thanks for reporting! We bumped the version in #328 and will do a new release soon. The fix will be in @azure/functions 4.6.1, and ETA is early-mid next week.

@timtucker
Copy link

timtucker commented Feb 16, 2025

This seems like a pretty short-term fix.

Undici V5 EOL is slated for April 30, 2025:
https://blog.platformatic.dev/undici-v7-is-here

Moving ahead with #305 would help here, although pushing Node 22 as a dependency when support for 22 in Azure Functions hasn't gone to GA yet is an issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants