Skip to content

Commit f3cec28

Browse files
authored
Bump undici due to security issue (#8044)
See GHSA-3787-6prv-h9w3 For reference, `undici` is used to polyfill `fetch` in our Node bundles, as we are not restricting Node support to 18+ yet. Fixes #8038
1 parent e5a1a34 commit f3cec28

File tree

10 files changed

+21
-12
lines changed

10 files changed

+21
-12
lines changed

.changeset/short-falcons-look.md

+9
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
---
2+
'@firebase/auth-compat': patch
3+
'@firebase/firestore': patch
4+
'@firebase/functions': patch
5+
'@firebase/storage': patch
6+
'@firebase/auth': patch
7+
---
8+
9+
Bump undici version to 5.28.3 due to security issue.

integration/messaging/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@
1515
"express": "4.18.2",
1616
"geckodriver": "2.0.4",
1717
"mocha": "9.2.2",
18-
"undici": "5.26.5",
18+
"undici": "5.28.3",
1919
"selenium-assistant": "6.1.1"
2020
}
2121
}

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -153,7 +153,7 @@
153153
"tslint": "6.1.3",
154154
"typedoc": "0.16.11",
155155
"typescript": "4.7.4",
156-
"undici": "5.26.5",
156+
"undici": "5.28.3",
157157
"watch": "1.0.2",
158158
"webpack": "5.76.0",
159159
"yargs": "17.7.2"

packages/auth-compat/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@
5454
"@firebase/auth-types": "0.12.0",
5555
"@firebase/component": "0.6.5",
5656
"@firebase/util": "1.9.4",
57-
"undici": "5.26.5",
57+
"undici": "5.28.3",
5858
"tslib": "^2.1.0"
5959
},
6060
"license": "Apache-2.0",

packages/auth/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -129,7 +129,7 @@
129129
"@firebase/component": "0.6.5",
130130
"@firebase/logger": "0.4.0",
131131
"@firebase/util": "1.9.4",
132-
"undici": "5.26.5",
132+
"undici": "5.28.3",
133133
"tslib": "^2.1.0"
134134
},
135135
"license": "Apache-2.0",

packages/firestore/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@
102102
"@firebase/webchannel-wrapper": "0.10.5",
103103
"@grpc/grpc-js": "~1.9.0",
104104
"@grpc/proto-loader": "^0.7.8",
105-
"undici": "5.26.5",
105+
"undici": "5.28.3",
106106
"tslib": "^2.1.0"
107107
},
108108
"peerDependencies": {

packages/functions/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@
7171
"@firebase/auth-interop-types": "0.2.1",
7272
"@firebase/app-check-interop-types": "0.3.0",
7373
"@firebase/util": "1.9.4",
74-
"undici": "5.26.5",
74+
"undici": "5.28.3",
7575
"tslib": "^2.1.0"
7676
},
7777
"nyc": {

packages/storage/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@
4848
"dependencies": {
4949
"@firebase/util": "1.9.4",
5050
"@firebase/component": "0.6.5",
51-
"undici": "5.26.5",
51+
"undici": "5.28.3",
5252
"tslib": "^2.1.0"
5353
},
5454
"peerDependencies": {

repo-scripts/changelog-generator/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
"@changesets/types": "3.3.0",
2121
"@changesets/get-github-info": "0.5.2",
2222
"@types/node": "20.8.10",
23-
"undici": "5.26.5"
23+
"undici": "5.28.3"
2424
},
2525
"license": "Apache-2.0",
2626
"devDependencies": {

yarn.lock

+4-4
Original file line numberDiff line numberDiff line change
@@ -16835,10 +16835,10 @@ undici-types@~5.26.4:
1683516835
resolved "https://registry.npmjs.org/undici-types/-/undici-types-5.26.5.tgz#bcd539893d00b56e964fd2657a4866b221a65617"
1683616836
integrity sha512-JlCMO+ehdEIKqlFxk6IfVoAUVmgz7cU7zD/h9XZ0qzeosSHmUJVOzSQvvYSYWXkFXC+IfLKSIffhv0sVZup6pA==
1683716837

16838-
undici@5.26.5:
16839-
version "5.26.5"
16840-
resolved "https://registry.npmjs.org/undici/-/undici-5.26.5.tgz#f6dc8c565e3cad8c4475b187f51a13e505092838"
16841-
integrity sha512-cSb4bPFd5qgR7qr2jYAi0hlX9n5YKK2ONKkLFkxl+v/9BvC0sOpZjBHDBSXc5lWAf5ty9oZdRXytBIHzgUcerw==
16838+
undici@5.28.3:
16839+
version "5.28.3"
16840+
resolved "https://registry.npmjs.org/undici/-/undici-5.28.3.tgz#a731e0eff2c3fcfd41c1169a869062be222d1e5b"
16841+
integrity sha512-3ItfzbrhDlINjaP0duwnNsKpDQk3acHI3gVJ1z4fmwMK31k5G9OVIAMLSIaP6w4FaGkaAkN6zaQO9LUvZ1t7VA==
1684216842
dependencies:
1684316843
"@fastify/busboy" "^2.0.0"
1684416844

0 commit comments

Comments
 (0)