Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| JavaScript | Mar 26, 2026 1:24p.m. | Review ↗ | |
| Secrets | Mar 26, 2026 1:24p.m. | Review ↗ |
Bumps [undici](https://github.com/nodejs/undici) from 7.20.0 to 7.24.6. - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v7.20.0...v7.24.6) --- updated-dependencies: - dependency-name: undici dependency-version: 7.24.6 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
f5f2fca to
766902c
Compare
guibranco
left a comment
There was a problem hiding this comment.
Automatically approved by gstraccini[bot]
|
Infisical secrets check: ✅ No secrets leaked! 💻 Scan logs2026-03-26T13:23:43Z INF scanning for exposed secrets...
1:23PM INF 547 commits scanned.
2026-03-26T13:23:44Z INF scan completed in 637ms
2026-03-26T13:23:44Z INF no leaks found
|
Bumps undici from 7.20.0 to 7.24.6.
Release notes
Sourced from undici's releases.
... (truncated)
Commits
38eab36Bumped v7.24.6 (#4931)993609dtest: auto-init WPT submodule (#4930)1eacc49build(deps-dev): bump typescript from 5.9.3 to 6.0.2 (#4926)b64e7e4fix: avoid prototype collisions in parseHeaders (#4923)deba679Revert "fix: assume http/https scheme for scheme-less proxy env vars (#4914)"feef62bfix: support Connection header with connection-specific header names per RFC ...a613d9adocs: clarify fetch and FormData pairing (#4922)2ba99a3fix: wrap kConnector call in try/catch to prevent client hang (#4834)a7398c0fix(cache): check Authorization on request headers per RFC 9111 §3.5 (#4911)2b2afbcfix: assume http/https scheme for scheme-less proxy env vars (#4914)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.