Skip to content

Bump undici and workflow in /apps/web - #33

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/web/multi-fe11146aca
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/web/multi-fe11146aca

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown

Bumps undici to 7.30.0 and updates ancestor dependency workflow. These dependencies need to be updated together.

Updates undici from 7.29.0 to 7.30.0

Release notes

Sourced from undici's releases.

v7.30.0

What's Changed

Full Changelog: nodejs/undici@v7.29.1...v7.30.0

v7.29.1

⚠️ Security fixes

High severity

  • GHSA-w293-vg96-wgc3: BalancedPool could drop function-valued connection options while cloning its configuration, including custom TLS certificate validation callbacks. Undici now preserves connect and legacy tls options when creating upstreams. Fixed by f690157d.
  • GHSA-rfgv-xxqx-mfg5: a WebSocket server could select a subprotocol when none was requested, causing an uncaught TypeError that could terminate the process. Undici now rejects the handshake with protocol error 1002. Fixed by 6615e017.

Medium severity

  • GHSA-3wwx-pv8p-q78v: a malformed permessage-deflate payload exceeding the configured decompression limit could emit an unhandled zlib error and terminate the process. Undici now destroys the inflater after reaching the limit. Fixed by 63cf698b.
  • GHSA-rx4f-c7p8-82vq: an unclean WebSocketStream close could create an unobserved rejected promise when its writable stream was locked, potentially terminating the process. Undici now propagates the failure through the retained writable stream controller. Fixed by 1858656e.
  • GHSA-2jfj-6hjv-fm6j: shared caches could store and replay responses containing Set-Cookie, disclosing one user's cookies to another caller. Undici now excludes these responses from shared caches, including existing entries and revalidation paths. Fixed by b6c5a002.
  • GHSA-3xpg-4rpp-hhhm: the decompression interceptor did not bound decoded output, allowing compressed responses to consume excessive memory. Undici now limits every decompression stage to 64 MiB by default and supports a configurable maxSize. Fixed by 2c7d7e12.
  • GHSA-pmjh-fq2x-6v4x: a terminal retry failure after response headers were exposed could orphan the original response body, causing consumers to hang indefinitely. Undici now propagates the terminal error to the exposed body. Fixed by 3c672659.

Low severity

  • GHSA-8436-99hf-9mmv: cache interceptors could store and replay responses to unsafe HTTP methods such as POST or DELETE. Undici now restricts cache reads and writes to safe methods while preserving invalidation by successful unsafe requests. Fixed by b61d9432.
  • GHSA-2gqq-gqf2-x968: the dump interceptor could treat an oversized chunked response as successfully truncated when no Content-Length was present. Undici now enforces maxSize against received bytes and aborts oversized responses. Fixed by 21693f40.
  • GHSA-r53p-7pc4-xj5r: the retry interceptor could concatenate a resumed response with inconsistent framing into downstream output, enabling response splitting or corruption. Undici now validates Content-Range against the original response framing before resuming. Fixed by cd8af90b.

What's Changed

Full Changelog: nodejs/undici@v7.29.0...v7.29.1

Commits

Updates workflow from 4.8.3 to 4.8.11

Release notes

Sourced from workflow's releases.

workflow@4.8.11

@​workflow/world-vercel@​4.7.6

  • #4557 3c033a9 @​SandboxRD - Fix createQueueDispatcher() and createEventsDispatcher() crashing under Bun with compose is not a function. Bun resolves undici to its built-in module, whose dispatchers can't compose interceptors and are ignored by Bun's fetch, so the plain dispatcher is used instead.
  • #4275 b5a78f8 @​alangenfeld - Honor server-provided Retry-After delays when scheduling queue redeliveries.

@​workflow/builders@​4.1.16

  • #3954 08b4420 @​withkarann - Fix directive discovery missing "use step" and "use workflow" when a backtick appears earlier in a comment or regex literal
  • #4537 6bb5224 @​VaguelySerious - Keep JSON import attributes in generated bundles, and stop bundling the builder's own serde checker into step and workflow bundles

@​workflow/vite@​4.0.26

workflow@4.8.10

@​workflow/core@​4.8.10

  • #4176 e1f712b @​pranaygp - Fix an unhandled rejection that could exit the process when the encryption-key lookup for a forwarded writable stream failed (for example a run metadata read that timed out) before anything was written to that stream. The lookup now starts on the first write, and a failure rejects that stream instead.
  • #4443 3699c30 @​TooTallNate - Serialize a DataView as the bytes it views. It previously fell through to devalue's built-in encoding, which persists the whole backing ArrayBuffer — for a view onto Node's pooled Buffer allocator, unrelated process memory.
  • #4422 bc6a97f @​TooTallNate - Retry the max-deliveries run_failed/step_failed write and the step handler's workflow re-queue through queue redelivery when they fail transiently (429, 5xx, transport) instead of acking and leaving the run stuck running.
  • #4408 b23170d @​pranaygp - start() with an explicit deploymentId (and so recreateRunFromExisting, i.e. Replay Run) no longer fails in a process that is not itself a deployment; it takes the cross-deployment path instead.
  • #4326 5e6c79c @​pranaygp - Mark WorkflowRunFailedError and WorkflowRunCancelledError as non-retryable, and make FatalError.is() honor the fatal marker, so a step that reads a terminal run's returnValue fails on its first attempt with the error intact instead of exhausting its retry budget first.
  • #4179 d437c32 @​karthikscale3 - Route unrecognized backend connection and stream failures through existing retry policies, rebuilding shared event connections after repeated HTTP/2 failures. Keep invalid backend URLs, blocked ports, and unsupported request headers out of those retries. Include error cause chains in run-failure logs to expose underlying socket, DNS, and TLS failures.

@​workflow/cli@​4.3.14

@​workflow/world-local@​4.4.2

  • #4458 42c9810 @​pranaygp - Upgrade undici to 7.30.0, which stops a failed HTTP/2 stream from leaving a phantom in-flight request on its connection.

@​workflow/world-postgres@​4.3.8

  • #4458 42c9810 @​pranaygp - Upgrade undici to 7.30.0, which stops a failed HTTP/2 stream from leaving a phantom in-flight request on its connection.

@​workflow/world-vercel@​4.7.5

  • #4458 42c9810 @​pranaygp - Send event requests with bodies too large to re-buffer over HTTP/1.1 so they no longer stall behind in-flight HTTP/2 streams, and retry event-log reads whose HTTP/2 stream the peer reset.
  • #4179 d437c32 @​karthikscale3 - Route unrecognized backend connection and stream failures through existing retry policies, rebuilding shared event connections after repeated HTTP/2 failures. Keep invalid backend URLs, blocked ports, and unsupported request headers out of those retries. Include error cause chains in run-failure logs to expose underlying socket, DNS, and TLS failures.
  • #4458 42c9810 @​pranaygp - Upgrade undici to 7.30.0, which stops a failed HTTP/2 stream from leaving a phantom in-flight request on its connection.

@​workflow/web-shared@​4.1.26

@​workflow/next@​4.1.14

  • #4337 304e5dc @​pranaygp - Fix next dev sometimes running the workflow build (and starting a second watcher) twice on startup when Next.js resets process.env between next.config evaluations

... (truncated)

Changelog

Sourced from workflow's changelog.

4.8.11

Patch Changes

  • Updated dependencies []:
    • @​workflow/cli@​4.3.15
    • @​workflow/core@​4.8.11
    • @​workflow/astro@​4.0.26
    • @​workflow/nest@​4.0.27
    • @​workflow/next@​4.1.15
    • @​workflow/nitro@​4.1.17
    • @​workflow/rollup@​4.0.26
    • @​workflow/sveltekit@​4.0.26
    • @​workflow/typescript-plugin@​4.0.3
    • @​workflow/nuxt@​4.0.27

4.8.10

Patch Changes

4.8.9

Patch Changes

4.8.8

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [undici](https://github.com/nodejs/undici) to 7.30.0 and updates ancestor dependency [workflow](https://github.com/vercel/workflow/tree/HEAD/packages/workflow). These dependencies need to be updated together.


Updates `undici` from 7.29.0 to 7.30.0
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](nodejs/undici@v7.29.0...v7.30.0)

Updates `workflow` from 4.8.3 to 4.8.11
- [Release notes](https://github.com/vercel/workflow/releases)
- [Changelog](https://github.com/vercel/workflow/blob/workflow@4.8.11/packages/workflow/CHANGELOG.md)
- [Commits](https://github.com/vercel/workflow/commits/workflow@4.8.11/packages/workflow)

---
updated-dependencies:
- dependency-name: undici
  dependency-version: 7.30.0
  dependency-type: indirect
- dependency-name: workflow
  dependency-version: 4.8.11
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@dependabot
dependabot Bot requested a review from Litju as a code owner October 2, 2026 14:24
@dependabot dependabot Bot added javascript Pull requests that update javascript code dependencies Pull requests that update a dependency file labels Oct 2, 2026
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 926a51b0-13b0-4529-b105-ab2ddaebd275

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants