Skip to content

chore(deps): update dependency @vercel/ncc to v0.44.1 - #349

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/vercel-ncc-0.x
Open

chore(deps): update dependency @vercel/ncc to v0.44.1#349
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/vercel-ncc-0.x

Conversation

@renovate

@renovate renovate Bot commented Jun 23, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@vercel/ncc 0.38.40.44.1 age confidence

Release Notes

vercel/ncc (@​vercel/ncc)

v0.44.1

Compare Source

Bug Fixes

v0.44.0

Compare Source

Features

v0.43.0

Compare Source

Changes

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner June 23, 2026 19:16
@renovate renovate Bot added dependencies Pull requests that update a dependency file renovate PR created by RenovateBot labels Jun 23, 2026
@renovate
renovate Bot force-pushed the renovate/vercel-ncc-0.x branch from 4d62ecd to f49bf41 Compare July 14, 2026 03:13
@renovate renovate Bot changed the title chore(deps): update dependency @vercel/ncc to v0.44.0 chore(deps): update dependency @vercel/ncc to v0.44.1 Jul 14, 2026
@renovate
renovate Bot force-pushed the renovate/vercel-ncc-0.x branch from f49bf41 to c301073 Compare August 11, 2026 22:47
@renovate
renovate Bot force-pushed the renovate/vercel-ncc-0.x branch from c301073 to f9f9403 Compare August 12, 2026 09:44
@github-actions

Copy link
Copy Markdown
Contributor

JS Dependency Audit

0 added · 0 removed · 19 total (0 vs base)

Projects audited
  • . (manager: yarn-classic)
  • ./dist (manager: unknown) — skipped on PR head: no recognized lockfile

No change in vulnerabilities compared to the base branch.

Full current vulnerability list (19)
  • 🟠 high brace-expansion (>=3.0.0 <5.0.7) — brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups advisory
  • 🟠 high brace-expansion (>=4.0.0 <5.0.8) — brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash advisory
  • 🟠 high brace-expansion (>=4.0.0 <5.0.9) — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation advisory
  • 🟠 high flatted (<3.4.0) — flatted vulnerable to unbounded recursion DoS in parse() revive phase advisory
  • 🟠 high flatted (<=3.4.1) — Prototype Pollution via parse() in NodeJS flatted advisory
  • 🟠 high undici (>=6.0.0 <6.24.0) — Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client advisory
  • 🟠 high undici (<6.24.0) — Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression advisory
  • 🟠 high undici (<6.24.0) — Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation advisory
  • 🟠 high undici (<6.27.0) — undici WebSocket client vulnerable to denial of service via fragment count bypass advisory
  • 🟡 moderate brace-expansion (>=4.0.0 <5.0.5) — brace-expansion: Zero-step sequence causes process hang and memory exhaustion advisory
  • 🟡 moderate brace-expansion (>=5.0.0 <5.0.6) — brace-expansion: Large numeric range defeats documented max DoS protection advisory
  • 🟡 moderate undici (<6.24.0) — Undici has an HTTP Request/Response Smuggling issue advisory
  • 🟡 moderate undici (<6.24.0) — Undici has CRLF Injection in undici via upgrade option advisory
  • 🟡 moderate undici (<6.27.0) — undici vulnerable to HTTP header injection via Set-Cookie percent-decoding advisory
  • 🟡 moderate undici (<6.28.0) — undici vulnerable to downstream response desynchronization via retry interceptor advisory
  • 🟡 moderate undici (<6.28.0) — undici vulnerable to CRLF Injection via blob-like body 'type' property advisory
  • 🟡 moderate undici (<6.28.0) — undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields advisory
  • 🔵 low undici (<6.27.0) — undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching advisory
  • 🔵 low undici (<6.27.0) — undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse advisory

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file renovate PR created by RenovateBot

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants