chore(deps): bump undici and openclaw in /openclaw - #15
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [undici](https://github.com/nodejs/undici) to 8.10.0 and updates ancestor dependency [openclaw](https://github.com/openclaw/openclaw). These dependencies need to be updated together. Updates `undici` from 8.3.0 to 8.10.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](nodejs/undici@v8.3.0...v8.10.0) Updates `openclaw` from 2026.6.5 to 2026.8.1 - [Release notes](https://github.com/openclaw/openclaw/releases) - [Changelog](https://github.com/openclaw/openclaw/blob/v2026.8.1/CHANGELOG.md) - [Commits](openclaw/openclaw@v2026.6.5...v2026.8.1) --- updated-dependencies: - dependency-name: undici dependency-version: 8.10.0 dependency-type: indirect - dependency-name: openclaw dependency-version: 2026.8.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
@dependabot recreate |
|
The dependabot.yml entry that created this PR has been deleted so this PR can't be recreated. Please close the PR so Dependabot can create a new one with the current dependabot.yml. |
|
@dependabot recreate |
|
The dependabot.yml entry that created this PR has been deleted so this PR can't be recreated. Please close the PR so Dependabot can create a new one with the current dependabot.yml. |
|
Closing rather than recreating again. These are pre-grouping security PRs: each edits the same lockfile as its sibling, so merging one conflicts the other, The repo now has |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps undici to 8.10.0 and updates ancestor dependency openclaw. These dependencies need to be updated together.
Updates
undicifrom 8.3.0 to 8.10.0Release notes
Sourced from undici's releases.
... (truncated)
Commits
c8d80e6Bumped v8.10.0 (#5644)66923b4fix: preserve DNS origin hostname on sockets (#5577)3926499fix: retry refused HTTP/2 streams (#5598)73d6e9efix(h2): detach upgrade close handler after GOAWAY (#5641)b111adbfix(mock): emit request body lifecycle hooks (#5367)ae4a3e3build(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#5636)ec3fbf1build(deps): bump github/codeql-action/init from 4.36.2 to 4.37.3 (#5634)2151720build(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 (#5633)b96a116fix(interceptors): allow interceptors without opts.origin (#5628)a18ef2dfix(mock): non-string path matchers under ignoreTrailingSlash, and DataView r...Updates
openclawfrom 2026.6.5 to 2026.8.1Release notes
Sourced from openclaw's releases.
... (truncated)
Changelog
Sourced from openclaw's changelog.
... (truncated)
Commits
ea80657chore(release): refresh 2026.8.1 final changeloge1199b1fix(plugin-sdk): preserve shipped caller contracts6866c58chore(release): finalize 2026.8.1 changelog061bffdtest: include Android approval in publish workflow routing8be657dfix: keep Android publication independent of core releaseda582d9fix: allow Android releases from protected publish tagsce39365fix: package oversized release contribution records without losing notesf2fae49docs: finalize 2026.8.1 release notes131fbd6test(agents): use real admission and durable sessions in runner fixturesbeb07f5fix(agents): preserve native session accounting at finalizationDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.