Skip to content

[1.0] chore: override undici to ^7.29.0, ip-address to ^10.3.1, brace-expansion build tool to ^5.0.9 - #294

Merged
xyos merged 1 commit into
1.0from
fix/override-undici-ip-address-1.0
Aug 7, 2026
Merged

[1.0] chore: override undici to ^7.29.0, ip-address to ^10.3.1, brace-expansion build tool to ^5.0.9#294
xyos merged 1 commit into
1.0from
fix/override-undici-ip-address-1.0

Conversation

@xyos

@xyos xyos commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Issue

V2313695928

Description of Changes

Bumps npm dependency override versions flagged by the nightly Security Scan (Amazon Inspector, code-editor-sagemaker-server target) and regenerates the affected package-lock overrides + OSS attribution.

  • undici: ^7.28.0 -> ^7.29.0
  • ip-address: ^10.1.1 -> ^10.3.1
  • brace-expansion (in build-tools/oss-attribution/oss-attribution-generator): ^5.0.8 -> ^5.0.9

The downstream finding-override-{shell-quote,tar,ws}.diff patches are refreshed only for diff-context drift in the shared root overrides block; their own override versions are unchanged.

Note: on main the brace-expansion build-tool bump is covered by Dependabot PR #292; that PR targets main only, so this branch includes the bump directly.

Testing

  • ./scripts/prepare-src.sh applies the full patch series cleanly for both leaf targets (code-editor-sagemaker-server and code-editor-web-embedded-with-terminal) after the rebase-heal.
  • ./scripts/update-package-locks.sh regenerated lockfiles + unified OSS attribution for all four targets with exit 0, inside the code-editor-ubuntu container.
  • Verified resolved versions with jq in all 8 lockfiles (4 series, root + remote/): undici 7.29.0 and ip-address 10.4.0 (>= 10.3.1) everywhere; brace-expansion resolves to 5.0.9 in the build-tool lockfile.
  • LICENSE-THIRD-PARTY diff is exactly the two version lines (ip-address 10.2.0 -> 10.4.0, undici 7.28.0 -> 7.29.0).

Screenshots/Videos

N/A

Additional Notes

Override-only change; no source/behavior changes. Patch headers keep the deterministic @generator metadata (scripts/patches/apply-override.sh) so they can be regenerated on upstream bumps.

Backporting

Same fix raised separately against main (#293), 1.1, and 1.2.


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

…sion build tool to ^5.0.9

Bumps the undici and ip-address dependency override versions flagged by the nightly Security Scan and regenerates the affected package-lock overrides and OSS attribution. Also bumps brace-expansion to ^5.0.9 in the oss-attribution-generator build tool. Downstream finding-override patches (shell-quote, tar, ws) are refreshed only for context drift in the shared overrides block; their own override versions are unchanged.
@xyos
xyos added this pull request to the merge queue Aug 7, 2026
Merged via the queue into 1.0 with commit f2f2c27 Aug 7, 2026
1 check passed
@xyos
xyos deleted the fix/override-undici-ip-address-1.0 branch August 7, 2026 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants