Skip to content

[1.2] chore: override undici to ^7.29.0, ip-address to ^10.3.1, brace-expansion build tool to ^5.0.9 - #296

Merged
xyos merged 1 commit into
1.2from
fix/override-undici-ip-address-1.2
Aug 7, 2026
Merged

[1.2] chore: override undici to ^7.29.0, ip-address to ^10.3.1, brace-expansion build tool to ^5.0.9#296
xyos merged 1 commit into
1.2from
fix/override-undici-ip-address-1.2

Conversation

@xyos

@xyos xyos commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Issue

Description of Changes

Bumps npm dependency override versions flagged by the nightly Security Scan (Amazon Inspector, code-editor-sagemaker-server target) and regenerates the affected package-lock overrides + OSS attribution.

  • undici: ^7.28.0 -> ^7.29.0
  • ip-address: ^10.1.1 -> ^10.3.1
  • brace-expansion (in build-tools/oss-attribution/oss-attribution-generator): ^5.0.8 -> ^5.0.9

The downstream finding-override-{axios,ws,github-copilot,form-data,tar,anthropic-sdk,shell-quote}.diff patches and a few later quilt-managed patches are refreshed only for diff-context drift in the shared root overrides block (hunk offsets and header style); their own override versions and code changes are unchanged.

Note: on main the brace-expansion build-tool bump is covered by Dependabot PR #292; that PR targets main only, so this branch includes the bump directly.

Testing

  • ./scripts/prepare-src.sh applies the full patch series cleanly for both leaf targets (code-editor-sagemaker-server and code-editor-web-embedded-with-terminal) after the rebase-heal.
  • ./scripts/update-package-locks.sh regenerated lockfiles + unified OSS attribution for all four targets with exit 0, inside the code-editor-ubuntu container.
  • Verified resolved versions with jq in all 8 lockfiles (4 series, root + remote/): undici 7.29.0 and ip-address 10.4.0 (>= 10.3.1) everywhere; brace-expansion resolves to 5.0.9 in the build-tool lockfile.
  • LICENSE-THIRD-PARTY diff is exactly the two version lines (ip-address 10.2.0 -> 10.4.0, undici 7.28.0 -> 7.29.0).

Screenshots/Videos

N/A

Additional Notes

Override-only change; no source/behavior changes. Patch headers keep the deterministic @generator metadata (scripts/patches/apply-override.sh) so they can be regenerated on upstream bumps.

Backporting

Same fix raised separately against main (#293), 1.0 (#294), and 1.1 (#295).


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

…sion build tool to ^5.0.9

Bumps the undici and ip-address dependency override versions flagged by the nightly Security Scan and regenerates the affected package-lock overrides and OSS attribution. Also bumps brace-expansion to ^5.0.9 in the oss-attribution-generator build tool. Downstream finding-override patches (axios, ws, github-copilot, form-data, tar, anthropic-sdk, shell-quote) and quilt-managed patches later in the series are refreshed for context drift in the shared overrides block; their own override versions and code changes are unchanged.
@xyos
xyos requested a review from a team as a code owner August 7, 2026 17:11
@xyos
xyos enabled auto-merge August 7, 2026 17:28
@xyos
xyos added this pull request to the merge queue Aug 7, 2026
Merged via the queue into 1.2 with commit 4a7c87c Aug 7, 2026
1 check passed
@xyos
xyos deleted the fix/override-undici-ip-address-1.2 branch August 7, 2026 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants