Skip to content

fix(deps): clear high advisories, drop expired PartyKit exception - #40

Merged
sarthakagrawal927 merged 1 commit into
mainfrom
fix/dependency-gate-undici
Oct 3, 2026
Merged

sarthakagrawal927 merged 1 commit into
mainfrom
fix/dependency-gate-undici

Conversation

@sarthakagrawal927

Copy link
Copy Markdown
Member

The "Code health" job has failed on main since run 35635208148: quality:dependencies throws because the time-boxed PartyKit/Miniflare advisory exception expired on 2026-09-12 (#26). The current audit also shows 3 more high advisories that aren't on the allowlist.

Advisory Package Path Fix
GHSA-vrm6-8vpv-qv8q, GHSA-v9p9-hfj2-hcw8, GHSA-vxpw-j846-p89q undici 5.29.0 server>partykit>miniflare override undici@^5.28.4 → 6.29.0
GHSA-x8mw-p69m-v3mx @fastify/busboy via undici 5 removed (undici 6 no longer depends on it)
GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p brace-expansion 5.0.9 ultracite>glob>minimatch (dev) override 5.x → 5.0.12

The gate no longer has an allowlist or expiry date, so any critical/high advisory fails it.

pnpm audit: 0 critical/high, 4 moderate. node scripts/check-code-health.mjs dependencies passes.

Risk: the undici override crosses Miniflare 3's declared ^5.28.4 range. It only affects the parked v2 PartyKit relay (server/, used by pnpm run dev), not the v1 on-phone path. The same override is on draft #39, where Miniflare dispatchFetch, redirects and WebSocket echo were checked on Node 20.19. PartyKit's own bundled Undici copy is not covered by this change, and #26 tracks that.

Overlaps with draft #39 (same package.json overrides, except brace-expansion 5.0.12 here vs 5.0.11). #39 will need a trivial rebase.

🤖 Generated with Claude Code

The code-health dependency gate has failed since 2026-09-12 when the
time-boxed PartyKit/Miniflare Undici exception expired; three more highs
(brace-expansion x2, @fastify/busboy) have since appeared.

- override undici ^5.28.4 (miniflare 3, via partykit) to 6.29.0, which
  also drops the vulnerable @fastify/busboy dependency
- override brace-expansion 5.x to 5.0.12 (dev, via ultracite)
- remove the advisory allowlist and expiry; any critical/high now fails

pnpm audit: 0 critical/high (4 moderate). Refs #26.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sarthakagrawal927
sarthakagrawal927 merged commit 6df7cc3 into main Oct 3, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant