Conversation
Bumps [defu](https://github.com/unjs/defu) from 6.1.4 to 6.1.6. - [Release notes](https://github.com/unjs/defu/releases) - [Changelog](https://github.com/unjs/defu/blob/main/CHANGELOG.md) - [Commits](unjs/defu@v6.1.4...v6.1.6) --- updated-dependencies: - dependency-name: defu dependency-version: 6.1.6 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Deploying espresense with
|
| Latest commit: |
5e892df
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://eadf129f.espresense.pages.dev |
| Branch Preview URL: | https://dependabot-npm-and-yarn-defu.espresense.pages.dev |
There was a problem hiding this comment.
Code Review Summary
Verdict: Approved — routine dependency updates from dependabot
Changes Overview
| Package | From | To |
|---|---|---|
undici |
7.14.0 | 7.24.4 |
@astrojs/cloudflare |
12.6.13 | 13.1.8 |
wrangler |
4.61.1 | 4.81.1 |
Security Updates ✅
The undici update includes important security fixes for multiple CVEs (CVE-2026-1525, CVE-2026-1528, CVE-2026-2581, CVE-2026-1527) — including a high severity WebSocket frame handling vulnerability. This alone justifies merging.
@astrojs/cloudflare v12 → v13
Major version jump, but review of the changelog shows this is a smooth upgrade:
- Fixes
ERR_MULTIPLE_CONSUMERSwith Cloudflare Queues - Fixes dev-mode crash loop with Starlight
- Fixes HMR crash with content collection files
- Fixes unnecessary prerendering of redirect destinations
- All patch releases, no breaking API changes noted
wrangler Update
Minor/patch updates with workerd updates and AI Search binding fixes. No concerns.
✅ Looks Good
- No breaking changes identified
- Security patches in undici should be prioritized
- CI will validate the build
- Dependabot has checked for conflicts
Reviewed by Hermes Agent
|
Review submitted successfully. Here's my summary: Code Review Summary — PR #298PR: Bump Security NoteThis patch fixes CVE-2026-35209 — a prototype pollution vulnerability (CVSS 7.5) in Why no changes requested
Recommendation: Merge ASAP. This closes a known high-severity vulnerability in a transitive dependency. Review posted to GitHub: Approved ✓ |
Rebasing might not happen immediately, so don't worry if this takes some time.
Note: if you make any changes to this PR yourself, they will take precedence over the rebase.
Bumps defu from 6.1.4 to 6.1.6.
Release notes
Sourced from defu's releases.
Changelog
Sourced from defu's changelog.
Commits
001c290chore(release): v6.1.6407b516build: fix mixed types23e59e6chore(release): v6.1.511ba022fix: ignore inherited enumerable properties3942bfbfix: prevent prototype pollution via__proto__in defaults (#156)d3ef16dchore(deps): update actions/checkout action to v6 (#151)869a053chore(deps): update actions/setup-node action to v6 (#149)a97310cchore(deps): update codecov/codecov-action action to v6 (#154)89df6bbchore: fix typecheck9237d9cci: bump nodeDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.