Skip to content

fix(security): patch undici <=6.26.0 high severity vulnerability#344

Merged
Nuzhy-Deriv merged 1 commit into
deriv-com:masterfrom
Nuzhy-Deriv:nuzhy/vul-fix
Jun 22, 2026
Merged

fix(security): patch undici <=6.26.0 high severity vulnerability#344
Nuzhy-Deriv merged 1 commit into
deriv-com:masterfrom
Nuzhy-Deriv:nuzhy/vul-fix

Conversation

@Nuzhy-Deriv

Copy link
Copy Markdown
Contributor

Adds undici override and postinstall script to replace the vulnerable undici@6.26.0 bundled inside npm's node-gyp with the patched 6.27.0. Updates package-lock.json to reflect the patched version.

Adds undici override and postinstall script to replace the vulnerable
undici@6.26.0 bundled inside npm's node-gyp with the patched 6.27.0.
Updates package-lock.json to reflect the patched version.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@Nuzhy-Deriv Nuzhy-Deriv merged commit cd2d813 into deriv-com:master Jun 22, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant