Skip to content

use patch for high sev incomplete sanitization in undici#143

Closed
Uk1288 wants to merge 1 commit into
mainfrom
fix-for-high-sev-incomplete-sanitization-in-undici
Closed

use patch for high sev incomplete sanitization in undici#143
Uk1288 wants to merge 1 commit into
mainfrom
fix-for-high-sev-incomplete-sanitization-in-undici

Conversation

@Uk1288
Copy link
Copy Markdown
Collaborator

@Uk1288 Uk1288 commented Apr 14, 2026

This is a bit of an extreme action to patch the undici dependency in an attempt to fix the js/incomplete-sanitization issue. The undici is pulled transitively through @actions/http-client.

A better fix is to wait for the fix to get into the @actions/http-client.

@Uk1288 Uk1288 requested a review from a team as a code owner April 14, 2026 07:38
@Uk1288 Uk1288 closed this Apr 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant