Skip to content

@azure/functions v4.8.0 package brings vulnerable undici transitive dependency (v5.29.0) #367

@himanshu-zversal

Description

@himanshu-zversal

Hello team,

While reviewing dependencies of the @azure/functions npm package v4.8.0, I noticed that it brings in [email protected] as a transitive dependency.
This version of undici has known security vulnerabilities:

GHSA-c76h-2ccp-4975

GHSA-3g92-w8c5-73pq

Details:

Package: @azure/[email protected]

Vulnerable dependency: [email protected]

Impact: Projects consuming @azure/functions inherit the vulnerable undici version.

Expected:
@azure/functions should update its dependency chain to pull in a latest version of undici (7.16.0).

Could you please review and update the dependency to mitigate this security issue?

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions