Security: transitive undici@5.29.0 vulnerabilities via @github/local-action@7.0.1
- 主要言語
- TypeScript
- スター
- 451
- フォーク
- 28
- PR マージ指標
- 30日以内にマージされた PR はありません
説明
## Summary
`@github/local-action@7.0.1` pulls in a vulnerable `undici@5.29.0` through several `@actions/*` dependencies. Snyk reports **10 transitive issues** (Risk Score MAX **170**), of which **9 have no supported fix** in the current dependency tree (0 fixable via a direct bump).
All high-severity findings trace back to a single package: **`undici@5.29.0`**.
## Affected package
- **Direct dependency:** `@github/local-action@7.0.1`
- **Vulnerable transitive package:** `undici@5.29.0`
- **Fixed in:** `undici@6.24.0`, `undici@7.24.0`
## Vulnerabilities
| Issue | CWE | CVE | CVSS | Snyk ID |
|-------|-----|-----|------|---------|
| Uncaught Exception | [CWE-248](https://cwe.mitre.org/data/definitions/248.html) | CVE-2026-2229 | 8.7 (High) | SNYK-JS-UNDICI-15518070 |
| CRLF Injection | [CWE-93](https://cwe.mitre.org/data/definitions/93.html) | — | 9.2 (Critical) | — |
| Permissive List of Allowed Inputs | [CWE-183](https://cwe.mitre.org/data/definitions/183.html) | — | 8.3 (High) | — |
コントリビューションガイド
調査の方向性
まずリポジトリの依存関係マニフェストと lockfile を調査し、@github/local-action@7.0.1 がどのように undici@5.29.0 を取り込んでいるかを追跡します。利用可能な依存関係の更新またはその他のサポートされている解決方法によって報告された脆弱性が解消されるかを確認し、その後、プロジェクトの依存関係セキュリティスキャンを再実行して、検出結果が対処済みであることを確認します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- typescript
- 領域
- devops, security
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 45/100