Skip to content

Conversation

@chunqilu
Copy link
Contributor

Issue

security scan reports that main and 1.0 branch contains security vulnerabilities in undici which is used by @vscode/proxy-agent, we need to mitigate this risk.

Description of Changes

this change update @vscode/proxy-agent from 0.32.0 to 0.37.0 which uses undici 7.18.2 in https://github.com/microsoft/vscode-proxy-agent/blob/main/package-lock.json.

Testing

Screenshots/Videos

Additional Notes

Backporting


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@chunqilu chunqilu requested a review from a team as a code owner January 26, 2026 15:24
@chunqilu chunqilu merged commit 7b92da7 into main Jan 26, 2026
3 checks passed
@chunqilu chunqilu deleted the update-vscode-proxy-agent branch January 26, 2026 15:40
feiyangliu2023 pushed a commit that referenced this pull request Jan 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants