fix(deps): undici WebSocket DoS 보안 패치를 적용한다 - #18
Merged
Merged
Conversation
PR #16의 CI 변경과 분리해 undici 잠금 버전만 6.28.0에서 6.28.1로 갱신한다. GHSA-rfgv-xxqx-mfg5의 비정상 WebSocket handshake에 의한 프로세스 종료를 수정한다.
OstenHun
marked this pull request as ready for review
October 1, 2026 17:17
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
2026-10-01 병합 결과
이 보안 PR은
develop에 병합됐습니다. 병합 커밋은6766db7a554f41a760ae68d6a82a16877baf672d이며, undici 6.28.1을 확인했습니다.병합 후 develop CI에서 테스트 75개, typecheck, build 모두 통과했고 설치 감사도 취약점 0건입니다. PR #16은 이 develop을 동기화한 뒤 Node.js 22/24 CI 정렬을 별도로 진행합니다. 운영 배포는 수행하지 않았습니다.
아래는 분리 당시의 변경 범위와 검증 기록입니다.
요약
PR #16에서 보안 의존성 변경을 분리합니다.
develop@3834a38기준으로package-lock.json의 undici만6.28.0 → 6.28.1로 갱신합니다. 버전, tarball URL, integrity의 3줄만 변경하며 CI 설정과 제품 코드는 변경하지 않습니다.[Critical Review]
Gate Status: ready_for_verification
ws를 사용합니다. npm undici의 결함은 로컬에서 재현했지만, AMDC 기본 경로의 원격 공격 가능성이 확인됐다는 뜻은 아닙니다.discord.js와@discordjs/rest는 모두 undici^6.27.0을 허용하므로 6.28.1은 기존 범위에 들어갑니다. Node 요구사항>=18.17도 동일합니다.[Trade-off Analysis]
[Actionable Next Step]
검증
분리된 최종 트리
1e321ad를 클라우드 Linux / Node.js 24.19.0에서 검증했습니다.npm ci: 통과npm test: 75개 통과, 실패·건너뜀 0npm run typecheck,npm run build,git diff --check: 통과npm audit --json: 취약점 0건48f9b22a8bbabdca56bee44665a196abcd9f8a06의 설치, 테스트 75개, typecheck, build 모두 통과. CI 설치 감사도 0건develop@3834a38과 GitHub 생성 merge ref3fe95bd의 트리가 head와 동일한1e321ad임을 별도 확인했습니다. merge-ref checkout 변경은 #16이 담당합니다.분리와 병합 순서
이 PR은
develop에서 직접 분기해 보안 패치만 포함합니다. PR #16에서는 되돌림 커밋으로 같은 의존성 변경을 제거해 기존 충돌 해결 이력을 보존합니다.권장 순서는 이 보안 PR을 먼저 검토·병합한 뒤 PR #16을 최신
develop에 동기화해 CI를 재확인하는 것입니다. 보안 PR이 병합되기 전 CI 전용 #16에는 현재 develop의 undici 6.28.0 감사 경고가 남습니다. 두 PR을 분리하는 작업은 병합이나 배포를 포함하지 않습니다.검증은 현재 코드와 가짜 입력에 한정합니다. 실제 Discord/AMDB/OpenAI 호출, 운영 배포, Windows·Docker 실행 검증은 수행하지 않았습니다.