Skip to content

[v7.x] drop: remove Node.js 26 from shared-builtin CI build - #5592

Merged
mcollina merged 1 commit into
nodejs:v7.xfrom
mcollina:drop-v26-shared-builtin
Jul 25, 2026
Merged

mcollina merged 1 commit into
nodejs:v7.xfrom
mcollina:drop-v26-shared-builtin

Conversation

@mcollina

Copy link
Copy Markdown
Member

Node.js 26 has diverged from undici's v7.x branch, making the shared-builtin compilation and Node.js core test run unreliable. Remove v26 from the test-shared-builtin matrix while keeping it in the regular test matrix (CI and WASM SIMD tests).

Node.js 26 has diverged from undici's v7.x branch, making the
shared-builtin compilation and Node.js core test run unreliable.
Remove v26 from the test-shared-builtin matrix while keeping it
in the regular test matrix (CI and WASM SIMD tests).
@mcollina
mcollina requested review from ronag and trivikr July 24, 2026 12:56
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.15%. Comparing base (f9eba0a) to head (d6d5aa1).
⚠️ Report is 9 commits behind head on v7.x.

Additional details and impacted files
@@            Coverage Diff             @@
##             v7.x    #5592      +/-   ##
==========================================
+ Coverage   93.09%   93.15%   +0.05%     
==========================================
  Files         112      112              
  Lines       36018    36751     +733     
==========================================
+ Hits        33531    34235     +704     
- Misses       2487     2516      +29     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mcollina
mcollina requested a review from metcoder95 July 24, 2026 13:26
@mcollina
mcollina merged commit 8d347dd into nodejs:v7.x Jul 25, 2026
65 of 68 checks passed
@github-actions github-actions Bot mentioned this pull request Sep 4, 2026
meta-codesync Bot pushed a commit to facebook/memlab that referenced this pull request Sep 29, 2026
Summary:
Bumps [[ https://github.com/nodejs/undici | undici ]] from 7.29.0 to 7.30.0 in the memlab `website/` workspace. `yarn.lock` change only; it also picks up the 7.29.1 security release.

**v7.30.0**
- fix: selectively re-enable SIMD for ppc64 ([[ nodejs/undici#5794 | #5794 ]])
- Backport upgrade diagnostics lifecycle fixes ([[ nodejs/undici#5783 | #5783 ]])
- fix: honor backpressure in the decompression interceptor ([[ nodejs/undici#5837 | #5837 ]])
- fix: close rejected HTTP/2 WebSocket streams ([[ nodejs/undici#5876 | #5876 ]])
- test(fetch): make pull-dont-push exceed any socket buffer ([[ nodejs/undici#5889 | #5889 ]])

**v7.29.1 — security fixes**

High severity:
- [[ GHSA-w293-vg96-wgc3 | GHSA-w293-vg96-wgc3 ]]: `BalancedPool` could drop function-valued connection options, including custom TLS certificate validation callbacks, when cloning its configuration
- [[ GHSA-rfgv-xxqx-mfg5 | GHSA-rfgv-xxqx-mfg5 ]]: a WebSocket server selecting a subprotocol when none was requested caused an uncaught `TypeError` that could terminate the process

Medium severity:
- [[ GHSA-3wwx-pv8p-q78v | GHSA-3wwx-pv8p-q78v ]]: a permessage-deflate payload over the decompression limit could emit an unhandled zlib error and terminate the process
- [[ GHSA-rx4f-c7p8-82vq | GHSA-rx4f-c7p8-82vq ]]: an unclean `WebSocketStream` close with a locked writable stream could create an unobserved rejected promise
- [[ GHSA-2jfj-6hjv-fm6j | GHSA-2jfj-6hjv-fm6j ]]: shared caches could store and replay responses containing `Set-Cookie`, disclosing one user's cookies to another caller
- [[ GHSA-3xpg-4rpp-hhhm | GHSA-3xpg-4rpp-hhhm ]]: the decompression interceptor did not bound decoded output; every stage is now limited to 64 MiB by default, configurable via `maxSize`
- [[ GHSA-pmjh-fq2x-6v4x | GHSA-pmjh-fq2x-6v4x ]]: a terminal retry failure after response headers were exposed could orphan the response body and hang consumers

Low severity:
- [[ GHSA-8436-99hf-9mmv | GHSA-8436-99hf-9mmv ]]: cache interceptors could store and replay responses to unsafe methods such as `POST` or `DELETE`
- [[ GHSA-2gqq-gqf2-x968 | GHSA-2gqq-gqf2-x968 ]]: the dump interceptor could treat an oversized chunked response without `Content-Length` as successfully truncated
- [[ GHSA-r53p-7pc4-xj5r | GHSA-r53p-7pc4-xj5r ]]: the retry interceptor could concatenate a resumed response with inconsistent framing, enabling response splitting or corruption

**v7.29.1 — other changes**
- fix(h2): honour `headersTimeout` ([[ nodejs/undici#5604 | #5604 ]])
- fix(h2): keep the connection ref'd while requests are outstanding ([[ nodejs/undici#5605 | #5605 ]])
- fix(h2): retire the request that completed, not the head of the queue ([[ nodejs/undici#5618 | #5618 ]])
- fix(h2): settle a request whose stream is cancelled ([[ nodejs/undici#5607 | #5607 ]])
- fix(h2): handle GOAWAY for CONNECT streams ([[ nodejs/undici#5640 | #5640 ]])
- perf: reduce `EventSourceStream` parser allocations ([[ nodejs/undici#5646 | #5646 ]])
- perf(h1): drop the idle-socket timer floor with a ref'd `setImmediate` ([[ nodejs/undici#5769 | #5769 ]])
- CI only: drop Node.js 26 from the shared-builtin build ([[ nodejs/undici#5592 | #5592 ]]); raise the Windows workflow timeout ([[ nodejs/undici#5621 | #5621 ]])

Full changelog: [[ nodejs/undici@v7.29.0...v7.30.0 | v7.29.0...v7.30.0 ]]

Opened by Dependabot. Comment `dependabot rebase` on the GitHub PR to resolve conflicts; do not hand-edit the PR branch.

Pull Request resolved: #155

Differential Revision: D122269178

Pulled By: JacksonGL

fbshipit-source-id: 56fb568c08248253c483c6b44b1175af4a6b6d0c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants