Skip to content

chore(deps): upgrade undici to 7.29.0 - #3315

Merged
NathanColosimo merged 2 commits into
mainfrom
pgp/bump-undici-7.29.0
Aug 4, 2026
Merged

chore(deps): upgrade undici to 7.29.0#3315
NathanColosimo merged 2 commits into
mainfrom
pgp/bump-undici-7.29.0

Conversation

@pranaygp

Copy link
Copy Markdown
Contributor

Upgrades undici from 7.28.0 to 7.29.0 in the workspace catalog, consumed by @workflow/world-local and @workflow/world-vercel.

  • Unit tests pass for both packages (world-local 508, world-vercel 334)
  • Changeset included (patch bump for both packages)

🤖 Generated with Claude Code

@pranaygp
pranaygp requested a review from a team as a code ownerAugust 4, 2026 01:25
CopilotAI review requested due to automatic review settings August 4, 2026 01:25
@changeset-bot

changeset-botBot commented Aug 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e50aac8

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 19 packages
NameType
@workflow/world-localPatch
@workflow/world-vercelPatch
@workflow/cliPatch
@workflow/corePatch
@workflow/vitestPatch
@workflow/webPatch
@workflow/world-postgresPatch
workflowPatch
@workflow/world-testingPatch
@workflow/buildersPatch
@workflow/nextPatch
@workflow/nitroPatch
@workflow/web-sharedPatch
@workflow/astroPatch
@workflow/nestPatch
@workflow/rollupPatch
@workflow/sveltekitPatch
@workflow/vitePatch
@workflow/nuxtPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

📊 Workflow Benchmarks

commit e50aac8 · Tue, 04 Aug 2026 21:26:34 GMT · run logs

Backend: vercel · app: nextjs-turbopack

MetricScenarioBest (ms)P75 (ms)P90 (ms)P99 (ms)Samples
TTFSstep1315 (+514%) 🔻1399 🔴 (+17%) 🔻1451 🔴 (+18%) 🔻1498 🔴 (-8.4%)30
TTFSstream366 (+49%) 🔻1486 🔴 (+39%) 🔻1588 🔴 (+45%) 🔻3675 🔴 (+221%) 🔻30
TTFShook + stream1429 (+276%) 🔻1759 🔴 (+33%) 🔻1816 🔴 (+32%) 🔻6758 🔴 (+362%) 🔻30
STSO1020 steps (inline)140 (+40%) 🔻171 (+6.9%)191 (-1.5%)288 (-34%) 💚1018
STSO1020 steps (queue-hop)3150 (+6.1%)3150 (+6.1%)3150 (+6.1%)3150 (+6.1%)1
WO1020 steps174368 (+2.4%)174368 (+2.4%)174368 (+2.4%)174368 (+2.4%)1
SLstream latency121 (+25%) 🔻200 🔴 (+34%) 🔻225 🔴 (+0.9%)317 🔴 (-58%) 💚30
SOstream overhead (text)141 (+18%) 🔻205 (-21%) 💚221 (-62%) 💚635 (-21%) 💚30
SOstream overhead (structured)160 (+37%) 🔻223 (-28%) 💚233 (-59%) 💚236 (-73%) 💚30
📈 STSO distribution vs main (inline / queue-hop histograms)

1020 steps (inline)

Cumulative STSO time: main 166837ms → this run 169813ms (Δ +2976ms, +2%)

 100-150 ms ███┃██████████████ main 624 this 123 -501
150-200 ms █████████░░░░░░░░░░░░░░┃ main 302 this 829 +527
200-250 ms ┃ main 48 this 50 +2
250-300 ms ┃ main 13 this 7 -6
300-350 ms ┃ main 12 this 2 -10
350-400 ms ┃ main 6 this 3 -3
400-450 ms ┃ main 3 this 4 +1
500-550 ms ┃ main 2 this 0 -2
550-600 ms ┃ main 3 this 0 -3
650-700 ms ┃ main 1 this 0 -1
850-900 ms ┃ main 1 this 0 -1
2150-2200 ms ┃ main 1 this 0 -1
3300-3350 ms ┃ main 1 this 0 -1
3800-3850 ms ┃ main 1 this 0 -1

1020 steps (queue-hop)

Cumulative STSO time: main 2968ms → this run 3150ms (Δ +182ms, +6%)

2500-3000 ms ┃███████████████████████ main 1 this 0 -1
3000-3500 ms ░░░░░░░░░░░░░░░░░░░░░░░┃ main 0 this 1 +1
📜 Previous results (1)

0d41ea1

Tue, 04 Aug 2026 01:44:31 GMT · run logs

vercel / nextjs-turbopack

MetricScenarioBest (ms)P75 (ms)P90 (ms)P99 (ms)Samples
TTFSstep219 (-79%) 💚1350 🔴 (+20%) 🔻1410 🔴 (+24%) 🔻1959 🔴 (+35%) 🔻30
TTFSstream259 (+12%)1356 🔴 (+25%) 🔻1399 🔴 (+26%) 🔻1489 🔴 (+17%) 🔻30
TTFShook + stream393 (-20%) 💚1554 🔴 (+12%)1567 🔴 (+8.9%)1653 🔴 (-7.4%)30
STSO1020 steps (inline)94 (-4.1%)133 (-13%)151 (-17%) 💚272 (-7.8%)1018
STSO1020 steps (queue-hop)2389 (-16%) 💚2389 (-16%) 💚2389 (-16%) 💚2389 (-16%) 💚1
WO1020 steps134768 (-9.4%)134768 (-9.4%)134768 (-9.4%)134768 (-9.4%)1
SLstream latency117 (+6.4%)152 🔴 (-22%) 💚174 🔴 (-39%) 💚222 🔴 (-43%) 💚30
SOstream overhead (text)120 (-2.4%)231 (+7.4%)503 🔴 (+104%) 🔻797 (+175%) 🔻30
SOstream overhead (structured)123 (+6.0%)227 (+16%) 🔻428 (+82%) 🔻807 (+133%) 🔻30
ℹ️ Metric definitions & methodology

The collapsed STSO distribution section above buckets every step gap of the sequential-steps run (not a sampled window), split by whether the step ending the gap ran inline — in the same warm process as the step before it, so the gap is pure framework overhead — or after a queue-hop — the first step of a fresh process, which pays queue dispatch, client reinit and event-log replay. Bars overlay the two runs: is main, marks where this run lands, bridges the gap when this run has more samples in a bucket.

Best/P75/P90/P99 deltas compare against the most recent benchmark run on main at the time of this run. 🔻 flags a delta worse than +15%, 💚 one better than −15%.

Metrics — TTFS: time to first step body (in-deployment start() → first step body, deployment clocks) · STSO: step-to-step overhead (gap between consecutive step bodies) · WO: workflow overhead (whole-run time outside step bodies, in-deployment anchored) · SL: stream latency (in-deployment write → read propagation, readAt - writtenAt) · SO: stream overhead (end-to-end write+consume time beyond the modelled generation window)

Scenarios — step: one trivial no-op step, no stream; no hooks, so the run stays in turbo mode (in-process fast path) · stream: one streaming step; no hooks, so the run stays in turbo mode (in-process fast path) · hook + stream: registers a hook before one step, which exits turbo mode (dispatch path) · 1020 steps: 1020 trivial sequential steps; STSO is measured between consecutive steps in the given step ranges, and WO is the whole-run overhead outside step bodies · stream latency: parallel reader/writer steps on a dedicated stream; SL is the in-deployment write->read propagation (readAt - writtenAt) · stream overhead (text): writer streams 300 variable-length text token deltas paced at 100/s for 3s (a haiku-size LLM's token throughput) while a parallel reader drains the whole stream; SO is the end-to-end write+consume time beyond the 3s generation window (overhead/backpressure) · stream overhead (structured): same workload as stream overhead (text), but each delta is an AI-SDK-style structured object ({ type: 'text-delta', id, text }) instead of a raw string, so the SO gap vs the text scenario is the added serialization cost

🔴 marks a percentile over its target (within target is left unmarked). Targets (p75/p90/p99, ms) — TTFS 200/300/600 · SL 50/60/125 · SO 250/500/1000

All metrics are measured from deployment-side timestamps only. Runs are triggered by an in-deployment route that stamps the anchor (clientStart) right before start(), so the CI runner’s request and its path through api.vercel.com sit outside every measured window. TTFS = in-deployment start() → first step body (turbo uses the in-process fast path, non-turbo the dispatch path), and includes the VQS dispatch hop plus any /flow cold start. STSO/WO are measured between step bodies on the deployment. SL is measured inside the workflow (parallel reader/writer steps), so it no longer includes the api.vercel.com read path.

Cold starts are kept in the numbers on purpose — they are part of real bursty-workload latency. The workbench deployment cold-starts the /flow invocation for a large fraction of runs, inflating P75+; the Best column shows the fastest (warm-start) sample for comparison.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Pranay Prakash <pranay.gp@gmail.com>
@github-actions

github-actionsBot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

🧪 E2E Test Results

All tests passed

E2E Test Summary

Summary
PassedFailedSkippedTotal
✅ ▲ Vercel Production293205003432
✅ 💻 Local Development329004543744
✅ 📦 Local Production329004543744
✅ 🐘 Local Postgres329004543744
✅ 🪟 Windows31200312
✅ 📋 Other206804282496
✅ vercel-multi-region270027
Total152090229017499
Details by Category

✅ ▲ Vercel Production

AppPassedFailedSkipped
✅ astro-node127029
✅ astro-quickjs127029
✅ example-node127029
✅ example-quickjs127029
✅ express-node127029
✅ express-quickjs127029
✅ fastify-node127029
✅ fastify-quickjs127029
✅ hono-node127029
✅ hono-quickjs127029
✅ nextjs-turbopack-node15204
✅ nextjs-turbopack-quickjs15204
✅ nextjs-webpack-node15204
✅ nextjs-webpack-quickjs15204
✅ nitro-node127029
✅ nitro-quickjs127029
✅ nuxt-node127029
✅ nuxt-quickjs127029
✅ sveltekit-node146010
✅ sveltekit-quickjs146010
✅ vite-node127029
✅ vite-quickjs127029

✅ 💻 Local Development

AppPassedFailedSkipped
✅ astro-stable-node130026
✅ astro-stable-quickjs130026
✅ express-stable-node130026
✅ express-stable-quickjs130026
✅ fastify-stable-node130026
✅ fastify-stable-quickjs130026
✅ hono-stable-node130026
✅ hono-stable-quickjs130026
✅ nextjs-turbopack-canary-node137019
✅ nextjs-turbopack-canary-quickjs137019
✅ nextjs-turbopack-stable-node15600
✅ nextjs-turbopack-stable-quickjs15600
✅ nextjs-webpack-canary-node137019
✅ nextjs-webpack-canary-quickjs137019
✅ nextjs-webpack-stable-node15600
✅ nextjs-webpack-stable-quickjs15600
✅ nitro-stable-node130026
✅ nitro-stable-quickjs130026
✅ nuxt-stable-node130026
✅ nuxt-stable-quickjs130026
✅ sveltekit-stable-node14907
✅ sveltekit-stable-quickjs14907
✅ vite-stable-node130026
✅ vite-stable-quickjs130026

✅ 📦 Local Production

AppPassedFailedSkipped
✅ astro-stable-node130026
✅ astro-stable-quickjs130026
✅ express-stable-node130026
✅ express-stable-quickjs130026
✅ fastify-stable-node130026
✅ fastify-stable-quickjs130026
✅ hono-stable-node130026
✅ hono-stable-quickjs130026
✅ nextjs-turbopack-canary-node137019
✅ nextjs-turbopack-canary-quickjs137019
✅ nextjs-turbopack-stable-node15600
✅ nextjs-turbopack-stable-quickjs15600
✅ nextjs-webpack-canary-node137019
✅ nextjs-webpack-canary-quickjs137019
✅ nextjs-webpack-stable-node15600
✅ nextjs-webpack-stable-quickjs15600
✅ nitro-stable-node130026
✅ nitro-stable-quickjs130026
✅ nuxt-stable-node130026
✅ nuxt-stable-quickjs130026
✅ sveltekit-stable-node14907
✅ sveltekit-stable-quickjs14907
✅ vite-stable-node130026
✅ vite-stable-quickjs130026

✅ 🐘 Local Postgres

AppPassedFailedSkipped
✅ astro-stable-node130026
✅ astro-stable-quickjs130026
✅ express-stable-node130026
✅ express-stable-quickjs130026
✅ fastify-stable-node130026
✅ fastify-stable-quickjs130026
✅ hono-stable-node130026
✅ hono-stable-quickjs130026
✅ nextjs-turbopack-canary-node137019
✅ nextjs-turbopack-canary-quickjs137019
✅ nextjs-turbopack-stable-node15600
✅ nextjs-turbopack-stable-quickjs15600
✅ nextjs-webpack-canary-node137019
✅ nextjs-webpack-canary-quickjs137019
✅ nextjs-webpack-stable-node15600
✅ nextjs-webpack-stable-quickjs15600
✅ nitro-stable-node130026
✅ nitro-stable-quickjs130026
✅ nuxt-stable-node130026
✅ nuxt-stable-quickjs130026
✅ sveltekit-stable-node14907
✅ sveltekit-stable-quickjs14907
✅ vite-stable-node130026
✅ vite-stable-quickjs130026

✅ 🪟 Windows

AppPassedFailedSkipped
✅ nextjs-turbopack-node15600
✅ nextjs-turbopack-quickjs15600

✅ 📋 Other

AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable-node130026
✅ e2e-local-dev-nest-stable-quickjs130026
✅ e2e-local-dev-tanstack-start-node130026
✅ e2e-local-dev-tanstack-start-quickjs130026
✅ e2e-local-postgres-nest-stable-node130026
✅ e2e-local-postgres-nest-stable-quickjs130026
✅ e2e-local-postgres-tanstack-start-node130026
✅ e2e-local-postgres-tanstack-start-quickjs130026
✅ e2e-local-prod-nest-stable-node130026
✅ e2e-local-prod-nest-stable-quickjs130026
✅ e2e-local-prod-tanstack-start-node130026
✅ e2e-local-prod-tanstack-start-quickjs130026
✅ e2e-vercel-prod-nest-node127029
✅ e2e-vercel-prod-nest-quickjs127029
✅ e2e-vercel-prod-tanstack-start-node127029
✅ e2e-vercel-prod-tanstack-start-quickjs127029

✅ vercel-multi-region

AppPassedFailedSkipped
✅ nextjs-turbopack2700

📋 View full workflow run

@socket-security

socket-securityBot commented Aug 4, 2026

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Addednpm/​undici@​7.29.09310010098100

View full report

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the workspace catalog to use undici@7.29.0, updating the resolved dependency for the packages that consume undici via catalog: (notably @workflow/world-local and @workflow/world-vercel), and records the change with a changeset.

Changes:

  • Bump the workspace catalog entry for undici from 7.28.0 to 7.29.0.
  • Regenerate pnpm-lock.yaml to reflect the new catalog resolution (including importer versions).
  • Add a changeset to publish patch releases of @workflow/world-local and @workflow/world-vercel.

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated no comments.

FileDescription
pnpm-workspace.yamlUpdates the workspace dependency catalog to undici: 7.29.0.
pnpm-lock.yamlUpdates the lockfile catalog/importer resolutions and adds undici@7.29.0 metadata.
.changeset/bump-undici-7-29-0.mdRecords a patch-level release for the affected packages.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Signed-off-by: Nathan Colosimo <110621881+NathanColosimo@users.noreply.github.com>

@VaguelySeriousVaguelySerious left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM assuming checks pass

@NathanColosimo
NathanColosimo enabled auto-merge (squash) August 4, 2026 21:10
@NathanColosimo
NathanColosimo merged commit 1222aab into mainAug 4, 2026
416 of 421 checks passed
@NathanColosimo
NathanColosimo deleted the pgp/bump-undici-7.29.0 branch August 4, 2026 21:59
@github-actions

Copy link
Copy Markdown
Contributor

No backport to stable for 1222aab (AI decision).

This is a routine patch-level dependency bump of undici (7.28.0 → 7.29.0) in the workspace catalog, with no mention of a security vulnerability or a bug that affects stable. The commit only touches a changeset, pnpm-lock.yaml, and pnpm-workspace.yaml, and nothing indicates it keeps the maintenance line working correctly.

To override, re-run the Backport to stable workflow manually via workflow_dispatch and paste this commit SHA into the ref input:

1222aab74da39b4a7ae93e6c5ecc2dc4707b68d0

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@pranaygp@VaguelySerious@NathanColosimo