Skip to content

chore(cli)!: replace node-fetch with undici - #306

Merged
so0k merged 2 commits into
open-constructs:mainfrom
X-Guardian:chore/replace-node-fetch-with-undici
Jul 10, 2026
Merged

chore(cli)!: replace node-fetch with undici#306
so0k merged 2 commits into
open-constructs:mainfrom
X-Guardian:chore/replace-node-fetch-with-undici

Conversation

@X-Guardian

@X-Guardian X-Guardian commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Description

@cdktn/cli-core depended on the legacy node-fetch package and its proxy helper https-proxy-agent. This PR replaces that with the undici package — a modern, actively maintained fetch implementation with first-class proxy and mocking support — and removes node-fetch, @types/node-fetch, and https-proxy-agent.

Changes

  • Fetch → undici. All three files now import { fetch } from "undici" instead of node-fetch. We use undici's exported fetch rather than the global fetch deliberately: it keeps the whole HTTP stack — code and test mocks — on a single undici instance. globalThis.fetch uses Node's internal undici, which is a different instance from the undici npm package, so mocking has to target the same one the code uses.

  • Proxy → undici ProxyAgent via the dispatcher option. node-fetch's agent option (a Node http.Agent from https-proxy-agent) is replaced by an undici ProxyAgent built from the same http_proxy / HTTP_PROXY env vars and passed as the request dispatcher.

  • Proxy support extended to package-manager.ts. Previously only registry-api.ts and prebuilt-providers.ts honoured a proxy; package-manager.ts (the PyPI / NuGet / Maven Central / GitHub / npm availability probes) never did. It now uses the same dispatcher, so all registry traffic respects a corporate proxy consistently.

  • undici@8.6.0 dependency + Node floor. undici is added to @cdktn/cli-core. undici 8 requires Node ≥ 22.19.0, so both published packages (@cdktn/cli-core and cdktn-cli) declare "engines": { "node": ">=22.19.0" } — surfacing a clear install-time warning on older Node instead of an opaque runtime failure.

  • Tests → undici MockAgent. prebuilt-providers.test.ts and package-manager.test.ts exercise undici's fetch, so their nock scopes are replaced with an undici MockAgent wired via setGlobalDispatcher.

Checklist

  • I have updated the PR title to match CDKTN's style guide
  • I have run the linter on my code locally
  • I have performed a self-review of my code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation if applicable
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works if applicable
  • New and existing unit tests pass locally with my changes

@X-Guardian
X-Guardian marked this pull request as ready for review July 6, 2026 15:08
@X-Guardian
X-Guardian requested a review from a team as a code owner July 6, 2026 15:08
@jsteinich jsteinich changed the title chore(cli): replace node-fetch with undici chore(cli)!: replace node-fetch with undici Jul 7, 2026

@so0k so0k left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, noticed this is flagged as breaking change (due to Node version bump?)

@X-Guardian

Copy link
Copy Markdown
Contributor Author

Shouldn't be a breaking change. The engines.node property only creates a warning on install.

@X-Guardian X-Guardian changed the title chore(cli)!: replace node-fetch with undici chore(cli): replace node-fetch with undici Jul 8, 2026
@jsteinich

Copy link
Copy Markdown
Contributor

Shouldn't be a breaking change. The engines.node property only creates a warning on install.

I had marked as a breaking change due to the part in the PR description: undici 8 requires Node ≥ 22.19.0. If that's accurate, then this does seem like a breaking change as we haven't officially dropped support for Node 20 yet.

I don't really see that as a problem as I expect the next release to come with a major version bump regardless.

@X-Guardian X-Guardian changed the title chore(cli): replace node-fetch with undici chore(cli)!: replace node-fetch with undici Jul 8, 2026
@X-Guardian

Copy link
Copy Markdown
Contributor Author

OK Jon, I've restored the breaking change marker in the PR title.

@so0k

so0k commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

LGTM, added docs PR - see preview environment - merging now

Docs: open-constructs/cdk-terrain-docs#28 — bumps the Node.js prerequisite to 22.19+ in the install and deploy-applications tutorials.
Preview: https://cdkterrain-docs-node-22-19-prereqs.mintlify.app

@X-Guardian
X-Guardian force-pushed the chore/replace-node-fetch-with-undici branch from 1ae4192 to a4b3db7 Compare July 10, 2026 09:59
@sakul-learning

Copy link
Copy Markdown
Contributor

Non-blocking follow-up: undici v8.7.0 is now available and retains the same Node.js >=22.19.0 requirement as the v8.6.0 version introduced here. After this transport migration merges, a small dependency-only update to v8.7.0 would be straightforward.

@so0k
so0k merged commit 1317141 into open-constructs:main Jul 10, 2026
258 checks passed
so0k pushed a commit that referenced this pull request Aug 7, 2026
🤖 Release PR — merge to cut a new release. Kept open and rebased
as commits land on `main`.
---


<details><summary>0.24.0</summary>

##
[0.24.0](v0.23.4...v0.24.0)
(2026-08-06)


### ⚠ BREAKING CHANGES

* **lib:** validate Terraform function versions by default
([#362](#362))
* **deps:** Require Node 22 minimum
([#345](#345))
* **lib:** preserve symlinks in TerraformAsset walkers
([#321](#321))
* **cli:** replace node-fetch with undici
([#306](#306))

### Features

* **lib:** canonical asset hashes behind the canonicalAssetHashes
feature flag
([#323](#323))
([76dd4ff](76dd4ff))
* **lib:** validate Terraform function versions by default
([#362](#362))
([4ac0736](4ac0736))
* support newer provider plugin-protocol features via targetVersions
(RFC-04)
([#296](#296))
([90322f9](90322f9))


### Bug Fixes

* **cli:** don't downgrade prebuilt providers on a transient registry
failure
([#298](#298))
([a960c5c](a960c5c))
* **cli:** include dev dependencies in npm version lookup
([#280](#280))
([955204a](955204a))
* **docs:** fix stale constructs pin breaking with()/IMixin docs
([#305](#305))
([605cf63](605cf63))
* **gha:** Allow pnpm to update the lockfile after package updates
([#318](#318))
([a899b7c](a899b7c))
* **gha:** Fix pnpm upgrade workflow
([#335](#335))
([e1a69fc](e1a69fc))
* **gha:** flip merged release PR label to autorelease: tagged
([#302](#302))
([8d64f6c](8d64f6c))
* **gha:** mint the Go-publish token from the CDKTN Maintainers app
([#369](#369))
([71921ce](71921ce))
* **gha:** mint the Go-publish token from the open-constructs-cdktn App
([#368](#368))
([179f10c](179f10c))
* **gha:** pass the Go-publish App token as x-access-token userinfo
([#370](#370))
([4e3ff19](4e3ff19))
* **lib:** Disallow constructs 10.8 until support can be added
([#363](#363))
([8bdae0d](8bdae0d))
* **lib:** preserve symlinks in TerraformAsset walkers
([#321](#321))
([6360e20](6360e20))
* typo in `moveFromId` JSDoc
([#355](#355))
([e1cf8ce](e1cf8ce))


### Miscellaneous Chores

* **cli:** replace Ink + React with smaller-tree CLI libraries
([#264](#264))
([a6aff7e](a6aff7e))
* **cli:** replace node-fetch with undici
([#306](#306))
([1317141](1317141))
* **deps:** bump glob to 13.0.6
([#307](#307))
([47ee2bb](47ee2bb))
* **deps:** bump the github-actions-backward-compatible group with 2
updates
([#295](#295))
([eab2a01](eab2a01))
* **deps:** replace lerna with nx
([#315](#315))
([94999fc](94999fc))
* **deps:** Require Node 22 minimum
([#345](#345))
([2bf315d](2bf315d))
* **deps:** update ci-info to 4.4.0 across all packages
([#329](#329))
([557a163](557a163))
* **deps:** update fs-extra to 11.3.6 across all packages
([#328](#328))
([95753a9](95753a9))
* **deps:** update minimatch to 10.2.5
([#330](#330))
([d1c1c53](d1c1c53))
* **deps:** Update sscaff to v2.0.388
([#331](#331))
([38ea0ba](38ea0ba))
* **deps:** Update zod to v4.4.3
([#332](#332))
([c10ee35](c10ee35))
* **deps:** Upgrade dependencies
([#347](#347))
([45d3a66](45d3a66))
* remove cdktf from tests
([#277](#277))
([dc9a8e9](dc9a8e9))
* ship Terraform 1.15.8 in the jsii-terraform image
([#367](#367))
([deaa9b0](deaa9b0))
* Upgrade dependencies for lib
([#348](#348))
([d616f17](d616f17))
</details>

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: open-constructs-cdktn[bot] <291052431+open-constructs-cdktn[bot]@users.noreply.github.com>
@github-actions

Copy link
Copy Markdown
Contributor

I'm going to lock this pull request because it has been closed for 30 days. This helps our maintainers find and focus on the active issues. If you've found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Aug 10, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants