Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency ws to v1.1.5 - autoclosed #9

Closed

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Jul 5, 2022

This PR contains the following updates:

Package Type Update Change
ws dependencies patch 1.1.1 -> 1.1.5

By merging this PR, the issue #8 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 7.5 WS-2017-0421
High High 7.4 WS-2017-0107

Release Notes

websockets/ws (ws)

v1.1.5

Compare Source

Bug fixes

  • Fixed a DoS vulnerability (f8fdcd4).

v1.1.4

Compare Source

Notable changes

  • Removed istanbul coverage folder from npm package (fac50ac).

v1.1.3

Compare Source

Notable changes

  • Added support for bufferutil@>1 and utf-8-validate@>2 (b4cf110).

v1.1.2

Compare Source

Bug fixes

  • The masking key is now generated using crypto.randomBytes() instead of
    Math.random() (#​994).
  • Fixed an issue that could cause a stack overflow crash (c1f3b21).

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Jul 5, 2022
@mend-for-github-com mend-for-github-com bot changed the title Update dependency ws to v1.1.5 Update dependency ws to v1.1.2 Nov 20, 2022
@mend-for-github-com mend-for-github-com bot changed the title Update dependency ws to v1.1.2 Update dependency ws to v1.1.5 Mar 26, 2023
@mend-for-github-com mend-for-github-com bot changed the title Update dependency ws to v1.1.5 Update dependency ws to v1.1.5 - autoclosed Nov 13, 2024
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/ws-1.x-lockfile branch November 13, 2024 07:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants