Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump ws from 8.14.2 to 8.17.1 #1835

Merged
merged 1 commit into from
Jul 17, 2024
Merged

Bump ws from 8.14.2 to 8.17.1 #1835

merged 1 commit into from
Jul 17, 2024

Conversation

mattvot
Copy link
Contributor

@mattvot mattvot commented Jul 17, 2024

What

A clone of a change Dependabot made but is failing to rebase. This deals with a "ws affected by a DoS when handling a request with many HTTP headers" security vulnerability.

Bumps ws from 8.14.2 to 8.17.1.


updated-dependencies:

  • dependency-name: ws dependency-type: indirect ...

How to review

  1. See changes match the Dependabot change Bump ws from 8.14.2 to 8.17.1 #1693

Related PRs

#1693

Taken from a Dependabot PR that failed to rebase.

Bumps [ws](https://github.com/websockets/ws) from 8.14.2 to 8.17.1.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/[email protected])

---
updated-dependencies:
- dependency-name: ws
  dependency-type: indirect
...
@mattvot mattvot marked this pull request as ready for review July 17, 2024 11:06
@mattvot mattvot requested review from a team as code owners July 17, 2024 11:06
Copy link

@mattvot mattvot merged commit 1976181 into main Jul 17, 2024
7 checks passed
@mattvot mattvot deleted the bau/update-ws branch July 17, 2024 11:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants