Skip to content

chore(deps): Bump ws from 8.21.0 to 8.21.1 - #65

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ws-8.21.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ws-8.21.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 17, 2026

Copy link
Copy Markdown

Bumps ws from 8.21.0 to 8.21.1.

Release notes

Sourced from ws's releases.

8.21.1

Bug fixes

  • Empty fragments are now counted toward the limit (a2f4e7c0).
  • The default values of the maxBufferedChunks and maxFragments options have been reduced (f197ac65).
Commits
  • ae1de54 [dist] 8.21.1
  • 8e9511b [ci] Trust Coveralls Homebrew tap
  • f197ac6 [fix] Lower default values of maxBufferedChunks and maxFragments
  • 8df8265 [ci] Update actions/checkout action to v7
  • a2f4e7c [fix] Count empty fragments toward the limit (#2329)
  • e79f912 [pkg] Approve install scripts for bufferutil and utf-8-validate
  • 4ea355d [doc] Document 32-bit signed integer coercion for option values
  • 2120f4c [example] Remove uuid dependency
  • 4c534a6 [security] Add latest vulnerability to SECURITY.md
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ws](https://github.com/websockets/ws) from 8.21.0 to 8.21.1.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.0...8.21.1)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.21.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Jul 17, 2026
@dependabot
dependabot Bot requested a review from bobbyjohnstx as a code owner July 17, 2026 11:26
@dependabot dependabot Bot added dependencies javascript Pull requests that update javascript code labels Jul 17, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Dependency Audit Failed

�[0m�[1mbun audit �[0m�[2mv1.3.14 (0d9b296a)�[0m
vite  >=7.1.0 <=7.1.4
  workspace:@tinycode/app › vite
  workspace:@tinycode/desktop › vite
  workspace:@tinycode/ui › vite
  workspace:@tinycode/app › @tailwindcss/vite
  workspace:@tinycode/desktop › electron-vite
  workspace:@tinycode/app › vite-plugin-icons-spritesheet
  workspace:@tinycode/app › vite-plugin-solid
  low: Vite middleware may serve files starting with the same name with the public directory - https://github.com/advisories/GHSA-g4jq-h2w9-997c
  low: Vite's `server.fs` settings were not applied to HTML files - https://github.com/advisories/GHSA-jqfw-vq24-v9c3
  moderate: vite allows server.fs.deny bypass via backslash on Windows - https://github.com/advisories/GHSA-93m4-6634-74q7
  moderate: launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows - https://github.com/advisories/GHSA-v6wh-96g9-6wx3
  moderate: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling - https://github.com/advisories/GHSA-4w7w-66w2-5vf9
  high: Vite: `server.fs.deny` bypassed with queries - https://github.com/advisories/GHSA-v2wj-q39q-566r
  high: Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket - https://github.com/advisories/GHSA-p9ff-h696-f583
  high: vite: `server.fs.deny` bypass on Windows alternate paths - https://github.com/advisories/GHSA-fx2h-pf6j-xcff

uuid  <11.1.1
  workspace:@tinycode/app › effect
  workspace:@tinycode/desktop › @actions/artifact
  moderate: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided - https://github.com/advisories/GHSA-w5hq-g745-h8pq

undici  <6.23.0
  workspace:tinycode › @actions/github
  workspace:@tinycode/http-recorder › @effect/platform-node
  workspace:@tinycode/desktop › @actions/artifact
  workspace:tinycode › @actions/core
  workspace:@tinycode/desktop › electron
  workspace:@tinycode/desktop › electron-builder
  workspace:tinycode › @npmcli/arborist
  moderate: Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion - https://github.com/advisories/GHSA-g9mf-h72j-4rw9
  moderate: Undici has an HTTP Request/Response Smuggling issue - https://github.com/advisories/GHSA-2mjp-6q6p-2qxm
  high: Undici has Unbounded Memory Consumption in WebSocket permessage-deflate Decompression - https://github.com/advisories/GHSA-vrm6-8vpv-qv8q
  high: Undici has Unhandled Exception in WebSocket Client Due to Invalid server_max_window_bits Validation - https://github.com/advisories/GHSA-v9p9-hfj2-hcw8
  moderate: Undici has CRLF Injection in undici via `upgrade` option - https://github.com/advisories/GHSA-4992-7rv2-5pvq
  high: undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent - https://github.com/advisories/GHSA-vmh5-mc38-953g
  high: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass - https://github.com/advisories/GHSA-38rv-x7px-6hhq
  moderate: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding - https://github.com/advisories/GHSA-p88m-4jfj-68fv
  moderate: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding - https://github.com/advisories/GHSA-p88m-4jfj-68fv
  high: undici WebSocket client vulnerable to denial of service via fragment count bypass - https://github.com/advisories/GHSA-vxpw-j846-p89q
  high: undici WebSocket client vulnerable to denial of service via fragment count bypass - https://github.com/advisories/GHSA-vxpw-j846-p89q
  low: undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse - https://github.com/advisories/GHSA-35p6-xmwp-9g52
  low: undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse - https://github.com/advisories/GHSA-35p6-xmwp-9g52
  low: undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching - https://github.com/advisories/GHSA-g8m3-5g58-fq7m
  low: undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching - https://github.com/advisories/GHSA-g8m3-5g58-fq7m
  moderate: undici vulnerable to cross-user information disclosure via shared cache whitespace bypass - https://github.com/advisories/GHSA-pr7r-676h-xcf6

form-data  >=4.0.0 <4.0.6
  workspace:@tinycode/desktop › @actions/artifact
  workspace:@tinycode/desktop › electron-builder
  workspace:tinycode › @types/npmcli__arborist
  high: form-data: CRLF injection in form-data via unescaped multipart field names and filenames - https://github.com/advisories/GHSA-hmw2-7cc7-3qxx

minimatch  >=10.0.0 <10.2.1
  (direct dependency)
  workspace:tinycode › minimatch
  workspace:tinycode › @npmcli/arborist
  workspace:tinycode › glob
  workspace:tinycode › @npmcli/config
  workspace:@tinycode/desktop › electron-builder
  workspace:@tinycode/desktop › @actions/artifact
  high: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - https://github.com/advisories/GHSA-3ppc-4f35-3m26
  high: minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments - https://github.com/advisories/GHSA-7r86-cg39-jmmj
  high: minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions - https://github.com/advisories/GHSA-23c5-xmqv-rm74

diff  >=6.0.0 <8.0.3
  (direct dependency)
  workspace:@tinycode/app › diff
  workspace:tinycode › diff
  workspace:@tinycode/ui › diff
  workspace:@tinycode/plugin › @opentui/core
  workspace:tinycode › @pierre/diffs
  low: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch - https://github.com/advisories/GHSA-73rr-hh4g-fpgx

@hey-api/openapi-ts  <0.97.3
  workspace:@tinycode/sdk › @hey-api/openapi-ts
  moderate: @hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key - https://github.com/advisories/GHSA-hhx9-57xq-r5rw

seroval  <=1.4.0
  workspace:@tinycode/app › solid-js
  high: Seroval affected by Denial of Service via Array serialization - https://github.com/advisories/GHSA-66fc-rw6m-c2q6
  high: seroval Affected by Remote Code Execution via JSON Deserialization - https://github.com/advisories/GHSA-3rxj-6cgf-8cfw
  high: seroval Affected by Prototype Pollution via JSON Deserialization - https://github.com/advisories/GHSA-hj76-42vx-jwp4
  high: Seroval affected by Denial of Service via Deeply Nested Objects - https://github.com/advisories/GHSA-3j22-8qj3-26mx
  high: seroval affected by Denial of Service via RegExp serialization - https://github.com/advisories/GHSA-hx9m-jf43-8ffr

@opentelemetry/core  <2.8.0
  workspace:tinycode › @opentelemetry/exporter-trace-otlp-http
  workspace:tinycode › @opentelemetry/sdk-trace-base
  workspace:tinycode › @opentelemetry/sdk-trace-node
  workspace:tinycode › @effect/opentelemetry
  moderate: OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation - https://github.com/advisories/GHSA-8988-4f7v-96qf

js-yaml  <3.15.0
  workspace:@tinycode/desktop › electron-updater
  workspace:tinycode › gray-matter
  workspace:@tinycode/sdk › @hey-api/openapi-ts
  workspace:@tinycode/desktop › electron-builder
  moderate: JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases - https://github.com/advisories/GHSA-h67p-54hq-rp68

hono  <4.12.25
  (direct dependency)
  workspace:tinycode › @modelcontextprotocol/sdk
  workspace:tinycode › @openauthjs/openauth
  moderate: hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`) - https://github.com/advisories/GHSA-wwfh-h76j-fc44
  moderate: hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice - https://github.com/advisories/GHSA-j6c9-x7qj-28xf
  high: hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard - https://github.com/advisories/GHSA-88fw-hqm2-52qc
  moderate: hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length` - https://github.com/advisories/GHSA-rv63-4mwf-qqc2
  moderate: hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest - https://github.com/advisories/GHSA-wgpf-jwqj-8h8p

protobufjs  <=7.6.2
  workspace:tinycode › @opentelemetry/exporter-trace-otlp-http
  moderate: protobufjs : Schema-derived names can shadow runtime-significant properties - https://github.com/advisories/GHSA-f38q-mgvj-vph7

@babel/core  <=7.29.0
  workspace:tinycode › @babel/core
  workspace:@tinycode/plugin › @opentui/solid
  workspace:@tinycode/desktop › electron-vite
  workspace:@tinycode/app › vite-plugin-solid
  workspace:tinycode › @babel/core
  workspace:@tinycode/desktop › @sentry/vite-plugin
  low: @babel/core: Arbitrary File Read via sourceMappingURL Comment - https://github.com/advisories/GHSA-4x5r-pxfx-6jf8

45 vulnerabilities (19 high, 18 moderate, 8 low)

To update all dependencies to the latest compatible versions:
  bun update

To update all dependencies to the latest versions (including breaking changes):
  bun update --latest


Please review and address HIGH/CRITICAL vulnerabilities.

@dependabot @github

dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/ws-8.21.1 branch July 28, 2026 17:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant