Skip to content

Commit 96ce6f9

Browse files
prog1devfacebook-github-bot
authored andcommitted
Bump ws package to 1.1.5 due to vulnerability issues (#21769)
Summary: Update `ws` package from 1.1.0 to 1.1.5 due to vulnerability issues. Here is `npm audit` report: ``` === npm audit security report === ┌──────────────────────────────────────────────────────────────────────────────┐ │ Manual Review │ │ Some vulnerabilities require your attention to resolve │ │ │ │ Visit https://go.npm.me/audit-guide for additional guidance │ └──────────────────────────────────────────────────────────────────────────────┘ ┌───────────────┬──────────────────────────────────────────────────────────────┐ │ High │ Denial of Service │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Package │ ws │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Patched in │ >= 1.1.5 <2.0.0 || >=3.3.1 │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Dependency of │ c635d8a886cde7688a0123f573cc5b1f0430780052ba848c8fa1dc8a4c3… │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Path │ c635d8a886cde7688a0123f573cc5b1f0430780052ba848c8fa1dc8a4c3… │ │ │ > react-devtools-core > ws │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ More info │ https://nodesecurity.io/advisories/550 │ └───────────────┴──────────────────────────────────────────────────────────────┘ ``` Pull Request resolved: #21769 Reviewed By: hramos Differential Revision: D10379892 Pulled By: cpojer fbshipit-source-id: 9d03f8231a90c5f55eb95ccac029aedd45a49a2d
1 parent 073ad6a commit 96ce6f9

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -209,7 +209,7 @@
209209
"serve-static": "^1.13.1",
210210
"shell-quote": "1.6.1",
211211
"stacktrace-parser": "^0.1.3",
212-
"ws": "^1.1.0",
212+
"ws": "^1.1.5",
213213
"xcode": "^1.0.0",
214214
"xmldoc": "^0.4.0",
215215
"yargs": "^9.0.0"

yarn.lock

+1-1
Original file line numberDiff line numberDiff line change
@@ -7164,7 +7164,7 @@ write@^0.2.1:
71647164
dependencies:
71657165
mkdirp "^0.5.1"
71667166

7167-
ws@^1.1.0, ws@^1.1.1:
7167+
ws@^1.1.0, ws@^1.1.1, ws@^1.1.5:
71687168
version "1.1.5"
71697169
resolved "https://registry.yarnpkg.com/ws/-/ws-1.1.5.tgz#cbd9e6e75e09fc5d2c90015f21f0c40875e0dd51"
71707170
integrity sha512-o3KqipXNUdS7wpQzBHSe180lBGO60SoK0yVo3CYJgb2MkobuWuBX6dhkYP5ORCLd55y+SaflMOV5fqAB53ux4w==

0 commit comments

Comments
 (0)