Skip to content

[Snyk] Upgrade ws from 8.5.0 to 8.7.0#1225

Closed
rfelber wants to merge 1 commit intomainfrom
snyk-upgrade-6620879caab95f1df306ac4d5010dfc2
Closed

[Snyk] Upgrade ws from 8.5.0 to 8.7.0#1225
rfelber wants to merge 1 commit intomainfrom
snyk-upgrade-6620879caab95f1df306ac4d5010dfc2

Conversation

@rfelber
Copy link
Copy Markdown
Member

@rfelber rfelber commented Jun 17, 2022

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade ws from 8.5.0 to 8.7.0.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.
  • The recommended version was released 22 days ago, on 2022-05-26.
Release notes
Package name: ws
  • 8.7.0 - 2022-05-26

    Features

    • Added the ability to inspect the invalid handshake requests and respond to
      them with a custom HTTP response. (6e5a5ce).

    Bug fixes

    • The handshake is now aborted if the Upgrade header field value in the HTTP
      response is not a case-insensitive match for the value "websocket" (0fdcc0a).
    • The Authorization and Cookie headers are no longer sent when following an
      insecure redirect (wss: to ws:) to the same host (d68ba9e).
  • 8.6.0 - 2022-05-01

    Features

    • Added the ability to remove confidential headers on a per-redirect basis (#2030).
  • 8.5.0 - 2022-02-07

    Features

    • Added the ability to use a custom WebSocket class on the server (#2007).

    Bug fixes

    • When following redirects, the Authorization and Cookie headers are no
      longer sent if the redirect host is different from the original host (#2013).
from ws GitHub release notes
Commit messages
Package name: ws

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@github-actions
Copy link
Copy Markdown

github-actions bot commented Jun 17, 2022

MegaLinter status: ⚠️ WARNING

Descriptor Linter Files Fixed Errors Elapsed time
✅ GIT git_diff yes no 0.18s
✅ JSON eslint-plugin-jsonc 2 0 1.3s
✅ JSON jsonlint 2 0 0.61s
⚠️ JSON prettier 2 1 0.66s
✅ JSON v8r 2 0 3.73s
✅ SPELL misspell 2 0 0.04s

See errors details in artifact MegaLinter reports on CI Job page
Set VALIDATE_ALL_CODEBASE: true in mega-linter.yml to validate all sources, not only the diff

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants