chore(deps): bump websocket-driver from 0.7.4 to 0.7.5 in /frontend/webcoder_ui#98
Conversation
Bumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.4 to 0.7.5. - [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md) - [Commits](faye/websocket-driver-node@0.7.4...0.7.5) --- updated-dependencies: - dependency-name: websocket-driver dependency-version: 0.7.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
|
PR-specific note (#98 — highest priority of the four). This PR is the fix for the only CRITICAL alert in the repo: GHSA-xv26-6w52-cph6 (CVSS 9.2) plus GHSA-mp7j-qc5w-4988, both websocket-driver 0.7.4 -> 0.7.5. Its lock delta also carries ws 7.5.11 -> 7.5.12, which does NOT satisfy the 7.5.13 the ideal tree now wants, so it does not by itself resolve Blocker 2 below. Its own quality run additionally died on a THIRD, transient cause, unrelated to the two below — step 9 Install opengrep: Diagnosis: left OPEN. This PR is unique and still wanted, but it is blocked by two repo-level defects on Blocker 1 — the required That set is NOT closable by bounded-floor bumps, so it is an owner call:
Blocker 2 —
Note No action taken on this PR beyond this comment: it carries a real, unique change |
Bumps websocket-driver from 0.7.4 to 0.7.5.
Changelog
Sourced from websocket-driver's changelog.
Commits
5d6a9aaBump version to 0.7.5c55679aFail the connection if a message is larger than the configured max length aft...5b197caClose a draft-75/76 connection if a length header grows to exceed the configu...fc93a48Test on Node v22, v24, and v262e82d34Test on recent versions of Nodee4962dbSwitch from Travis CI to GitHub Actions3f2f9b7Travis update: cache npm modules, remove sudo, run on Node 15Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.