Skip to content

Bump ws to 8.20.1 in yoga yarn.lock (CVE-2026-45736) (#1983)#1983

Closed
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D108618638
Closed

Bump ws to 8.20.1 in yoga yarn.lock (CVE-2026-45736) (#1983)#1983
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D108618638

Conversation

@rozele

@rozele rozele commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Summary:

Remediates a medium-severity security vulnerability in the ws npm package reported for the facebook/yoga repository (GHSA-58qx-3vcg-4xpx / CVE-2026-45736), which affects ws >= 8.0.0, < 8.20.1.

Updates the ws@^8.13.0, ws@^8.19.0 entry in xplat/yoga/yarn.lock from 8.19.0 to the fixed 8.20.1, including the new resolved URL and integrity hash from the npm registry. Both existing semver ranges are satisfied by 8.20.1, so no package.json change is needed. ws is a transitive dependency.

The separate ws@^7.3.1 (7.5.10) entry is below 8.0.0 and is not affected, so it is left unchanged.

Reviewed By: javache

Differential Revision: D108618638

@meta-cla meta-cla Bot added the CLA Signed label Jun 29, 2026
@meta-codesync

meta-codesync Bot commented Jun 29, 2026

Copy link
Copy Markdown

@rozele has exported this pull request. If you are a Meta employee, you can view the originating Diff in D108618638.

Summary:
Pull Request resolved: react#1983

Pull Request resolved: react#1982

Remediates a medium-severity security vulnerability in the `ws` npm package reported for the `facebook/yoga` repository (GHSA-58qx-3vcg-4xpx / CVE-2026-45736), which affects `ws >= 8.0.0, < 8.20.1`.

Updates the `ws@^8.13.0, ws@^8.19.0` entry in `xplat/yoga/yarn.lock` from `8.19.0` to the fixed `8.20.1`, including the new `resolved` URL and `integrity` hash from the npm registry. Both existing semver ranges are satisfied by `8.20.1`, so no `package.json` change is needed. `ws` is a transitive dependency.

The separate `ws@^7.3.1` (7.5.10) entry is below 8.0.0 and is not affected, so it is left unchanged.

Reviewed By: javache

Differential Revision: D108618638
@rozele rozele force-pushed the export-D108618638 branch from aaf680b to 9fec7d7 Compare June 29, 2026 16:48
@meta-codesync meta-codesync Bot changed the title Bump ws to 8.20.1 in yoga yarn.lock (CVE-2026-45736) (#1982) Bump ws to 8.20.1 in yoga yarn.lock (CVE-2026-45736) (#1983) Jun 29, 2026
@meta-codesync meta-codesync Bot closed this in 92c7a1c Jun 29, 2026
@meta-codesync

meta-codesync Bot commented Jun 29, 2026

Copy link
Copy Markdown

This pull request has been merged in 92c7a1c.

@meta-codesync meta-codesync Bot added the Merged label Jun 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant