From d0dcf527ad2b98f550840c9375c92c2d15ae1d57 Mon Sep 17 00:00:00 2001 From: Noah Sherwin Date: Tue, 23 Jul 2024 03:01:05 -0700 Subject: [PATCH] fix(deps): :ambulance: bump ws to 8.18.0 (>=8.17.1) Vulnerable versions are vulnerable to a DoS attack. This vulnerability doesn't directly affect us, but shouldn't be left alone. See https://github.com/advisories/GHSA-3h5v-q93c-6h6q --- package-lock.json | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index 0564a66f..f475518f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -14169,10 +14169,11 @@ "integrity": "sha512-l4Sp/DRseor9wL6EvV2+TuQn63dMkPjZ/sp9XkghTEbV9KlPS1xUsZ3u7/IQO4wxtcFB4bgpQPRcR3QCvezPcQ==" }, "node_modules/ws": { - "version": "8.16.0", - "resolved": "https://registry.npmjs.org/ws/-/ws-8.16.0.tgz", - "integrity": "sha512-HS0c//TP7Ina87TfiPUz1rQzMhHrl/SG2guqRcTOIUYD2q8uhUdNHZYJUaQ8aTGPzCh+c6oawMKW35nFl1dxyQ==", + "version": "8.18.0", + "resolved": "https://registry.npmjs.org/ws/-/ws-8.18.0.tgz", + "integrity": "sha512-8VbfWfHLbbwu3+N6OKsOMpBdT4kXPDDB9cJk2bJ6mh9ucxdlnNvH1e+roYkKmN9Nxw2yjz7VzeO9oOz2zJ04Pw==", "dev": true, + "license": "MIT", "engines": { "node": ">=10.0.0" },