From 51b23c248ae5a423cd8d8dc438953481bbec01dd Mon Sep 17 00:00:00 2001 From: Tom Boucher Date: Mon, 15 Jun 2026 14:07:52 -0400 Subject: [PATCH] fix(#1274): bump ws to ^8.21.0 to clear advisory GHSA-96hv-2xvq-fx4p (#1275) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The direct production dependency ws was pinned to 8.20.1, in the vulnerable range of GHSA-96hv-2xvq-fx4p (high — memory-exhaustion DoS). The freshly disclosed advisory turned the #3588 `npm audit --omit=dev reports zero advisories` CI gate red repo-wide (next + every open PR). Bump to the patched ^8.21.0 (backward-compatible). npm audit --omit=dev now reports 0. Closes #1274 Co-authored-by: Claude Opus 4.8 --- package-lock.json | 8 ++++---- package.json | 2 +- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index 9e6ac4b95..75296076f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -10,7 +10,7 @@ "license": "MIT", "dependencies": { "@anthropic-ai/claude-agent-sdk": "^0.2.84", - "ws": "8.20.1" + "ws": "^8.21.0" }, "bin": { "gsd_run": "gsd-core/bin/gsd_run", @@ -5207,9 +5207,9 @@ "license": "ISC" }, "node_modules/ws": { - "version": "8.20.1", - "resolved": "https://registry.npmjs.org/ws/-/ws-8.20.1.tgz", - "integrity": "sha512-It4dO0K5v//JtTXuPkfEOaI3uUN87iYPnqo/ZzqCoG3g8uhA66QUMs/SrM0YK7/NAu+r4LMh/9dq2A7k+rHs+w==", + "version": "8.21.0", + "resolved": "https://registry.npmjs.org/ws/-/ws-8.21.0.tgz", + "integrity": "sha512-Vsp28b7DRcimFQvrqu2Wek3z1iYxDCWqHYB8Qsnk/S4RfaCQzPGPyBNuVjJV3cd6UiKtUtp6sNM77gWvzcCH+g==", "license": "MIT", "engines": { "node": ">=10.0.0" diff --git a/package.json b/package.json index cd84866e5..9a647afef 100644 --- a/package.json +++ b/package.json @@ -50,7 +50,7 @@ }, "dependencies": { "@anthropic-ai/claude-agent-sdk": "^0.2.84", - "ws": "8.20.1" + "ws": "^8.21.0" }, "devDependencies": { "@eslint/js": "^9.39.4",