In vulnerable versions of ws, the issue can be mitigated in the following ways:
Reduce the maximum allowed length of the request headers using the
[--max-http-header-size=size][] and/or the [maxHeaderSize][] options so
that no more headers than the server.maxHeadersCount limit can be sent.
Bumps the npm_and_yarn group with 11 updates in the / directory:
7.5.4
7.6.0
3.1.0
removed
4.47.0
5.92.1
6.2.4
8.5.1
3.1.0
3.1.6
4.18.2
4.19.2
1.15.4
1.15.6
2.7.1
2.8.9
1.3.5
1.3.8
8.4.31
8.4.38
8.14.2
8.17.1
Bumps the npm_and_yarn group with 7 updates in the /search-prototype directory:
6.3.0
6.3.1
3.0.2
3.0.3
4.18.1
4.19.2
1.15.4
1.15.6
7.5.9
7.5.10
3.1.8
3.1.10
1.2.3
1.2.5
Updates
semver
from 7.5.4 to 7.6.0Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
377f709
chore: release 7.6.0 (#661)a7ab13a
feat: preserve pre-release and build parts of a version on coerce (#671)816c7b2
chore: postinstall for dependabot template-oss PR0bd24d9
chore: bump@npmcli/template-oss
from 4.21.1 to 4.21.3e521932
chore: postinstall for dependabot template-oss PR8873991
chore: chore: chore: postinstall for dependabot template-oss PRf317dc8
chore: bump@npmcli/template-oss
from 4.19.0 to 4.21.07303db1
chore: add clean() test for build metadata (#658)6240d75
chore: add missing quotes in README.md (#656)14d263f
chore: postinstall for dependabot template-oss PRRemoves
glob-parent
Updates
webpack
from 4.47.0 to 5.92.1Release notes
Sourced from webpack's releases.
... (truncated)
Commits
a82e0cd
chore(release): 5.92.10d07d65
fix: error with contenthash and css experiment8efac43
test: added10638c0
chore(deps-dev): bump eslint-plugin-n from 17.8.1 to 17.9.0d0f7b65
chore(deps-dev): bump lint-staged from 15.2.5 to 15.2.750bd02c
chore(deps-dev): bump@eslint/js
from 9.4.0 to 9.5.09e395cd
chore(deps): bump acorn from 8.11.3 to 8.12.0db7f83c
chore(deps-dev): bump globals from 15.4.0 to 15.6.0b7d2cbe
chore(deps-dev): bump@types/node
from 20.14.2 to 20.14.518dab63
chore(deps-dev): bump@types/node
from 20.14.2 to 20.14.5Updates
@hapi/hoek
from 6.2.4 to 8.5.1Commits
5bd73f6
8.5.14d0804b
Backport #352. Closes #3534ae5f53
8.5.083019b8
Add isPromise(). Closes #346b9aa286
Add declaration5dcbb9c
8.4.0d898b06
Add TS utils. Closes #345ea1741d
8.3.2f6eb28d
Improve clone() performance. Closes #3448fa5664
8.3.1Updates
@hapi/topo
from 3.1.0 to 3.1.6Commits
745941e
3.1.6e50af62
Hoek dep. Closes #582a524b6
3.1.59e20087
Remove types. Closes #5680de44a
3.1.4f793bd0
Cleanupb79bfcf
Merge pull request #46 from jarrodyellets/master87f9a7d
Update README.mdd5c2c62
Merge pull request #47 from jarrodyellets/apiUpdateacb364d
update APIUpdates
express
from 4.18.2 to 4.19.2Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
Commits
04bc627
4.19.2da4d763
Improved fix for open redirect allow list bypass4f0f6cc
4.19.1a003cfa
Allow passing non-strings to res.location with new encoding handling checks f...a1fa90f
fixed un-edited version in history.md for 4.19.011f2b1d
build: fix build due to inconsistent supertest behavior in older versions084e365
4.19.00867302
Prevent open redirect allow list bypass due to encodeurl567c9c6
Add note on how to update docs for new release (#5541)69a4cf2
deps: cookie@0.6.0Maintainer changes
This version was pushed to npm by wesleytodd, a new releaser for express since your current version.
Updates
follow-redirects
from 1.15.4 to 1.15.6Commits
35a517c
Release version 1.15.6 of the npm package.c4f847f
Drop Proxy-Authorization across hosts.8526b4a
Use GitHub for disclosure.b1677ce
Release version 1.15.5 of the npm package.d8914f7
Preserve fragment in responseUrl.Updates
hosted-git-info
from 2.7.1 to 2.8.9Changelog
Sourced from hosted-git-info's changelog.
... (truncated)
Commits
8d4b369
chore(release): 2.8.929adfe5
fix: backport regex fix from #76afeaefd
chore(release): 2.8.85038b18
fix: #61 & #65 addressing issues w/ url.URL implmentation which regressed nod...7440afa
chore(release): 2.8.72d0bb66
fix: Do not attempt to use url.URL when unavailablef2cdfcf
fix: Do not pass scp-style URLs to the WhatWG url.URLe1b83df
chore(release): 2.8.6ff259a6
Ensure passwords in hosted Git URLs are correctly escaped624fd6f
chore(release): 2.8.5Maintainer changes
This version was pushed to npm by nlf, a new releaser for hosted-git-info since your current version.
Updates
ini
from 1.3.5 to 1.3.8Commits
a2c5da8
1.3.8af5c6bb
Do not use Object.create(null)8b648a1
don't test where our devdeps don't even workc74c8af
1.3.7024b8b5
update deps, add linting032fbaf
Use Object.create(null) to avoid default object property hazards2da9039
1.3.6cfea636
better git push script, before publish instead of after56d2805
do not allow invalid hazardous string as section nameMaintainer changes
This version was pushed to npm by isaacs, a new releaser for ini since your current version.
Updates
postcss
from 8.4.31 to 8.4.38Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
a69d45e
Release 8.4.38 version64e35d9
Update dependenciesc1ad8fb
Merge pull request #1932 from romainmenke/fix-warning-end-index--inventive-nu...b45e7e9
fix endIndex1bea246
failing test: for endIndex 0 in rangeBy0fd1d86
Add changelog auto release on Github49c906e
Release 8.4.37 versionb5bd92c
Fix another broken prev source map issue2882039
Update dependenciese5ad939
Release 8.4.36 versionUpdates
ws
from 8.14.2 to 8.17.1Release notes
Sourced from ws's releases.
... (truncated)
Commits
3c56601
[dist] 8.17.1e55e510
[security] Fix crash when the Upgrade header cannot be read (#2231)6a00029
[test] Increase code coverageddfe4a8
[perf] Reduce the amount ofcrypto.randomFillSync()
callsb73b118
[dist] 8.17.029694a5
[test] Use thehighWaterMark
variable934c9d6
[ci] Test on node 221817bac
[ci] Do not test on node 2196c9b3d
[major] Flip the default value ofallowSynchronousEvents
(#2221)e5f32c7
[fix] Emit at most one event per event loop iteration (#2218)Updates
semver
from 6.3.0 to 6.3.1Release notes
Sourced from semver's releases.
Changelog
Sourced from semver's changelog.
Commits
377f709
chore: release 7.6.0 (#661)a7ab13a
feat: preserve pre-release and build parts of a version on coerce (#671)816c7b2
chore: postinstall for dependabot template-oss PR0bd24d9
chore: bump@npmcli/template-oss
from 4.21.1 to 4.21.3e521932
chore: postinstall for dependabot template-oss PR8873991
chore: chore: chore: postinstall for dependabot template-oss PRf317dc8
chore: bump@npmcli/template-oss
from 4.19.0 to 4.21.07303db1
chore: add clean() test for build metadata (#658)6240d75
chore: add missing quotes in README.md (#656)14d263f
chore: postinstall for dependabot template-oss PRUpdates
braces
from 3.0.2 to 3.0.3Commits
74b2db2
3.0.388f1429
update eslint. lint, fix unit tests.415d660
Snyk js braces 6838727 (#40)190510f
fix tests, skip 1 test in test/braces.expand716eb9f
readme bumpa5851e5
Merge pull request #37 from coderaiser/fix/vulnerability2092bd1
feature: braces: add maxSymbols (https://github.com/micromatch/braces/issues/...9f5b4cf
fix: vulnerability (https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727)98414f9
remove funding file665ab5d
update keepEscaping doc (#27)Updates
express
from 4.18.1 to 4.19.2Release notes
Sourced from express's releases.