In vulnerable versions of ws, the issue can be mitigated in the following ways:
Reduce the maximum allowed length of the request headers using the
[--max-http-header-size=size][] and/or the [maxHeaderSize][] options so
that no more headers than the server.maxHeadersCount limit can be sent.
Bumps ws to 8.17.1 and updates ancestor dependencies ws, gatsby, gatsby-plugin-google-analytics, gatsby-plugin-manifest, gatsby-plugin-material-ui, gatsby-plugin-offline, gatsby-plugin-react-helmet, gatsby-plugin-react-intl, gatsby-plugin-sharp, gatsby-plugin-sitemap, gatsby-plugin-typography, gatsby-source-filesystem and gatsby-transformer-sharp. These dependencies need to be updated together.
Updates
ws
from 7.4.5 to 8.17.1Release notes
Sourced from ws's releases.
... (truncated)
Commits
3c56601
[dist] 8.17.1e55e510
[security] Fix crash when the Upgrade header cannot be read (#2231)6a00029
[test] Increase code coverageddfe4a8
[perf] Reduce the amount ofcrypto.randomFillSync()
callsb73b118
[dist] 8.17.029694a5
[test] Use thehighWaterMark
variable934c9d6
[ci] Test on node 221817bac
[ci] Do not test on node 2196c9b3d
[major] Flip the default value ofallowSynchronousEvents
(#2221)e5f32c7
[fix] Emit at most one event per event loop iteration (#2218)Updates
gatsby
from 3.15.0 to 5.13.7Release notes
Sourced from gatsby's releases.
... (truncated)
Commits
d92aa8c
chore(release): Publish74d1fd1
fix(gatsby-adapter-netlify): support monorepos (#39005) (#39037)36f23d2
chore(release): Publish04c438a
perf(gatsby-adapter-netlify): improve adapt() performance (#38988) (#38991)6c63350
chore(release): Publish326c89a
feat: allow dsg/ssr renders without access to datastore if it's not required ...e7231ec
chore: pin@vercel/webpack-asset-relocator-loader
(#38981) (#38982)0f9ad54
chore(release): Publishb6935a4
chore(gatsby-source-contentful): upgrade is-online (#38862) (#38970)8f0f7c5
chore(release): PublishUpdates
gatsby-plugin-google-analytics
from 3.15.0 to 5.13.1Release notes
Sourced from gatsby-plugin-google-analytics's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-google-analytics's changelog.
... (truncated)
Commits
b24134d
chore(release): Publish18ffcfa
chore(release): Publishdb248ab
chore(changelogs): update changelogs (#38526)e6e2fb4
chore(release): Publish next pre-minorfd4d702
chore(changelogs): update changelogs (#38248)0991178
chore(release): Publish next pre-minorebe9bc6
chore(release): Publish next57a4af5
chore(changelogs): update changelogs (#38096)99664bc
chore(release): Publish next pre-minora9c54f7
chore(release): Publish nextUpdates
gatsby-plugin-manifest
from 3.15.0 to 5.13.1Release notes
Sourced from gatsby-plugin-manifest's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-manifest's changelog.
... (truncated)
Commits
b24134d
chore(release): Publish18ffcfa
chore(release): Publish26871b8
chore(release): Publish next9a26700
chore(changelogs): update changelogs (#38667)7ba63eb
chore(changelogs): update changelogs (#38658)d90d747
chore(changelogs): update changelogs (#38642)ca15ef3
chore(deps): upgrade sharp to latest v0.32.6 (#38374)db248ab
chore(changelogs): update changelogs (#38526)e6e2fb4
chore(release): Publish next pre-minor1ebae56
chore(release): Publish nextUpdates
gatsby-plugin-material-ui
from 3.0.1 to 4.1.0Commits
6eda811
v4.1.0c59c025
chore: Update node in cib9ddd06
feat: Add gatsby v4 supportf49dca5
v4.0.3e787e20
mui V5 support (#78)Updates
gatsby-plugin-offline
from 4.15.0 to 6.13.2Release notes
Sourced from gatsby-plugin-offline's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-offline's changelog.
... (truncated)
Commits
8f0f7c5
chore(release): Publishedaf016
fix(gatsby-adapter-netlify): handler generation on windows (#38900) (#38929)b24134d
chore(release): Publish18ffcfa
chore(release): Publish26871b8
chore(release): Publish next9a26700
chore(changelogs): update changelogs (#38667)7ba63eb
chore(changelogs): update changelogs (#38658)d90d747
chore(changelogs): update changelogs (#38642)db248ab
chore(changelogs): update changelogs (#38526)e6e2fb4
chore(release): Publish next pre-minorUpdates
gatsby-plugin-react-helmet
from 4.15.0 to 6.13.1Release notes
Sourced from gatsby-plugin-react-helmet's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-react-helmet's changelog.
... (truncated)
Commits
b24134d
chore(release): Publish18ffcfa
chore(release): Publishdb248ab
chore(changelogs): update changelogs (#38526)e6e2fb4
chore(release): Publish next pre-minorfd4d702
chore(changelogs): update changelogs (#38248)0991178
chore(release): Publish next pre-minorebe9bc6
chore(release): Publish next57a4af5
chore(changelogs): update changelogs (#38096)99664bc
chore(release): Publish next pre-minora9c54f7
chore(release): Publish nextUpdates
gatsby-plugin-react-intl
from 3.0.2 to 4.0.0Commits
e54fa5d
Release 4.0.0642e8a9
Merge pull request #16 from violy/main9d45d38
Update peerDependencies to include Gatsby 47564088
Update README.mdUpdates
gatsby-plugin-sharp
from 3.15.0 to 5.13.1Release notes
Sourced from gatsby-plugin-sharp's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-sharp's changelog.
... (truncated)
Commits
b24134d
chore(release): Publish18ffcfa
chore(release): Publish26871b8
chore(release): Publish next9a26700
chore(changelogs): update changelogs (#38667)7ba63eb
chore(changelogs): update changelogs (#38658)d90d747
chore(changelogs): update changelogs (#38642)ca15ef3
chore(deps): upgrade sharp to latest v0.32.6 (#38374)db248ab
chore(changelogs): update changelogs (#38526)e6e2fb4
chore(release): Publish next pre-minor1ebae56
chore(release): Publish nextUpdates
gatsby-plugin-sitemap
from 4.11.0 to 6.13.1Release notes
Sourced from gatsby-plugin-sitemap's releases.
... (truncated)
Changelog
Sourced from gatsby-plugin-sitemap's changelog.