Closed dependabot[bot] closed 2 weeks ago
New and removed dependencies detected. Learn more about Socket for GitHub ↗︎
Package | New capabilities | Transitives | Size | Publisher |
---|---|---|---|---|
npm/strip-ansi@6.0.1 | None | +1 |
9.64 kB | sindresorhus |
npm/terminal-link@2.1.1 | None | +3 |
149 kB | sindresorhus |
npm/typescript@5.0.4 | None | 0 |
39.2 MB | typescript-bot |
npm/uglify-js@3.9.1 | eval, filesystem Transitive: shell | +1 |
872 kB | alexlamsl |
npm/which@2.0.2 | environment Transitive: filesystem | +1 |
20.9 kB | isaacs |
npm/wrap-ansi@7.0.0 | None | +4 |
76.1 kB | sindresorhus |
Bumps ws from 7.5.5 to 7.5.10.
Release notes
Sourced from ws's releases.
Commits
d962d70
[dist] 7.5.1022c2876
[security] Fix crash when the Upgrade header cannot be read (#2231)8a78f87
[dist] 7.5.90435e6e
[security] Fix same host check for ws+unix: redirects4271f07
[dist] 7.5.8dc1781b
[security] Drop sensitive headers when following insecure redirects2758ed3
[fix] Abort the handshake if the Upgrade header is invalida370613
[dist] 7.5.71f72e2e
[security] Drop sensitive headers when following redirects (#2013)8ecd890
[dist] 7.5.6Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show