Skip to content

build(deps): bump ws from 8.18.2 to 8.20.1 in /ts#2361

Merged
TalZaccai merged 1 commit into
mainfrom
dependabot/npm_and_yarn/ts/ws-8.20.1
May 19, 2026
Merged

build(deps): bump ws from 8.18.2 to 8.20.1 in /ts#2361
TalZaccai merged 1 commit into
mainfrom
dependabot/npm_and_yarn/ts/ws-8.20.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 19, 2026

Bumps ws from 8.18.2 to 8.20.1.

Release notes

Sourced from ws's releases.

8.20.1

Bug fixes

  • Fixed an uninitialized memory disclosure issue in websocket.close() (c0327ec1).

Providing a TypedArray (e.g. Float32Array) as the reason argument for websocket.close(), rather than the supported string or Buffer types, caused uninitialized memory to be disclosed to the remote peer.

import { deepStrictEqual } from 'node:assert';
import { WebSocket, WebSocketServer } from 'ws';
const wss = new WebSocketServer(
{ port: 0, skipUTF8Validation: true },
function () {
const { port } = wss.address();
const ws = new WebSocket(ws://localhost:${port}, {
skipUTF8Validation: true
});
ws.on('close', function (code, reason) {
  deepStrictEqual(reason, Buffer.alloc(80));
});

}
);
wss.on('connection', function (ws) {
ws.close(1000, new Float32Array(20));
});

The issue was privately reported by Nikita Skovoroda.

8.20.0

Features

  • Added exports for the PerMessageDeflate class and utilities for the Sec-WebSocket-Extensions and Sec-WebSocket-Protocol headers (d3503c1f).

8.19.0

Features

  • Added the closeTimeout option (#2308).

Bug fixes

  • Handled a forthcoming breaking change in Node.js core (19984854).

... (truncated)

Commits
  • 5d9b316 [dist] 8.20.1
  • c0327ec [security] Fix uninitialized memory disclosure in websocket.close()
  • ce2a3d6 [ci] Test on node 26
  • 58e45b8 [ci] Do not test on node 25
  • 5f26c24 [ci] Run the lint step on node 24
  • 8439255 [dist] 8.20.0
  • d3503c1 [minor] Export the PerMessageDeflate class and header utils
  • 3ee5349 [api] Convert the isServer and maxPayload parameters to options
  • 91707b4 [doc] Add missing space
  • 8b55319 [pkg] Update eslint to version 10.0.1
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 19, 2026
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 03:08 Error
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 03:08 Error
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/ts/ws-8.20.1 branch from 4140b83 to 2efccf5 Compare May 19, 2026 19:03
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 19:03 Error
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 19:03 Error
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/ts/ws-8.20.1 branch from 2efccf5 to 56a3291 Compare May 19, 2026 19:20
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 19:20 Failure
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 19:20 Failure
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 20:10 Error
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 20:10 Error
Bumps [ws](https://github.com/websockets/ws) from 8.18.2 to 8.20.1.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.2...8.20.1)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.20.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/ts/ws-8.20.1 branch from 56a3291 to c45c29a Compare May 19, 2026 20:15
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 20:15 Failure
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 20:15 Failure
@dependabot dependabot Bot temporarily deployed to development-fork May 19, 2026 20:32 Inactive
@dependabot dependabot Bot had a problem deploying to development-fork May 19, 2026 20:32 Failure
@TalZaccai TalZaccai added this pull request to the merge queue May 19, 2026
Merged via the queue into main with commit 7f40c44 May 19, 2026
15 of 18 checks passed
@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/ts/ws-8.20.1 branch May 19, 2026 21:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant