Skip to content

chore(deps): bump ws from 8.18.0 to 8.21.3 - #862

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ws-8.21.3
Closed

chore(deps): bump ws from 8.18.0 to 8.21.3#862
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/ws-8.21.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps ws from 8.18.0 to 8.21.3.

Release notes

Sourced from ws's releases.

8.21.3

Bug fixes

  • The server now correctly rejects permessage-deflate offers if the incoming client_max_window_bits parameter value is smaller than its configured clientMaxWindowBits (e97a20ea).

8.21.2

Bug fixes

  • Fixed a test for CITGM (2eb3be0b).

8.21.1

Bug fixes

  • Empty fragments are now counted toward the limit (a2f4e7c0).
  • The default values of the maxBufferedChunks and maxFragments options have been reduced (f197ac65).

8.21.0

Features

  • Introduced the maxBufferedChunks and maxFragments options (2b2abd45).

Bug fixes

  • Fixed a remote memory exhaustion DoS vulnerability (2b2abd45).

A high volume of tiny fragments and data chunks could be sent by a peer, using modest network traffic, to crash a ws server or client due to OOM.

import { WebSocket, WebSocketServer } from 'ws';
const wss = new WebSocketServer({ port: 0 }, function () {
const data = Buffer.alloc(1);
const options = { fin: false };
const { port } = wss.address();
const ws = new WebSocket(ws://localhost:${port});
ws.on('open', function () {
(function send() {
ws.send(data, options, function (err) {
if (err) return;
send();
});
})();
});
</tr></table>

... (truncated)

Commits
  • c791e70 [dist] 8.21.3
  • e97a20e [fix] Reject offers with client_max_window_bits below config
  • 787ebf2 [dist] 8.21.2
  • b4d62eb Revert "[ci] Trust Coveralls Homebrew tap"
  • e4bb883 [security] Use GitHub PVR as main reporting channel
  • 2eb3be0 [test] Skip test on Node.js versions where it does not apply
  • ae1de54 [dist] 8.21.1
  • 8e9511b [ci] Trust Coveralls Homebrew tap
  • f197ac6 [fix] Lower default values of maxBufferedChunks and maxFragments
  • 8df8265 [ci] Update actions/checkout action to v7
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Not Automerged

The PR does not match any automerge rules.

Details: No configuration rule matched this update

Dependabot Information:

  • Package name(s): ws
  • Update type: minor
  • Dependency type: production
  • Previous version: 8.18.0
  • New version: 8.21.3

Modified Files:

  • package-lock.json
  • package.json

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/ws-8.21.3 branch from f493b58 to 22bf3ed Compare August 24, 2026 11:28
@github-actions

Copy link
Copy Markdown
Contributor

Not Automerged

The PR does not match any automerge rules.

Details: No configuration rule matched this update

Dependabot Information:

  • Package name(s): ws
  • Update type: minor
  • Dependency type: production
  • Previous version: 8.18.0
  • New version: 8.21.3

Modified Files:

  • package-lock.json
  • package.json

Bumps [ws](https://github.com/websockets/ws) from 8.18.0 to 8.21.3.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.18.0...8.21.3)

---
updated-dependencies:
- dependency-name: ws
  dependency-version: 8.21.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/ws-8.21.3 branch from 22bf3ed to de625ac Compare August 24, 2026 11:58
@github-actions

Copy link
Copy Markdown
Contributor

Not Automerged

The PR does not match any automerge rules.

Details: No configuration rule matched this update

Dependabot Information:

  • Package name(s): ws
  • Update type: minor
  • Dependency type: production
  • Previous version: 8.18.0
  • New version: 8.21.3

Modified Files:

  • package-lock.json
  • package.json

DutchmanNL added a commit that referenced this pull request Aug 24, 2026
Runtime dependencies:
* @iobroker/adapter-core ^3.4.1 -> ^3.4.3
* axios ^1.12.0 -> ^1.19.0
* ws ^8.7.0 -> ^8.21.3 (resolves GHSA-58qx-3vcg-4xpx / GHSA-96hv-2xvq-fx4p)

Dev dependencies:
* @tsconfig/node22 ^22.0.2 -> ^22.0.6
* @types/node ^22.10.0 -> ^22.20.1 (kept on the 22.x line to match engines.node >= 22)
* lockfile refresh pulls @iobroker/eslint-config 2.3.4, @iobroker/testing 5.3.0,
  @jey-cee/dm-utils 0.0.5, deepl-node 1.28.0 and adm-zip 0.6.0 (CVE-2026-39244)

GitHub Actions:
* actions/checkout v4 -> v7
* actions/github-script v7 -> v9

Deliberately not taken:
* hex-rgb 5.x and rgb-hex 4.x are ESM-only; this adapter is CommonJS and
  require()s both in main.js, so they stay on 4.3.0 / 3.0.0.

Supersedes dependabot PRs #865, #862, #857, #856 and makes #864 and #861 obsolete.

Verified locally: npm run lint (0 errors), npm run test:package (57 passing),
npm run test:js (1 passing), npm run test:integration (2 passing, adapter boots).

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@DutchmanNL

Copy link
Copy Markdown
Contributor

Superseded by the consolidated dependency update in #867 (merged).

@DutchmanNL DutchmanNL closed this Aug 24, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/ws-8.21.3 branch August 24, 2026 13:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant