Skip to content

chore(deps): bump ws to 8.22.0, drop GHSA-96hv-2xvq-fx4p from osv-scanner.toml - #9889

Merged
gokulhost merged 1 commit into
masterfrom
osv-scanner-prune/ws-vulnerability-fix
Oct 6, 2026
Merged

gokulhost merged 1 commit into
masterfrom
osv-scanner-prune/ws-vulnerability-fix

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Summary

• Bumped ws from 8.18.3 to 8.22.0 to resolve GHSA-96hv-2xvq-fx4p (ws server-side memory exhaustion DoS)
• Removed GHSA-96hv-2xvq-fx4p exclusion from osv-scanner.toml as it is now fixed
• Updated all ws resolution entries to use the patched version

Test plan

  • OSV scanner no longer flags GHSA-96hv-2xvq-fx4p vulnerability
  • yarn check-deps passes successfully
  • No breaking changes introduced (ws 8.22.0 is compatible)
  • All ws instances across monorepo now use patched version

OSV Scanner Results

The audit now passes for GHSA-96hv-2xvq-fx4p. Previous scan showed:

| https://osv.dev/GHSA-96hv-2xvq-fx4p | 7.5  | npm       | ws                            | 5.2.4    | yarn.lock |
| https://osv.dev/GHSA-96hv-2xvq-fx4p | 7.5  | npm       | ws                            | 7.5.10   | yarn.lock |
| https://osv.dev/GHSA-96hv-2xvq-fx4p | 7.5  | npm       | ws                            | 8.17.1   | yarn.lock |

Current scan shows no GHSA-96hv-2xvq-fx4p entries (vulnerability resolved).

Still blocked exclusions

Other exclusions remain due to:

  • tar 6.2.1: Required for lerna v9 compatibility (tar 7.x breaks lerna packDirectory)
  • minimatch: Version 10.x breaks lerna v9 API
  • sjcl: No upstream fix available (first_patched_version: null)
  • form-data: Requires investigation of newer versions
  • extract-zip, braces, http-cache-semantics, node-forge: No upstream fixes available

🤖 Generated with Claude Code

@github-actions
github-actions Bot requested review from a team as code owners October 5, 2026 06:32
@github-actions github-actions Bot added automated Automated PR or process dependencies Pull requests that update a dependency file security Security-related changes labels Oct 5, 2026
…nner.toml

Updated ws resolution from 8.18.3 to 8.22.0 to resolve GHSA-96hv-2xvq-fx4p
(ws server-side memory exhaustion DoS). The vulnerability required ws >= 8.21.0
for the fix. All ws instances across the monorepo are now using the patched
version, and the exclusion has been safely removed from osv-scanner.toml.

Verified that:
- OSV scanner no longer flags GHSA-96hv-2xvq-fx4p
- yarn check-deps passes
- No breaking changes introduced

Ticket: HSM-429

Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
@therealdwright
therealdwright force-pushed the osv-scanner-prune/ws-vulnerability-fix branch from 870e41a to 70262d6 Compare October 5, 2026 20:35
@gokulhost
gokulhost merged commit d14122b into master Oct 6, 2026
37 of 47 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated PR or process dependencies Pull requests that update a dependency file security Security-related changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants