Skip to content

chore(deps): bump ws to 8.22.0, drop GHSA-96hv-2xvq-fx4p from osv-scanner.toml - #9889

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
osv-scanner-prune/ws-vulnerability-fix
Open

github-actions[bot] wants to merge 1 commit into
masterfrom
osv-scanner-prune/ws-vulnerability-fix

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Summary

• Bumped ws from 8.18.3 to 8.22.0 to resolve GHSA-96hv-2xvq-fx4p (ws server-side memory exhaustion DoS)
• Removed GHSA-96hv-2xvq-fx4p exclusion from osv-scanner.toml as it is now fixed
• Updated all ws resolution entries to use the patched version

Test plan

  • OSV scanner no longer flags GHSA-96hv-2xvq-fx4p vulnerability
  • yarn check-deps passes successfully
  • No breaking changes introduced (ws 8.22.0 is compatible)
  • All ws instances across monorepo now use patched version

OSV Scanner Results

The audit now passes for GHSA-96hv-2xvq-fx4p. Previous scan showed:

| https://osv.dev/GHSA-96hv-2xvq-fx4p | 7.5  | npm       | ws                            | 5.2.4    | yarn.lock |
| https://osv.dev/GHSA-96hv-2xvq-fx4p | 7.5  | npm       | ws                            | 7.5.10   | yarn.lock |
| https://osv.dev/GHSA-96hv-2xvq-fx4p | 7.5  | npm       | ws                            | 8.17.1   | yarn.lock |

Current scan shows no GHSA-96hv-2xvq-fx4p entries (vulnerability resolved).

Still blocked exclusions

Other exclusions remain due to:

  • tar 6.2.1: Required for lerna v9 compatibility (tar 7.x breaks lerna packDirectory)
  • minimatch: Version 10.x breaks lerna v9 API
  • sjcl: No upstream fix available (first_patched_version: null)
  • form-data: Requires investigation of newer versions
  • extract-zip, braces, http-cache-semantics, node-forge: No upstream fixes available

🤖 Generated with Claude Code

…nner.toml

Updated ws resolution from 8.18.3 to 8.22.0 to resolve GHSA-96hv-2xvq-fx4p
(ws server-side memory exhaustion DoS). The vulnerability required ws >= 8.21.0
for the fix. All ws instances across the monorepo are now using the patched
version, and the exclusion has been safely removed from osv-scanner.toml.

Verified that:
- OSV scanner no longer flags GHSA-96hv-2xvq-fx4p
- yarn check-deps passes
- No breaking changes introduced

Ticket: HSM-429

Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
@github-actions
github-actions Bot requested review from a team as code owners October 5, 2026 06:32
@github-actions github-actions Bot added automated Automated PR or process dependencies Pull requests that update a dependency file security Security-related changes labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated PR or process dependencies Pull requests that update a dependency file security Security-related changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants