Commit ef15ca8
committed
chore(deps): bump transitive ws 8.20.0 -> 8.21.0 to clear GHSA-58qx-3vcg-4xpx
Lockfile-only refresh via npm audit fix. ws is pulled in transitively by
mqtt@5.15.1; cgateweb does not use ws directly (MQTT broker connections go
over TCP, not WebSocket), so real-world exposure to the uninitialized-
memory-disclosure advisory was negligible. Closing the alert anyway.
ip-address also bumped 10.1.0 -> 10.2.0 as a co-incident transitive
update; no advisory but the new version was the only resolution npm
could produce while keeping the lockfile consistent.
No package.json or source changes; npm test still passes (1228/1228).1 parent f25f17f commit ef15ca8
1 file changed
Lines changed: 5 additions & 5 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments