Skip to content

Commit eb78fd4

Browse files
committed
fix(ZMS): bump ws to 8.20.1 for CVE-2026-45736
Override jsdom's ws dependency in zmscitizenview to address medium-severity CVE-2026-45736 (DoS via unbounded HTTP upgrade headers).
1 parent b10592b commit eb78fd4

2 files changed

Lines changed: 6 additions & 3 deletions

File tree

zmscitizenview/package-lock.json

Lines changed: 3 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

zmscitizenview/package.json

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,10 +43,12 @@
4343
"vue-tsc": "^3.2.7"
4444
},
4545
"// overrides.@tootallnate/once": "local-web-server -> lws-rewrite -> http-proxy-agent pins once@2; force ^3.0.1 (abort-signal hang / GHSA).",
46+
"// overrides.ws": "jsdom -> ws@8.18.x; force ^8.20.1 (CVE-2026-45736).",
4647
"overrides": {
4748
"vite-plugin-vuetify": {
4849
"make-dir": "5.1.0"
4950
},
50-
"@tootallnate/once": "^3.0.1"
51+
"@tootallnate/once": "^3.0.1",
52+
"ws": "^8.20.1"
5153
}
5254
}

0 commit comments

Comments
 (0)