From 4d736b681d4c86a8e4806eb02c2dfe778be9548e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 21 Jul 2026 12:03:45 -0500 Subject: [PATCH] build(deps): bump ws from 8.19.0 to 8.21.1 (#9891) Bumps [ws](https://github.com/websockets/ws) from 8.19.0 to 8.21.1.
Release notes

Sourced from ws's releases.

8.21.1

Bug fixes

8.21.0

Features

Bug fixes

A high volume of tiny fragments and data chunks could be sent by a peer, using modest network traffic, to crash a ws server or client due to OOM.

import { WebSocket, WebSocketServer } from 'ws';

const wss = new WebSocketServer({ port: 0 }, function () { const data = Buffer.alloc(1); const options = { fin: false }; const { port } = wss.address(); const ws = new WebSocket(ws://localhost:${port});

ws.on('open', function () { (function send() { ws.send(data, options, function (err) { if (err) return; send(); }); })(); });

ws.on('error', console.error); ws.on('close', function (code, reason) { console.log(client close - code: ${code} reason: ${reason.toString()}); }); });

wss.on('connection', function (ws) { ws.on('error', console.error); ws.on('close', function (code, reason) { console.log(server close - code: ${code} reason: ${reason.toString()}); }); });

... (truncated)

Commits

[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ws&package-manager=npm_and_yarn&previous-version=8.19.0&new-version=8.21.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) ---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- .../adapters/openclaw-gateway/package.json | 2 +- pnpm-lock.yaml | 30 +++++-------------- server/package.json | 2 +- 3 files changed, 10 insertions(+), 24 deletions(-) diff --git a/packages/adapters/openclaw-gateway/package.json b/packages/adapters/openclaw-gateway/package.json index 4e0e031189..e38fc1ea60 100644 --- a/packages/adapters/openclaw-gateway/package.json +++ b/packages/adapters/openclaw-gateway/package.json @@ -52,7 +52,7 @@ "dependencies": { "@paperclipai/adapter-utils": "workspace:*", "picocolors": "^1.1.1", - "ws": "^8.19.0" + "ws": "^8.21.1" }, "devDependencies": { "@types/node": "^22.19.21", diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index d92bdae27f..2396482fdf 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -282,8 +282,8 @@ importers: specifier: ^1.1.1 version: 1.1.1 ws: - specifier: ^8.19.0 - version: 8.19.0 + specifier: ^8.21.1 + version: 8.21.1 devDependencies: '@types/node': specifier: ^22.19.21 @@ -822,8 +822,8 @@ importers: specifier: ^1.17.0 version: 1.17.0 ws: - specifier: ^8.19.0 - version: 8.19.0 + specifier: ^8.21.1 + version: 8.21.1 zod: specifier: ^3.24.2 version: 3.25.76 @@ -8353,20 +8353,8 @@ packages: wrappy@1.0.2: resolution: {integrity: sha512-l4Sp/DRseor9wL6EvV2+TuQn63dMkPjZ/sp9XkghTEbV9KlPS1xUsZ3u7/IQO4wxtcFB4bgpQPRcR3QCvezPcQ==} - ws@8.19.0: - resolution: {integrity: sha512-blAT2mjOEIi0ZzruJfIhb3nps74PRWTCz1IjglWEEpQl5XS/UNama6u2/rjFkDDouqr4L67ry+1aGIALViWjDg==} - engines: {node: '>=10.0.0'} - peerDependencies: - bufferutil: ^4.0.1 - utf-8-validate: '>=5.0.2' - peerDependenciesMeta: - bufferutil: - optional: true - utf-8-validate: - optional: true - - ws@8.21.0: - resolution: {integrity: sha512-Vsp28b7DRcimFQvrqu2Wek3z1iYxDCWqHYB8Qsnk/S4RfaCQzPGPyBNuVjJV3cd6UiKtUtp6sNM77gWvzcCH+g==} + ws@8.21.1: + resolution: {integrity: sha512-+0NTnW77fFN/DjQi6k/Sq/Yvk4Sgajw7urW8V+asjXnRgDs9gyGkdb7EzgfhA4goXsRIZKE28fzIXBHEzhuiWw==} engines: {node: '>=10.0.0'} peerDependencies: bufferutil: ^4.0.1 @@ -15994,7 +15982,7 @@ snapshots: recast: 0.23.12 semver: 7.8.5 use-sync-external-store: 1.6.0(react@19.2.7) - ws: 8.21.0 + ws: 8.21.1 optionalDependencies: '@types/react': 19.2.17 transitivePeerDependencies: @@ -16623,9 +16611,7 @@ snapshots: wrappy@1.0.2: {} - ws@8.19.0: {} - - ws@8.21.0: {} + ws@8.21.1: {} wsl-utils@0.1.0: dependencies: diff --git a/server/package.json b/server/package.json index 381824bcaf..6f6215d679 100644 --- a/server/package.json +++ b/server/package.json @@ -77,7 +77,7 @@ "pino-pretty": "^13.1.3", "sharp": "^0.35.3", "ssh2": "^1.17.0", - "ws": "^8.19.0", + "ws": "^8.21.1", "zod": "^3.24.2" }, "devDependencies": {