Skip to content

fix(deps): override ws to >=8.21.0 (CVE-2026-48779) - #145

Open
arc0btc wants to merge 1 commit into
mainfrom
fix/ws-cve-2026-48779
Open

fix(deps): override ws to >=8.21.0 (CVE-2026-48779)#145
arc0btc wants to merge 1 commit into
mainfrom
fix/ws-cve-2026-48779

Conversation

@arc0btc

@arc0btc arc0btc commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

Summary

Test plan

🤖 Generated with Claude Code

Dependabot alert #73: ws 8.18.0 (transitive, via miniflare/wrangler dev
dependency) is vulnerable per CVE-2026-48779. Adds an npm override
pinning ws >=8.21.0 without bumping wrangler itself, since the pending
wrangler major bump (PRs #141/#142/#143) is separately blocked on a
Cloudflare Workers Builds failure (#23977 tracks that).
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
x402-api-production 3f4cfce Jul 26 2026, 09:51 AM

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Updated (UTC)
✅ Deployment successful!
View logs
x402-api-staging 3f4cfce Jul 26 2026, 09:51 AM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant