Skip to content

fix(engine-bridge): patch ws high-severity CVEs - #172

Merged
N-thnI merged 1 commit into
mainfrom
fix/engine-bridge-ws-cve
Aug 5, 2026
Merged

fix(engine-bridge): patch ws high-severity CVEs#172
N-thnI merged 1 commit into
mainfrom
fix/engine-bridge-ws-cve

Conversation

@N-thnI

@N-thnI N-thnI commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Bumps ws in engine-bridge from 8.18.0 to ^8.21.2, resolving two high-severity advisories (GHSA-58qx-3vcg-4xpx uninitialized memory disclosure, GHSA-96hv-2xvq-fx4p memory exhaustion DoS).
  • npm audit now reports 0 vulnerabilities in engine-bridge.

Test plan

  • npm run build (tsc) passes
  • npm test — 71/71 tests pass
  • cargo build --workspace --all-targets unaffected (no Rust changes)

@N-thnI
N-thnI force-pushed the fix/engine-bridge-ws-cve branch from f855ebb to ce6d0c6 Compare August 5, 2026 11:37
@N-thnI
N-thnI merged commit 7b9f658 into main Aug 5, 2026
3 checks passed
@N-thnI
N-thnI deleted the fix/engine-bridge-ws-cve branch August 5, 2026 11:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant