127.json (3414B)
1 { 2 "number": 127, 3 "title": "chore(deps): bump ws from 1.1.4 to 1.1.5", 4 "state": "open", 5 "diff_file": "127.diff", 6 "author": "dependabot[bot]", 7 "created_at": "2019-12-10T01:37:43Z", 8 "closed_at": null, 9 "merged_at": null, 10 "base_ref": "master", 11 "head_ref": "dependabot/npm_and_yarn/ws-1.1.5", 12 "labels": [ 13 "dependencies" 14 ], 15 "assignees": [], 16 "requested_reviewers": [], 17 "body": "Bumps [ws](https://github.com/websockets/ws) from 1.1.4 to 1.1.5.\n<details>\n<summary>Release notes</summary>\n\n*Sourced from [ws's releases](https://github.com/websockets/ws/releases).*\n\n> ## 1.1.5\n> # Bug fixes\r\n> \r\n> - Fixed a DoS vulnerability (f8fdcd4).\n</details>\n<details>\n<summary>Commits</summary>\n\n- [`24edef5`](https://github.com/websockets/ws/commit/24edef58a0aab05e8220f76bd2377614dd4eee85) [dist] 1.1.5\n- [`f8fdcd4`](https://github.com/websockets/ws/commit/f8fdcd40ac8be7318a6ee41f5ceb7e77c995b407) [security] Fix DoS vulnerability\n- [`f7cfc51`](https://github.com/websockets/ws/commit/f7cfc51a9f4364c80d43329e8e604aff00e89e2a) [pkg] Remove .npmignore in favor of `files` package.json field\n- See full diff in [compare view](https://github.com/websockets/ws/compare/1.1.4...1.1.5)\n</details>\n<br />\n\n[](https://help.github.com/articles/configuring-automated-security-fixes)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n<details>\n<summary>Dependabot commands and options</summary>\n<br />\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot merge` will merge this PR after your CI passes on it\n- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it\n- `@dependabot cancel merge` will cancel a previously requested merge and block automerging\n- `@dependabot reopen` will reopen this PR if it is closed\n- `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language\n- `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language\n- `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language\n- `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language\n\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/MTRNord/freifunk-bot/network/alerts).\n\n</details>", 18 "comments": [], 19 "review_comments": [] 20 }