127.md (3175B)
1 # PR #127 chore(deps): bump ws from 1.1.4 to 1.1.5 2 3 - **Status:** open 4 - **Author:** @dependabot[bot] 5 - **Created:** 2019-12-10T01:37:43Z 6 - **Branch:** dependabot/npm_and_yarn/ws-1.1.5 → master 7 - **Labels:** dependencies 8 - **Diff:** [127.diff](./127.diff) 9 10 --- 11 12 Bumps [ws](https://github.com/websockets/ws) from 1.1.4 to 1.1.5. 13 <details> 14 <summary>Release notes</summary> 15 16 *Sourced from [ws's releases](https://github.com/websockets/ws/releases).* 17 18 > ## 1.1.5 19 > # Bug fixes 20 > 21 > - Fixed a DoS vulnerability (f8fdcd4). 22 </details> 23 <details> 24 <summary>Commits</summary> 25 26 - [`24edef5`](https://github.com/websockets/ws/commit/24edef58a0aab05e8220f76bd2377614dd4eee85) [dist] 1.1.5 27 - [`f8fdcd4`](https://github.com/websockets/ws/commit/f8fdcd40ac8be7318a6ee41f5ceb7e77c995b407) [security] Fix DoS vulnerability 28 - [`f7cfc51`](https://github.com/websockets/ws/commit/f7cfc51a9f4364c80d43329e8e604aff00e89e2a) [pkg] Remove .npmignore in favor of `files` package.json field 29 - See full diff in [compare view](https://github.com/websockets/ws/compare/1.1.4...1.1.5) 30 </details> 31 <br /> 32 33 [](https://help.github.com/articles/configuring-automated-security-fixes) 34 35 Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. 36 37 [//]: # (dependabot-automerge-start) 38 [//]: # (dependabot-automerge-end) 39 40 --- 41 42 <details> 43 <summary>Dependabot commands and options</summary> 44 <br /> 45 46 You can trigger Dependabot actions by commenting on this PR: 47 - `@dependabot rebase` will rebase this PR 48 - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it 49 - `@dependabot merge` will merge this PR after your CI passes on it 50 - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it 51 - `@dependabot cancel merge` will cancel a previously requested merge and block automerging 52 - `@dependabot reopen` will reopen this PR if it is closed 53 - `@dependabot ignore this [patch|minor|major] version` will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself) 54 - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) 55 - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language 56 - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language 57 - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language 58 - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language 59 60 You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/MTRNord/freifunk-bot/network/alerts). 61 62 </details> 63