From 16ad43410c6f71a7b079613b5cb858b587d17d76 Mon Sep 17 00:00:00 2001 From: Jonathan Norris Date: Mon, 25 May 2026 10:09:09 -0400 Subject: [PATCH 1/2] chore: resolve open dependabot security alerts Signed-off-by: Jonathan Norris --- package.json | 1 + yarn.lock | 8 ++++---- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/package.json b/package.json index 7f91e27c8..8029c557c 100644 --- a/package.json +++ b/package.json @@ -163,6 +163,7 @@ "yaml": "^2.8.3", "markdownlint-cli2/js-yaml": ">=4.1.1", "@docusaurus/theme-mermaid/mermaid": "^11.15.0", + "webpack-dev-server/ws": "^8.20.1", "styled-components/postcss": "^8.5.10", "webpack": "5.104.1", "fast-uri": ">=3.1.2", diff --git a/yarn.lock b/yarn.lock index 3cdee3da2..e40c97bd7 100644 --- a/yarn.lock +++ b/yarn.lock @@ -19118,9 +19118,9 @@ __metadata: languageName: node linkType: hard -"ws@npm:^8.18.0": - version: 8.18.3 - resolution: "ws@npm:8.18.3" +"ws@npm:^8.20.1": + version: 8.21.0 + resolution: "ws@npm:8.21.0" peerDependencies: bufferutil: ^4.0.1 utf-8-validate: ">=5.0.2" @@ -19129,7 +19129,7 @@ __metadata: optional: true utf-8-validate: optional: true - checksum: 10c0/eac918213de265ef7cb3d4ca348b891a51a520d839aa51cdb8ca93d4fa7ff9f6ccb339ccee89e4075324097f0a55157c89fa3f7147bde9d8d7e90335dc087b53 + checksum: 10c0/ef4a243476283fc49bc7550966c4af4aa0eef56273837211e700de3b664e08604a760cdddcb5ba43c049140e74ccfec5b0ee0bb439e08c2adf9138902fdde5f9 languageName: node linkType: hard From f5773ef367bb9bbc999a6f7691058746331ad00d Mon Sep 17 00:00:00 2001 From: Jonathan Norris Date: Tue, 26 May 2026 11:15:36 -0400 Subject: [PATCH 2/2] chore: use global ws resolution to cover all consumers Replace scoped webpack-dev-server/ws resolution with a global ws resolution so webpack-bundle-analyzer's ws@7.x instance is also patched to 8.21.0, as suggested in PR review. Signed-off-by: Jonathan Norris --- package.json | 2 +- yarn.lock | 15 --------------- 2 files changed, 1 insertion(+), 16 deletions(-) diff --git a/package.json b/package.json index 8029c557c..0361a8a93 100644 --- a/package.json +++ b/package.json @@ -163,7 +163,7 @@ "yaml": "^2.8.3", "markdownlint-cli2/js-yaml": ">=4.1.1", "@docusaurus/theme-mermaid/mermaid": "^11.15.0", - "webpack-dev-server/ws": "^8.20.1", + "ws": "^8.20.1", "styled-components/postcss": "^8.5.10", "webpack": "5.104.1", "fast-uri": ">=3.1.2", diff --git a/yarn.lock b/yarn.lock index e40c97bd7..9717d0ca0 100644 --- a/yarn.lock +++ b/yarn.lock @@ -19103,21 +19103,6 @@ __metadata: languageName: node linkType: hard -"ws@npm:^7.3.1": - version: 7.5.10 - resolution: "ws@npm:7.5.10" - peerDependencies: - bufferutil: ^4.0.1 - utf-8-validate: ^5.0.2 - peerDependenciesMeta: - bufferutil: - optional: true - utf-8-validate: - optional: true - checksum: 10c0/bd7d5f4aaf04fae7960c23dcb6c6375d525e00f795dd20b9385902bd008c40a94d3db3ce97d878acc7573df852056ca546328b27b39f47609f80fb22a0a9b61d - languageName: node - linkType: hard - "ws@npm:^8.20.1": version: 8.21.0 resolution: "ws@npm:8.21.0"