Skip to content

Update dependency subscriptions-transport-ws to v0.9.19#109

Open
mend-for-github-com[bot] wants to merge 1 commit intoalphafrom
whitesource-remediate/subscriptions-transport-ws-0.x-lockfile
Open

Update dependency subscriptions-transport-ws to v0.9.19#109
mend-for-github-com[bot] wants to merge 1 commit intoalphafrom
whitesource-remediate/subscriptions-transport-ws-0.x-lockfile

Conversation

@mend-for-github-com
Copy link
Copy Markdown

@mend-for-github-com mend-for-github-com bot commented Nov 4, 2025

This PR contains the following updates:

Package Type Update Change
subscriptions-transport-ws dependencies patch 0.9.160.9.19

By merging this PR, the issue #101 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
High High 7.5 CVE-2024-37890

Unreachable

Medium Medium 5.3 CVE-2021-32640

Unreachable


Release Notes

apollostack/subscriptions-transport-ws (subscriptions-transport-ws)

v0.9.19

Compare Source

  • Bump ws dependency to allow v6 and v7. Note that there are breaking changes in ws 6.0.0 and 7.0.0; for example, messages over 100MiB are rejected, and (in v7) the behavior of sending messages while the connection is starting or ending has changed. We are publishing this package to allow users of Apollo Server 2 to avoid seeing this CVE in their npm audit. However, note that (a) this CVE does not affect the subscriptions client, just the server and (b) Apollo Server 3 will remove its superficial integration with this package entirely. We encourage users of Apollo Server 2 to disable the integration with this unmaintained package via new ApolloServer({subscriptions: false}), and consider packages such as graphql-ws to power GraphQL subscriptions until such time as Apollo Server has more fully integrated subscriptions support.

v0.9.18

Compare Source

Bug Fixes
New Features

v0.9.17

Compare Source


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Nov 4, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/subscriptions-transport-ws-0.x-lockfile branch from bee9d77 to 3f84ece Compare December 29, 2025 14:33
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/subscriptions-transport-ws-0.x-lockfile branch from 3f84ece to 813bf61 Compare January 22, 2026 14:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants