chore(deps): bump websocket-driver from 0.7.0 to 0.7.5#449
chore(deps): bump websocket-driver from 0.7.0 to 0.7.5#449dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [websocket-driver](https://github.com/faye/websocket-driver-node) from 0.7.0 to 0.7.5. - [Changelog](https://github.com/faye/websocket-driver-node/blob/main/CHANGELOG.md) - [Commits](faye/websocket-driver-node@0.7.0...0.7.5) --- updated-dependencies: - dependency-name: websocket-driver dependency-version: 0.7.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
[blocking] The primary Cursor model (composer-2.5) was unavailable for this run. This review ran on the fallback auto model instead. Automated formal Approve is withheld for this run; human approval is required before merge.
Scope
Dependabot lockfile-only bump: yarn.lock resolves transitive websocket-driver from 0.7.0 to 0.7.5 (via faye-websocket; no package.json or app source in changedFiles). Changelog notes max-length / draft-75/76 hardening and safer Buffer usage—worth merging for dependency hygiene once a human signs off.
Upstream: faye/websocket-driver-node 0.7.0…0.7.5
CI
CI is still pending (ciStatus.state: pending); not treated as a review blocker.
Regression risk
Patch-level 0.7.x bump on an indirect WebSocket helper used by the toolchain—low regression risk absent app code changes.
Automated Approve withheld solely due to the fallback-model governance rule above; no code or lockfile defects found.
Note: Requested Cursor model
composer-2.5was unavailable; review was generated usingautoinstead. Automated formal Approve is withheld for this run — human approval is required before merge.
This review was generated by review-bot.
Bumps websocket-driver from 0.7.0 to 0.7.5.
Changelog
Sourced from websocket-driver's changelog.
Commits
5d6a9aaBump version to 0.7.5c55679aFail the connection if a message is larger than the configured max length aft...5b197caClose a draft-75/76 connection if a length header grows to exceed the configu...fc93a48Test on Node v22, v24, and v262e82d34Test on recent versions of Nodee4962dbSwitch from Travis CI to GitHub Actions3f2f9b7Travis update: cache npm modules, remove sudo, run on Node 155f711f0Bump version to 0.7.417cf70fPin http-parser-js to version that fixes https://github.com/creationix/http-p...5c2a184Add Node versions 13 and 14 on TravisDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.