Skip to content

chore(deps): bump ws from 7.4.5 to 8.1.0 - #125

Closed
dependabot[bot] wants to merge 1 commit into
add-link-docsfrom
dependabot/npm_and_yarn/ws-8.1.0
Closed

chore(deps): bump ws from 7.4.5 to 8.1.0#125
dependabot[bot] wants to merge 1 commit into
add-link-docsfrom
dependabot/npm_and_yarn/ws-8.1.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 12, 2021

Copy link
Copy Markdown

Bumps ws from 7.4.5 to 8.1.0.

Release notes

Sourced from ws's releases.

8.1.0

Features

  • Added ability to skip UTF-8 validation (#1928).

Bug fixes

  • Fixed an issue with a breaking change in Node.js master (6a72da3e).
  • Fixed a misleading error message (c95e695d).

8.0.0

Breaking changes

  • The WebSocket constructor now throws a SyntaxError if any of the subprotocol names are invalid or duplicated (0aecf0c9).

  • The server now aborts the opening handshake if an invalid Sec-WebSocket-Protocol header field value is received (1877ddeb).

  • The protocols argument of handleProtocols hook is no longer an Array but a Set (1877ddeb).

  • The opening handshake is now aborted if the Sec-WebSocket-Extensions header field value is empty or it begins or ends with a white space (e814110e).

  • Dropped support for Node.js < 10.0.0 (552b5067).

  • The WebSocket constructor now throws a SyntaxError if the connection URL contains a fragment identifier or if the URL's protocol is not one of 'ws:', 'wss:', or 'ws+unix:' (ebea038f).

  • Text messages and close reasons are no longer decoded to strings. They are passed as Buffers to the listeners of their respective events. The listeners of the 'message' event now take a boolean argument specifying whether or not the message is binary (e173423c).

    Existing code can be migrated by decoding the buffer explicitly.

    websocket.on('message',functionmessage(data,isBinary){constmessage=isBinary ? data : data.toString();// Continue as before.});websocket.on('close',functionclose(code,data){constreason=data.toString();// Continue as before.});

  • The package now uses an ES module wrapper (78adf5f7).

  • WebSocketServer.prototype.close() no longer closes existing connections (df7de574).

    Existing code can be migrated by closing the connections manually.

... (truncated)

Commits
  • 142f091 [dist] 8.1.0
  • d21c810 [feature] Add ability to skip UTF-8 validation (#1928)
  • 9bd3bd1 [minor] Fix typo (#1929)
  • 1e938f1 [major] Use an options object instead of positional arguments
  • 7f0b5c4 [example] Update uuid to version 8.3.2
  • fd47c96 [test] Move code block closer to where it is used
  • c95e695 [fix] Fix misleading error message
  • 6a72da3 [fix] Do not rely on undocumented behavior
  • 04e74a1 [license] Fix license text
  • fc40248 [dist] 8.0.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ws](https://github.com/websockets/ws) from 7.4.5 to 8.1.0.
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@7.4.5...8.1.0)
---
updated-dependencies:
- dependency-name: ws
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 12, 2021
@dependabot@github

dependabotBot commented on behalf of githubAug 12, 2021

Copy link
Copy Markdown
Author

Dependabot tried to add @jawnsy as a reviewer to this PR, but received the following error from GitHub:

POST https://api.github.com/repos/majacQ/code-server/pulls/125/requested_reviewers: 422 - Reviews may only be requested from collaborators. One or more of the users or teams you specified is not a collaborator of the majacQ/code-server repository. // See: https://docs.github.com/rest/reference/pulls#request-reviewers-for-a-pull-request

@atomistatomistBot added auto-branch-delete:on-close Delete branch when pull request gets closed auto-merge-method:merge Auto-merge with merge commit auto-merge:on-bpr-success Auto-merge on passed branch protection rule labels Aug 12, 2021
@dependabot@github

dependabotBot commented on behalf of githubAug 18, 2021

Copy link
Copy Markdown
Author

Superseded by #129.

@dependabotdependabotBot closed this Aug 18, 2021
@dependabot
dependabotBot deleted the dependabot/npm_and_yarn/ws-8.1.0 branch August 18, 2021 11:19
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-branch-delete:on-closeDelete branch when pull request gets closedauto-merge:on-bpr-successAuto-merge on passed branch protection ruleauto-merge-method:mergeAuto-merge with merge commitdependenciesPull requests that update a dependency filejavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants