Skip to content

Bump ws to 8.20.1 in yoga yarn.lock (CVE-2026-45736) (#1982)#1982

Closed
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D108618638
Closed

Bump ws to 8.20.1 in yoga yarn.lock (CVE-2026-45736) (#1982)#1982
rozele wants to merge 1 commit into
react:mainfrom
rozele:export-D108618638

Conversation

@rozele

@rozele rozele commented Jun 29, 2026

Copy link
Copy Markdown
Contributor

Summary:

Remediates a medium-severity security vulnerability in the ws npm package reported for the facebook/yoga repository (GHSA-58qx-3vcg-4xpx / CVE-2026-45736), which affects ws >= 8.0.0, < 8.20.1.

Updates the ws@^8.13.0, ws@^8.19.0 entry in xplat/yoga/yarn.lock from 8.19.0 to the fixed 8.20.1, including the new resolved URL and integrity hash from the npm registry. Both existing semver ranges are satisfied by 8.20.1, so no package.json change is needed. ws is a transitive dependency.

The separate ws@^7.3.1 (7.5.10) entry is below 8.0.0 and is not affected, so it is left unchanged.

Reviewed By: javache

Differential Revision: D108618638

@meta-cla meta-cla Bot added the CLA Signed label Jun 29, 2026
@meta-codesync

meta-codesync Bot commented Jun 29, 2026

Copy link
Copy Markdown

@rozele has exported this pull request. If you are a Meta employee, you can view the originating Diff in D108618638.

@meta-codesync meta-codesync Bot changed the title Bump ws to 8.20.1 in yoga yarn.lock (CVE-2026-45736) Bump ws to 8.20.1 in yoga yarn.lock (CVE-2026-45736) (#1982) Jun 29, 2026
rozele added a commit to rozele/yoga that referenced this pull request Jun 29, 2026
Summary:

Remediates a medium-severity security vulnerability in the `ws` npm package reported for the `facebook/yoga` repository (GHSA-58qx-3vcg-4xpx / CVE-2026-45736), which affects `ws >= 8.0.0, < 8.20.1`.

Updates the `ws@^8.13.0, ws@^8.19.0` entry in `xplat/yoga/yarn.lock` from `8.19.0` to the fixed `8.20.1`, including the new `resolved` URL and `integrity` hash from the npm registry. Both existing semver ranges are satisfied by `8.20.1`, so no `package.json` change is needed. `ws` is a transitive dependency.

The separate `ws@^7.3.1` (7.5.10) entry is below 8.0.0 and is not affected, so it is left unchanged.

[Session trajectory link](https://www.internalfb.com/intern/devai/devmate/inspector/?id=3a743029-22e2-40b2-b607-a8e40d18b255)

Reviewed By: javache

Differential Revision: D108618638
@rozele rozele force-pushed the export-D108618638 branch from 18bb132 to 00a11e0 Compare June 29, 2026 14:35
Summary:

Remediates a medium-severity security vulnerability in the `ws` npm package reported for the `facebook/yoga` repository (GHSA-58qx-3vcg-4xpx / CVE-2026-45736), which affects `ws >= 8.0.0, < 8.20.1`.

Updates the `ws@^8.13.0, ws@^8.19.0` entry in `xplat/yoga/yarn.lock` from `8.19.0` to the fixed `8.20.1`, including the new `resolved` URL and `integrity` hash from the npm registry. Both existing semver ranges are satisfied by `8.20.1`, so no `package.json` change is needed. `ws` is a transitive dependency.

The separate `ws@^7.3.1` (7.5.10) entry is below 8.0.0 and is not affected, so it is left unchanged.

[Session trajectory link](https://www.internalfb.com/intern/devai/devmate/inspector/?id=3a743029-22e2-40b2-b607-a8e40d18b255)

Reviewed By: javache

Differential Revision: D108618638
@rozele rozele force-pushed the export-D108618638 branch from 00a11e0 to a67ac7d Compare June 29, 2026 14:36
@rozele rozele closed this Jun 29, 2026
rozele added a commit to rozele/yoga that referenced this pull request Jun 29, 2026
Summary:

Remediates a medium-severity security vulnerability in the `ws` npm package reported for the `facebook/yoga` repository (GHSA-58qx-3vcg-4xpx / CVE-2026-45736), which affects `ws >= 8.0.0, < 8.20.1`.

Updates the `ws@^8.13.0, ws@^8.19.0` entry in `xplat/yoga/yarn.lock` from `8.19.0` to the fixed `8.20.1`, including the new `resolved` URL and `integrity` hash from the npm registry. Both existing semver ranges are satisfied by `8.20.1`, so no `package.json` change is needed. `ws` is a transitive dependency.

The separate `ws@^7.3.1` (7.5.10) entry is below 8.0.0 and is not affected, so it is left unchanged.

Reviewed By: javache

Differential Revision: D108618638
rozele added a commit to rozele/yoga that referenced this pull request Jun 29, 2026
Summary:
Pull Request resolved: react#1983

Pull Request resolved: react#1982

Remediates a medium-severity security vulnerability in the `ws` npm package reported for the `facebook/yoga` repository (GHSA-58qx-3vcg-4xpx / CVE-2026-45736), which affects `ws >= 8.0.0, < 8.20.1`.

Updates the `ws@^8.13.0, ws@^8.19.0` entry in `xplat/yoga/yarn.lock` from `8.19.0` to the fixed `8.20.1`, including the new `resolved` URL and `integrity` hash from the npm registry. Both existing semver ranges are satisfied by `8.20.1`, so no `package.json` change is needed. `ws` is a transitive dependency.

The separate `ws@^7.3.1` (7.5.10) entry is below 8.0.0 and is not affected, so it is left unchanged.

Reviewed By: javache

Differential Revision: D108618638
meta-codesync Bot pushed a commit that referenced this pull request Jun 29, 2026
Summary:
Pull Request resolved: #1983

Pull Request resolved: #1982

Remediates a medium-severity security vulnerability in the `ws` npm package reported for the `facebook/yoga` repository (GHSA-58qx-3vcg-4xpx / CVE-2026-45736), which affects `ws >= 8.0.0, < 8.20.1`.

Updates the `ws@^8.13.0, ws@^8.19.0` entry in `xplat/yoga/yarn.lock` from `8.19.0` to the fixed `8.20.1`, including the new `resolved` URL and `integrity` hash from the npm registry. Both existing semver ranges are satisfied by `8.20.1`, so no `package.json` change is needed. `ws` is a transitive dependency.

The separate `ws@^7.3.1` (7.5.10) entry is below 8.0.0 and is not affected, so it is left unchanged.

Reviewed By: javache

Differential Revision: D108618638

fbshipit-source-id: 676cc59b44754e5d2b36d3eb99bacf66d1b19749
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant