chore(deps): bump ws and engine.io-client#1921
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
c989ecb to
ebe8ec8
Compare
Bumps [ws](https://github.com/websockets/ws) and [engine.io-client](https://github.com/socketio/socket.io). These dependencies needed to be updated together. Updates `ws` from 8.20.1 to 8.21.0 - [Release notes](https://github.com/websockets/ws/releases) - [Commits](websockets/ws@8.20.1...8.21.0) Updates `engine.io-client` from 6.6.5 to 6.6.6 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/compare/engine.io-client@6.6.5...engine.io-client@6.6.6) --- updated-dependencies: - dependency-name: engine.io-client dependency-version: 6.6.6 dependency-type: indirect - dependency-name: ws dependency-version: 8.21.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
ebe8ec8 to
9f12501
Compare
enyst
left a comment
There was a problem hiding this comment.
🟢 Good taste
Supply-chain review: engine.io-client 6.6.6 and ws 8.21.0 were published 2026-06-16 and 2026-06-09; publishers and maintainers are continuous, the signed Socket.IO tag exists, and no install hooks were added. CI is green, and the diff is limited to the expected dependency and lockfile changes.
[RISK ASSESSMENT]
- [Overall PR]
⚠️ Risk Assessment: 🟢 LOW
The release is older than the seven-day guardrail, has normal publisher/source continuity, and introduces no suspicious lifecycle behavior.
VERDICT: ✅ Worth merging
KEY INSIGHT: The published artifact and source provenance are consistent with a routine upstream release.
This review was generated by an AI agent (OpenHands) on behalf of the reviewer.
✅ Mock-LLM Docker E2E Test Results60/60 passed Commit: Details
Posted by the Mock-LLM E2E workflow · results are deterministic (scripted LLM responses) |
✅ Mock-LLM E2E Tests60/60 passed Commit: Details
Posted by the Mock-LLM E2E workflow · results are deterministic (scripted LLM responses) |
Bumps ws and engine.io-client. These dependencies needed to be updated together.
Updates
wsfrom 8.20.1 to 8.21.0Release notes
Sourced from ws's releases.
Commits
bca91ad[dist] 8.21.02b2abd4[security] Limit retained message parts78eabe2[security] Add latest vulnerability to SECURITY.mdUpdates
engine.io-clientfrom 6.6.5 to 6.6.6Release notes
Sourced from engine.io-client's releases.
Commits
22cc483chore(release): engine.io-client@6.6.69dbec81chore(release): engine.io@6.6.93ad4e1fdocs: improve example with PM20e5afeedocs: add example with PM2eab9623docs(eio): correct maxHttpBufferSize default in JSDoc (#5508)c17890cdocs: add documentation about WebTransport20df6aedocs(examples): add client-side load balancing example16d1923ci(publish): enable staged publishingad48a9bdocs(examples): add example with HTTP/2190572drefactor(eio-client): remove XMLHttpRequest from the definition file🐳 Docker images for this PR
• GHCR package: https://github.com/OpenHands/agent-canvas/pkgs/container/agent-canvas
ghcr.io/openhands/agent-canvasghcr.io/openhands/agent-server:1.37.0-pythonopenhands-automation==1.3.1cc2238a66a843164803ddde70c0780d6c65849d5Pull (multi-arch manifest)
# Multi-arch manifest — Docker automatically pulls the correct architecture docker pull ghcr.io/openhands/agent-canvas:sha-cc2238aRun
All tags pushed for this build
About Multi-Architecture Support
sha-cc2238a) is a multi-arch manifest supporting both amd64 and arm64sha-cc2238a-amd64) are also available if needed