Files
twenty/packages
Charles Bochet 1b26061992 security: close ws & file-type alerts via parent upgrades (no resolution) (#21417)
Closes 3 more Dependabot alerts via **parent upgrades only — no
`resolutions`**.

### Closes
- **ws #1238** (`>= 8.0.0, < 8.20.1`)
- **file-type #622** (`>= 13.0.0, < 21.3.1`) and **#635** (`>= 20.0.0,
<= 21.3.1`)

### How
- **ws** — two parents pinned vulnerable copies; both have safe
releases:
  - `wrangler`/`miniflare`: `ws 8.18.0 → 8.20.1`
  - `socket.io`/`engine.io`/`socket.io-adapter`: `ws ~8.17.1 → ~8.20.1`
  - Every `ws` now resolves `>= 8.20.1` (or non-vulnerable 6.x/7.x).
- **file-type** — bumped `@swc/cli ^0.7.10 → ^0.8.1`, which pulls the
newer `@xhmikosr` bin-wrapper → downloader → decompress/archive-type
chain (`file-type ^20.5.0 → ^21.3.x`). `@swc/cli` is a devDependency
that isn't directly invoked (nx's swc compiler uses `@swc/core`), so
this is dev-tooling-only with no runtime impact.

### Verification
- `yarn install --immutable` ✓ (passes the hardened 3-day age gate)
- No vulnerable `ws` (`< 8.20.1`) or `file-type` (`20.x`) remains in
`yarn.lock`

### Remaining open alerts (not closeable without a `resolution` or a
major migration)
- `apollo-server-core` (#735/#736) — needs Apollo Server 3 → 4
- `webpack-dev-server` (#1237/#691/#692) —
`@electron-forge/plugin-webpack` only pins `^4` (no stable v5 consumer);
dev-tooling
- `qs` (#1305) — `express`/`body-parser` pin `~6.14`, which has no
patched release
- `uuid` (#1289) — spread across many `^8`/`^9`/`^10` transitives; v11
is a breaking jump
- `postcss` (#1061) — bundled exact by `next` and `styled-components`
- `ajv` (#481) — `@cyntler/react-doc-viewer` pins `^7` (latest still
does)
2026-06-10 19:03:28 +02:00
..