# What would be the impact of upgrading ws 1.1.5, a dependency of node-red? (ws has a known high vulnerability)

**URL:** <https://discourse.nodered.org/t/what-would-be-the-impact-of-upgrading-ws-1-1-5-a-dependency-of-node-red-ws-has-a-known-high-vulnerability/8697>\
**Category:** General\
**Created:** [7 March 2019 09:31 UTC](https://discourse.nodered.org/t/what-would-be-the-impact-of-upgrading-ws-1-1-5-a-dependency-of-node-red-ws-has-a-known-high-vulnerability/8697 "2019-03-07T09:31:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pkorecki](https://avatars.discourse-cdn.com/v4/letter/p/f14d63/32.png) [@pkorecki](https://discourse.nodered.org/u/pkorecki)\
**Post date:** [7 March 2019 09:31 UTC](https://discourse.nodered.org/t/what-would-be-the-impact-of-upgrading-ws-1-1-5-a-dependency-of-node-red-ws-has-a-known-high-vulnerability/8697/1 "2019-03-07T09:31:57Z")

</div>

Hello,  
In a project I am working on we're using node-red in order to extend project's capabilities.  
The final docker image is scanned with different tools to identify security vulnerabilities, and one of reported high vulnerabilities is related to ws 1.1.5 library (a dependency of node-red).  
Deatils can be found here: [https://www.npmjs.com/advisories/550](https://www.npmjs.com/advisories/550)

What would be the impact of upgrading [ws from 1.1.5](https://github.com/node-red/node-red/blob/d8b4c1e20948f3d9d6692ae500e8864fe30358a6/package.json#L79) to a non-vulnerable version ( minimum 3.3.1, latest version is 6.2.0 ) ?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [7 March 2019 10:01 UTC](https://discourse.nodered.org/t/what-would-be-the-impact-of-upgrading-ws-1-1-5-a-dependency-of-node-red-ws-has-a-known-high-vulnerability/8697/2 "2019-03-07T10:01:18Z")

</div>

Hi @pkorecki

there were very significant changes to the `ws` library from version 1.x up to its latest 6.x stream. It requires a lot of changes in the node-red code base to support.

The good news is 0.20 has had those changes applied and will be available in the next couple of days (all being well...).

---

<div class="post-metadata">

**Author:** ![pkorecki](https://avatars.discourse-cdn.com/v4/letter/p/f14d63/32.png) [@pkorecki](https://discourse.nodered.org/u/pkorecki)\
**Post date:** [7 March 2019 10:24 UTC](https://discourse.nodered.org/t/what-would-be-the-impact-of-upgrading-ws-1-1-5-a-dependency-of-node-red-ws-has-a-known-high-vulnerability/8697/3 "2019-03-07T10:24:46Z")

</div>

Thanks for quick answer!
