• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

zwave-js / zwave-js-ui / 37693373772
13%

Build:
DEFAULT BRANCH: master
Ran 07 Oct 2026 10:02PM UTC
Jobs 1
Files 46
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

07 Oct 2026 10:00PM UTC coverage: 13.161%. Remained the same
37693373772

push

github

web-flow
chore(deps): update dependency compression to v1.8.2 (#4849)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [compression](https://redirect.github.com/expressjs/compression) |
[`1.8.1` →
`1.8.2`](https://renovatebot.com/diffs/npm/compression/1.8.1/1.8.2) |
![age](https://developer.mend.io/api/mc/badges/age/npm/compression/1.8.2?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/compression/1.8.1/1.8.2?slim=true)
|

---

### compression vulnerable to Denial of Service via memory leak on
premature response close
[CVE-2026-87776](https://nvd.nist.gov/vuln/detail/CVE-2026-87776) /
[GHSA-vc2v-76pw-4v95](https://redirect.github.com/advisories/GHSA-vc2v-76pw-4v95)

<details>
<summary>More information</summary>

#### Details
##### Impact

A vulnerability in compression `< 1.8.2` allows an attacker to trigger a
Denial of Service (DoS) by disconnecting while a compressed response is
being sent. When the client aborts the connection before the response
finishes, the zlib stream created to compress that response is never
destroyed, so each aborted compressed response leaks its native zlib
memory. Repeated aborted requests can exhaust available memory. All
applications using compression are affected.

##### Patches

Users should upgrade to `1.8.2`.

##### Workarounds

None.

#### Severity
- CVSS Score: 7.5 / 10 (High)
- Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`

#### References
-
[https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95](https://redirect.github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95)
-
[https://nvd.nist.gov/vuln/detail/CVE-2026-87776](https://nvd.nist.gov/vuln/detail/CVE-2026-87776)
-
[https://github.com/expressjs/compression/commit/151f63e91](https://redirect.githu... (continued)

537 of 4566 branches covered (11.76%)

Branch coverage included in aggregate %.

991 of 7044 relevant lines covered (14.07%)

2.2 hits per line

Jobs
ID Job ID Ran Files Coverage
1 37693373772.1 07 Oct 2026 10:02PM UTC 46
13.16
GitHub Action Run
Source Files on build 37693373772
  • Tree
  • List 46
  • Changed 0
  • Source Changed 0
  • Coverage Changed 0
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #37693373772
  • 18cc89f7 on github
  • Prev Build on master (#37630009221)
  • Next Build on master (#37741894635)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc