Skip to content

[Snyk] Upgrade bybit-api from 4.2.1 to 4.3.1#31

Closed
tiagosiebler wants to merge 1 commit intomasterfrom
snyk-upgrade-0700c931ebc4e6c60cb9bdb1505a9c34
Closed

[Snyk] Upgrade bybit-api from 4.2.1 to 4.3.1#31
tiagosiebler wants to merge 1 commit intomasterfrom
snyk-upgrade-0700c931ebc4e6c60cb9bdb1505a9c34

Conversation

@tiagosiebler
Copy link
Member

snyk-top-banner

Snyk has created this PR to upgrade bybit-api from 4.2.1 to 4.3.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 8 versions ahead of your current version.

  • The recommended version was released 24 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-12613773
524 Proof of Concept
Release notes
Package name: bybit-api
  • 4.3.1 - 2025-09-12

    What's Changed

    • feat(v4.3.1): add new endpoints for limit price behavior and new delivery price by @ JJ-Cro in #485
    • feat(v4.3.1): add new endpoints for limit price behavior and new deli… by @ JJ-Cro in #489

    Full Changelog: v4.3.0...v4.3.1

  • 4.3.0 - 2025-09-05

    Summary

    Disabled by default to prevent any breaking changes. Enable it by passing this boolean in the REST client constructor:

    const client = new RestClientV5({
      key: key,
      secret: secret,
      throwExceptions: true,
    });

    Any retCode !== 0 response will be thrown in full, if enabled.

    What's Changed

    Full Changelog: v4.2.7...v4.3.0

  • 4.2.7 - 2025-08-25

    What's Changed

    • feat(v4.2.7): force ws request batching into groups of max 500 topics per batch by @ tiagosiebler in #479

    Full Changelog: v4.2.6...v4.2.7

  • 4.2.6 - 2025-08-25
    • Fixes deduping workflow introduced in previous release

    Full Changelog: v4.2.5...v4.2.6

  • 4.2.5 - 2025-08-25

    What's Changed

    This provides convenience in calling the subscribe method, where it will only emit subscribe events to bybit for the topics that haven't been subscribed to yet, preventing the scenario in #477 (which will cause non-duplicate topic subs to fail)

    Full Changelog: v4.2.4...v4.2.5

  • 4.2.4 - 2025-08-13

    What's Changed

    Full Changelog: v4.2.3...v4.2.4

  • 4.2.3 - 2025-08-12

    What's Changed

    Transitioned the release workflow to a token-less trusted publisher workflow, for a more secure way to publish new releases to npm.

    Historic Changelog

    Note: these are since the last "release" / tag on GitHub.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants