Skip to content

[Snyk] Upgrade bybit-api from 4.2.1 to 4.4.0#33

Merged
tiagosiebler merged 1 commit intomasterfrom
snyk-upgrade-4b7cb656d1ef0ebcfe810d330a048b55
Jan 15, 2026
Merged

[Snyk] Upgrade bybit-api from 4.2.1 to 4.4.0#33
tiagosiebler merged 1 commit intomasterfrom
snyk-upgrade-4b7cb656d1ef0ebcfe810d330a048b55

Conversation

@tiagosiebler
Copy link
Member

snyk-top-banner

Snyk has created this PR to upgrade bybit-api from 4.2.1 to 4.4.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 10 versions ahead of your current version.

  • The recommended version was released 22 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Allocation of Resources Without Limits or Throttling
SNYK-JS-AXIOS-12613773
452 Proof of Concept
Release notes
Package name: bybit-api
  • 4.4.0 - 2025-10-13

    What's Changed

    Full Changelog: v4.3.2...v4.4.0

  • 4.3.2 - 2025-10-03

    What's Changed

    • feat(v4.3.2): add rate limit, rpi orderbook & adl endpoints by @ JJ-Cro in #492
    • Add a new response field cumFeeDetail to return trading fee details instead of cumExecFee (resolves #491)

    Full Changelog: v4.3.1...v4.3.2

  • 4.3.1 - 2025-09-12

    What's Changed

    • feat(v4.3.1): add new endpoints for limit price behavior and new delivery price by @ JJ-Cro in #485
    • feat(v4.3.1): add new endpoints for limit price behavior and new deli… by @ JJ-Cro in #489

    Full Changelog: v4.3.0...v4.3.1

  • 4.3.0 - 2025-09-05

    Summary

    Disabled by default to prevent any breaking changes. Enable it by passing this boolean in the REST client constructor:

    const client = new RestClientV5({
      key: key,
      secret: secret,
      throwExceptions: true,
    });

    Any retCode !== 0 response will be thrown in full, if enabled.

    What's Changed

    Full Changelog: v4.2.7...v4.3.0

  • 4.2.7 - 2025-08-25

    What's Changed

    • feat(v4.2.7): force ws request batching into groups of max 500 topics per batch by @ tiagosiebler in #479

    Full Changelog: v4.2.6...v4.2.7

  • 4.2.6 - 2025-08-25
    • Fixes deduping workflow introduced in previous release

    Full Changelog: v4.2.5...v4.2.6

  • 4.2.5 - 2025-08-25

    What's Changed

    This provides convenience in calling the subscribe method, where it will only emit subscribe events to bybit for the topics that haven't been subscribed to yet, preventing the scenario in #477 (which will cause non-duplicate topic subs to fail)

    Full Changelog: v4.2.4...v4.2.5

  • 4.2.4 - 2025-08-13

    What's Changed

    Full Changelog: v4.2.3...v4.2.4

  • 4.2.3 - 2025-08-12

    What's Changed

    Transitioned the release workflow to a token-less trusted publisher workflow, for a more secure way to publish new releases to npm.

    Historic Changelog

    Note: these are since the last "release" / tag on GitHub.

@tiagosiebler tiagosiebler merged commit 8f4090f into master Jan 15, 2026
2 checks passed
@tiagosiebler tiagosiebler deleted the snyk-upgrade-4b7cb656d1ef0ebcfe810d330a048b55 branch January 15, 2026 10:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants