# Vendored Python dependencies ## `websockets` 17.0.1 - Upstream: - Release: - Source distribution: `websockets-17.0.1.tar.gz` - Source URL: - SHA-256: `5baa9bc0dfbae8c507e51c8cf1b6d4628086f7a87bbd3a9952bd5f035451f1cc` - License: BSD-3-Clause; see `LICENSE.websockets` and `THIRD_PARTY_NOTICES.md` - Python requirement: Python 3.11 or newer - Last security/release review: 2026-08-07 ([PyPI release metadata](https://pypi.org/project/websockets/17.0.1/), [GitHub Advisory Database query](https://api.github.com/advisories?ecosystem=pip&affects=websockets%4017.0.1&per_page=100)) The complete Python package from `src/websockets` is included. The C source for the optional `websockets.speedups` extension, upstream tests, documentation, packaging metadata, and generated bytecode are intentionally omitted. `websockets.frames` automatically uses its pure-Python masking implementation when the optional extension isn't present. The bridge prepends this `vendor` directory to `sys.path`. A globally installed package therefore cannot silently change the plugin's behavior. Do not patch the vendored package directly. Put integration behavior in the bridge adapter and update the dependency with: ```bash scripts/update-websockets-vendor ``` The update script downloads to a temporary directory, verifies the pinned archive hash, rejects links and binary artifacts, and replaces only `vendor/websockets`. Updating to another release requires reviewing its changelog and security notices, then updating the pinned version, URL and hash in both the script and this document in the same change.