Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency socket.io to ~1.7.4 - autoclosed #26

Closed

Conversation

dev-mend-for-github-com[bot]
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
socket.io dependencies minor ~1.3.7 -> ~1.7.4

By merging this PR, the issue #6 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 8.1 CVE-2020-28502
High High 7.5 CVE-2015-8315
High High 7.5 CVE-2016-10518
High High 7.5 CVE-2016-10542
High High 7.5 WS-2016-0040
High High 7.5 WS-2017-0421
High High 7.4 WS-2017-0107

Release Notes

socketio/socket.io

v1.7.4

Compare Source

  • [chore] Bump engine.io to version 1.8.4

v1.7.3

Compare Source

  • [chore] Bump engine.io-client to version 1.8.3

v1.7.2

Compare Source

  • [chore] Bump engine.io to version 1.8.2 (#​2782)
  • [fix] Fixes socket.use error packet (#​2772)

v1.7.1

Compare Source

(following socket.io-client update)

v1.7.0

Compare Source

  • [docs] Comment connected socket availability for adapters (#​2081)
  • [docs] Fixed grammar issues in the README.md (#​2159)
  • [feature] serve sourcemap for socket.io-client (#​2482)
  • [feature] Add a local flag (#​2628)
  • [chore] Bump engine.io to version 1.8.1 (#​2765)
  • [chore] Update client location and serve minified file (#​2766)

v1.6.0

Compare Source

  • [fix] Make ETag header comply with standard. (#​2603)
  • [feature] Loading client script on demand. (#​2567)
  • [test] Fix leaking clientSocket (#​2721)
  • [feature] Add support for all event emitter methods (#​2601)
  • [chore] Update year to 2016 (#​2456)
  • [feature] Add support for socket middleware (#​2306)
  • [feature] add support for Server#close(callback) (#​2748)
  • [fix] Don't drop query variables on handshake (#​2745)
  • [example] Add disconnection/reconnection logs to the chat example (#​2675)
  • [perf] Minor code optimizations (#​2219)
  • [chore] Bump debug to version 2.3.3 (#​2754)
  • [chore] Bump engine.io to version 1.8.0 (#​2755)
  • [chore] Bump socket.io-adapter to version 0.5.0 (#​2756)

v1.5.1

Compare Source

  • [fix] Avoid swallowing exceptions thrown by user event handlers (#​2682)
  • [test] Use client function to unify client in test script (#​2731)
  • [docs] Add link to LICENSE (#​2221)
  • [docs] Fix JSDoc of optional parameters (#​2465)
  • [docs] Fix typo (#​2724)
  • [docs] Link readme npm package badge to npm registry page (#​2612)
  • [docs] Minor fixes (#​2526)
  • [chore] Bump socket.io-parser to 2.3.0 (#​2730)
  • [chore] Add Github issue and PR templates (#​2733)
  • [chore] Bump engine.io to 1.7.2 (#​2729)
  • [chore] Bump socket.io-parser to 2.3.1 (#​2734)

v1.5.0

Compare Source

  • [feature] stop append /# before id when no namespace (#​2509)
  • [feature] Add a 'disconnecting' event to access to socket.rooms upon disconnection (#​2332)
  • [fix] Fix query string management (#​2422)
  • [fix] add quote to exec paths, prevent error when spaces in path (#​2508)
  • [docs] Prevent mixup for new programmers (#​2599)
  • [example] Fix chat display in Firefox (#​2477)
  • [chore] Add gulp & babel in the build process (#​2471)
  • [chore] Bump engine.io to 1.7.0 (#​2707)
  • [chore] Remove unused zuul-ngrok dependency (#​2708)
  • [chore] Point towards current master of socket.io-client (#​2710)
  • [chore] Restrict files included in npm package (#​2709)
  • [chore] Link build badge to master branch (#​2549)

v1.4.8

Compare Source

v1.4.7

Compare Source

v1.4.6

Compare Source

v1.4.5

Compare Source

v1.4.4

Compare Source

v1.4.3

Compare Source

v1.4.2

Compare Source

v1.4.1

Compare Source

v1.4.0

Compare Source


  • If you want to rebase/retry this PR, click this checkbox.

@dev-mend-for-github-com dev-mend-for-github-com bot added the security fix Security fix generated by WhiteSource label Apr 12, 2022
@dev-mend-for-github-com dev-mend-for-github-com bot changed the title Update dependency socket.io to ~1.7.4 Update dependency socket.io to ~1.7.4 - autoclosed Apr 12, 2022
@dev-mend-for-github-com dev-mend-for-github-com bot deleted the whitesource-remediate/socket.io-1.x branch April 12, 2022 13:33
@dev-mend-for-github-com dev-mend-for-github-com bot changed the title Update dependency socket.io to ~1.7.4 - autoclosed Update dependency socket.io to ~1.7.4 Apr 12, 2022
@dev-mend-for-github-com dev-mend-for-github-com bot restored the whitesource-remediate/socket.io-1.x branch April 12, 2022 14:28
@dev-mend-for-github-com dev-mend-for-github-com bot changed the title Update dependency socket.io to ~1.7.4 Update dependency socket.io to ~1.7.4 - autoclosed Apr 12, 2022
@dev-mend-for-github-com dev-mend-for-github-com bot deleted the whitesource-remediate/socket.io-1.x branch April 12, 2022 14:33
@dev-mend-for-github-com dev-mend-for-github-com bot changed the title Update dependency socket.io to ~1.7.4 - autoclosed Update dependency socket.io to ~1.7.4 Apr 12, 2022
@dev-mend-for-github-com dev-mend-for-github-com bot restored the whitesource-remediate/socket.io-1.x branch April 12, 2022 18:39
@dev-mend-for-github-com dev-mend-for-github-com bot changed the title Update dependency socket.io to ~1.7.4 Update dependency socket.io to ~1.7.4 - autoclosed Apr 13, 2022
@dev-mend-for-github-com dev-mend-for-github-com bot deleted the whitesource-remediate/socket.io-1.x branch April 13, 2022 01:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by WhiteSource
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

0 participants