Skip to content

Comments

[Snyk] Upgrade socket.io-client from 4.6.1 to 4.7.5#4

Open
codegrande wants to merge 1 commit intomainfrom
snyk-upgrade-685213bc287f57e2761680100a2e65db
Open

[Snyk] Upgrade socket.io-client from 4.6.1 to 4.7.5#4
codegrande wants to merge 1 commit intomainfrom
snyk-upgrade-685213bc287f57e2761680100a2e65db

Conversation

@codegrande
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade socket.io-client from 4.6.1 to 4.7.5.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 7 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2024-03-14.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Denial of Service (DoS)
SNYK-JS-SOCKETIOPARSER-5596892
375/1000
Why? CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: socket.io-client from socket.io-client GitHub release notes
Commit messages
Package name: socket.io-client
  • 4f6030f chore(release): 4.7.5
  • 34cbfbb fix: discard acknowledgements upon disconnection
  • 8cfea8c chore(release): 4.7.4
  • ca5d50e chore(release): 4.7.3
  • f9c16f2 fix(typings): fix the type of the socket#id attribute
  • b3f0cab ci: add Node.js 20 in the test matrix
  • 5a3eafe fix(typings): accept string | undefined as init argument
  • 605de78 fix: improve compatibility with node16 module resolution (#1595)
  • d00ccd2 ci: bump appiumVersion for Android tests in SauceLabs
  • 928d76d chore(release): 4.7.2
  • 74ca7ac chore: bump engine.io-client to version 6.5.2
  • 0536fcc chore(release): 4.7.1
  • 6169bb8 chore: bump dev dependencies
  • 84ec6cf refactor: expose the ESM build with debug (bis)
  • 630ff41 chore: bump engine.io-client to version 6.5.1
  • 9b235ec chore(release): 4.7.0
  • f2892ab fix: use same scope for setTimeout and clearTimeout calls (#1568)
  • 5bc94b5 fix: properly report timeout error when connecting
  • 781d753 feat: expose ESM build with debug (#1585)
  • 8f14b98 chore: bump engine.io-client to version 6.5.0
  • a04ae1b chore(release): 4.6.2
  • 7c1db9d chore: bump socket.io-parser to version 4.2.3
  • 61dea71 refactor: remove invalid comma from package.json
  • 7ead241 fix(exports): move `types` condition to the top (#1580)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants