bump debug to ~2.6.4 #52
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Please bump debug to
~2.6.4
, the same version used by (almost) all the othergithub.com/socketio/*
packages.The current version of debug that was pinned is reported as having a sec vulnerability by snyk via its dependency
ms
. It doesn't effect socket.io, but every user of socket.io has to figure that out themselves right now.It allows debug to be de-duplicated and the install tree flattened (a minor convenience).
I would also strongly suggest moving to
^2.x
, becausedebug
is a very small package, with a small and easy to manage API surface and maintainers who are very, very careful about semver and who will not introduce breaking changes in minors. In this PR, though, I just updated this to use the exact same debug dep spec you use elsewhere.