-
-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency socket.io to v2 [SECURITY] #44
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-socket.io-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
April 26, 2021 15:42
f6f01f1
to
dfcc841
Compare
renovate
bot
changed the title
Update dependency socket.io to v3 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Apr 26, 2021
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
May 15, 2021 19:55
dfcc841
to
3fac80c
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
May 15, 2021
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
June 6, 2021 20:20
3fac80c
to
c88d5ed
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Jun 6, 2021
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
October 19, 2021 00:20
c88d5ed
to
915de15
Compare
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
March 7, 2022 14:59
915de15
to
0799340
Compare
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
April 24, 2022 19:09
0799340
to
a9979f1
Compare
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
March 17, 2023 14:03
a9979f1
to
3398314
Compare
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
March 25, 2023 03:53
3398314
to
2ec6d14
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Mar 25, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
April 3, 2023 10:30
2ec6d14
to
81d3f61
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Apr 3, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
April 3, 2023 12:46
81d3f61
to
868b471
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Apr 3, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
April 17, 2023 09:36
868b471
to
5fc6134
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Apr 17, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
April 17, 2023 14:31
5fc6134
to
0703777
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Apr 17, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
May 28, 2023 11:37
0703777
to
a6a1432
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
May 28, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
May 28, 2023 13:40
a6a1432
to
7b10d1c
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
May 28, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
June 4, 2023 11:28
7b10d1c
to
3a63530
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Jun 4, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
June 4, 2023 12:21
3a63530
to
c798cb6
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Jun 4, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
June 13, 2023 15:01
c798cb6
to
3a4c2aa
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Jun 13, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
September 19, 2023 13:24
7d7ce99
to
e121782
Compare
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
September 26, 2023 14:16
e121782
to
e44d63b
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Sep 26, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
September 26, 2023 17:43
e44d63b
to
cb251c9
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Sep 26, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
September 28, 2023 15:40
cb251c9
to
c31cdde
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Sep 28, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
September 28, 2023 19:49
c31cdde
to
a7d7c77
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Sep 28, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
October 9, 2023 11:29
a7d7c77
to
fc8aae4
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Oct 9, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
October 9, 2023 13:20
fc8aae4
to
a05e2e1
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Oct 9, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
October 15, 2023 09:08
a05e2e1
to
a303f23
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Oct 15, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
October 15, 2023 17:52
a303f23
to
96b980a
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Oct 15, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
October 23, 2023 12:38
96b980a
to
6b09c5a
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Oct 23, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
October 23, 2023 17:40
6b09c5a
to
c5f60cd
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Oct 23, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
November 6, 2023 06:54
c5f60cd
to
1faaadc
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Nov 6, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
November 6, 2023 11:29
1faaadc
to
1c49269
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Nov 6, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
November 16, 2023 12:32
1c49269
to
16bf9a9
Compare
renovate
bot
changed the title
Update dependency socket.io to v2 [SECURITY]
Update dependency socket.io to v4 [SECURITY]
Nov 16, 2023
renovate
bot
force-pushed
the
renovate/npm-socket.io-vulnerability
branch
from
November 16, 2023 17:28
16bf9a9
to
e782424
Compare
renovate
bot
changed the title
Update dependency socket.io to v4 [SECURITY]
Update dependency socket.io to v2 [SECURITY]
Nov 16, 2023
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
~0.9.16
->~2.4.0
GitHub Vulnerability Alerts
CVE-2020-28481
The package socket.io before 2.4.0 are vulnerable to Insecure Defaults due to CORS Misconfiguration. All domains are whitelisted by default.
Release Notes
socketio/socket.io (socket.io)
v2.4.0
Compare Source
Bug Fixes
3.0.4 (2020-12-07)
3.0.3 (2020-11-19)
3.0.2 (2020-11-17)
Bug Fixes
3.0.1 (2020-11-09)
Bug Fixes
v2.3.0
Compare Source
This release mainly contains a bump of the
engine.io
andws
packages, but no additional features.v2.2.0
Compare Source
Features
Bug fixes
v2.1.1
Compare Source
Features
v2.1.0
Compare Source
Features
Bug fixes
Important note⚠️ from Engine.IO 3.2.0 release
There are two non-breaking changes that are somehow quite important:
ws
was reverted as the default wsEngine (https://github.com/socketio/engine.io/pull/550), as there was several blocking issues withuws
. You can still useuws
by runningnpm install uws --save
in your project and using thewsEngine
option:pingTimeout
now defaults to 5 seconds (instead of 60 seconds): https://github.com/socketio/engine.io/pull/551v2.0.4
Compare Source
Bug fixes
Links:
engine.io
: -ws
: -v2.0.3
Compare Source
Bug fixes
Links:
engine.io
: -ws
: -v2.0.2
Compare Source
Bug fixes
Links:
engine.io
: -ws
: -v2.0.1
Compare Source
Bug fixes
- update path of client file (#2934)
Links:
engine.io
: -ws
: -v2.0.0
Compare Source
This major release brings several performance improvements:
uws is now the default Websocket engine. It should bring significant improvement in performance (particularly in terms of memory consumption) (https://github.com/socketio/engine.io/releases/tag/2.0.0)
the Engine.IO and Socket.IO handshake packets were merged, reducing the number of roundtrips necessary to establish a connection. (#2833)
it is now possible to provide a custom parser according to the needs of your application (#2829). Please take a look at the example for more information.
Please note that this release is not backward-compatible, due to:
Please also note that if you are using a self-signed certificate,
rejectUnauthorized
now defaults totrue
(https://github.com/socketio/engine.io-client/pull/558).Finally, the API documentation is now in the repository (here), and the content of the website here. Do not hesitate if you see something wrong or missing!
The full list of changes:
local
flag (#2816)clients
method in the API documentation (#2812)Besides, we are proud to announce that Socket.IO is now a part of open collective: https://opencollective.com/socketio. More on that later.
v1.7.4
Compare Source
v1.7.3
Compare Source
v1.7.2
Compare Source
v1.7.1
Compare Source
(following
socket.io-client
update)v1.7.0
Compare Source
local
flag (#2628)v1.6.0
Compare Source
v1.5.1
Compare Source
client
in test script (#2731)v1.5.0
Compare Source
v1.4.8
Compare Source
v1.4.7
Compare Source
v1.4.6
Compare Source
v1.4.5
Compare Source
v1.4.4
Compare Source
v1.4.3
Compare Source
v1.4.2
Compare Source
v1.4.1
Compare Source
v1.4.0
Compare Source
v1.3.7
Compare Source
v1.3.6
Compare Source
v1.3.5
Compare Source
v1.3.4
Compare Source
v1.3.3
Compare Source
v1.3.2
Compare Source
v1.3.1
Compare Source
v1.3.0
Compare Source
v1.2.1
Compare Source
v1.2.0
Compare Source
v1.1.0
Compare Source
v1.0.6
Compare Source
v1.0.5
Compare Source
v1.0.4
Compare Source
v1.0.3
Compare Source
v1.0.2
Compare Source
v1.0.1
Compare Source
v1.0.0
Compare Source
v0.9.19
Compare Source
v0.9.18
Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.