Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

馃摝 update vulnerable subdependency engine.io #2211

Merged
merged 1 commit into from
May 5, 2023

Conversation

BenoitZugmeyer
Copy link
Member

Motivation

This fixes https://github.com/DataDog/browser-sdk/security/dependabot/57

Changes

Update socket.io and engine.io subdependencies. We need to upgrade socket.io because its dependency on engine.io is too strict and doesn't allow upgrading to a patched version.

Testing

  • Local
  • Staging
  • Unit
  • End to end

I have gone over the contributing documentation.

This fixes https://github.com/DataDog/browser-sdk/security/dependabot/57
We need to upgrade socket.io because its dependency on engine.io is too
strict and doesn't allow upgrading to a patched version.
@BenoitZugmeyer BenoitZugmeyer requested a review from a team as a code owner May 5, 2023 14:15
@BenoitZugmeyer BenoitZugmeyer changed the title update vulnerable subdependency engine.io 馃摝 update vulnerable subdependency engine.io May 5, 2023
@acorretti acorretti requested a review from a team May 5, 2023 14:18
@BenoitZugmeyer BenoitZugmeyer merged commit de04f8a into main May 5, 2023
17 checks passed
@BenoitZugmeyer BenoitZugmeyer deleted the benoit/update-socket-io branch May 5, 2023 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants