Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump socket.io from 2.4.1 to 2.5.1 in /docs #546

Merged
merged 1 commit into from
Jun 19, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jun 19, 2024

Bumps socket.io from 2.4.1 to 2.5.1.

Release notes

Sourced from socket.io's releases.

2.5.1

Bug Fixes

  • add a noop handler for the error event (d30630b)

Links:

2.5.0

⚠️ WARNING ⚠️

The default value of the maxHttpBufferSize option has been decreased from 100 MB to 1 MB, in order to prevent attacks by denial of service.

Security advisory: GHSA-j4f2-536g-r55m

Bug Fixes

  • fix race condition in dynamic namespaces (05e1278)
  • ignore packet received after disconnection (22d4bdf)
  • only set 'connected' to true after middleware execution (226cc16)
  • prevent the socket from joining a room after disconnection (f223178)

Links:

Changelog

Sourced from socket.io's changelog.

2.5.1 (2024-06-19)

Bug Fixes

  • add a noop handler for the error event (d30630b)

2.5.0 (2022-06-26)

Bug Fixes

  • fix race condition in dynamic namespaces (05e1278)
  • ignore packet received after disconnection (22d4bdf)
  • only set 'connected' to true after middleware execution (226cc16)
  • prevent the socket from joining a room after disconnection (f223178)
Commits
  • 88b2cdb chore(release): 2.5.1
  • d30630b fix: add a noop handler for the error event
  • f927ba2 test: fix tests on Node.js > 18
  • baa6804 chore(release): 2.5.0
  • f223178 fix: prevent the socket from joining a room after disconnection
  • 226cc16 fix: only set 'connected' to true after middleware execution
  • 05e1278 fix: fix race condition in dynamic namespaces
  • 22d4bdf fix: ignore packet received after disconnection
  • dfded53 chore: update engine.io version to 3.6.0
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot bot added the dependencies Update one or more dependencies version label Jun 19, 2024
Copy link

socket-security bot commented Jun 19, 2024

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/loader-utils@1.4.2 None 0 25.9 kB evilebottnawi
npm/lodash.debounce@4.0.8 None 0 14 kB jdalton
npm/lodash@4.17.21 None 0 1.41 MB bnjmnt4n
npm/magic-string@0.25.9 None 0 373 kB antfu
npm/make-dir@3.1.0 filesystem 0 10 kB sindresorhus
npm/make-error@1.3.6 None 0 12.4 kB julien-f
npm/merge2@1.4.1 None 0 8.9 kB zensh
npm/micromatch@4.0.5 None 0 55.9 kB jonschlinkert
npm/mime-types@2.1.35 None 0 18.3 kB dougwilson
npm/minimatch@3.1.2 None 0 34.9 kB isaacs
npm/minimist@1.2.8 None 0 54.5 kB ljharb
npm/mkdirp@0.5.6 filesystem 0 7.69 kB isaacs
npm/node-fetch@2.6.9 network +1 212 kB node-fetch-bot
npm/normalize-wheel@1.0.1 None 0 19.7 kB basilfx
npm/np@6.5.0 Transitive: filesystem +8 128 kB sindresorhus
npm/npm-run-path@4.0.1 environment 0 8.13 kB sindresorhus
npm/object-assign@4.1.1 None 0 5.49 kB sindresorhus
npm/object-inspect@1.12.3 None 0 94.8 kB ljharb
npm/object.assign@4.1.4 None +1 1.19 MB ljharb
npm/object.values@1.1.6 None 0 30.5 kB ljharb
npm/once@1.4.0 None +1 7.01 kB isaacs
npm/onetime@5.1.2 None 0 6.17 kB sindresorhus
npm/p-limit@3.1.0 None 0 7.75 kB sindresorhus
npm/parse-json@5.2.0 None 0 5.41 kB sindresorhus
npm/path-key@3.1.1 None 0 4.55 kB sindresorhus
npm/path-parse@1.0.7 None 0 4.51 kB jbgutierrez
npm/picomatch@2.3.1 None 0 90 kB mrmlnc
npm/prettier@2.8.4 environment, filesystem, unsafe 0 11.7 MB prettier-bot
npm/pretty-format@29.4.2 None +3 435 kB simenb
npm/query-string@6.14.1 None 0 37.3 kB sindresorhus
npm/react-dom@18.3.1 environment 0 4.51 MB react-bot
npm/react@18.3.1 environment 0 318 kB react-bot
npm/regenerate@1.4.2 None 0 49.2 kB mathias
npm/registry-url@5.1.0 None 0 4.33 kB sindresorhus
npm/resolve@1.22.1 environment, filesystem +1 155 kB ljharb
npm/rimraf@3.0.2 filesystem 0 17.3 kB isaacs
npm/rollup-plugin-typescript2@0.27.3 environment, eval, filesystem Transitive: unsafe +5 11.8 MB ezolenko
npm/run-async@2.4.1 None 0 6.6 kB sboudrias
npm/rxjs@6.6.7 None +1 5.16 MB blesh
npm/safe-buffer@5.2.1 None 0 32.1 kB feross
npm/safer-buffer@2.1.2 None 0 42.3 kB chalker
npm/semver@7.5.4 None +1 109 kB npm-cli-ops
npm/signal-exit@3.0.7 None 0 9.96 kB isaacs
npm/source-map-support@0.5.21 filesystem +1 90.2 kB linusu
npm/source-map@0.6.1 None 0 805 kB tromey
npm/start-server-and-test@1.15.3 environment +6 112 kB bahmutov
npm/string-width@4.2.3 None +2 109 kB sindresorhus
npm/strip-ansi@3.0.1 None +1 7.3 kB jbnicolai
npm/strip-json-comments@3.1.1 None 0 6.96 kB sindresorhus
npm/supports-color@5.5.0 environment 0 6.63 kB sindresorhus
npm/terminal-link@2.1.1 None 0 6.52 kB sindresorhus
npm/terser@4.8.1 eval Transitive: filesystem, shell +1 1.92 MB fabiosantoscode
npm/through@2.3.8 None 0 12.5 kB dominictarr
npm/ts-jest@29.0.5 environment, filesystem, unsafe Transitive: eval, network, shell +49 5.44 MB kul
npm/ts-node@10.9.1 environment, filesystem, unsafe +6 5.16 MB cspotcode
npm/tslib@2.5.0 None 0 60 kB typescript-bot
npm/type-fest@0.21.3 None 0 119 kB sindresorhus
npm/typescript@4.9.5 None 0 66.8 MB typescript-bot
npm/util.promisify@1.0.0 None 0 13.3 kB ljharb
npm/vite@4.5.3 environment, eval, filesystem, network, shell, unsafe +2 13.6 MB vitebot
npm/which@2.0.2 environment 0 9.97 kB isaacs
npm/yargs-parser@21.1.1 environment, filesystem 0 128 kB oss-bot
npm/yarn-or-npm@3.0.1 filesystem +5 40.3 kB camacho

🚮 Removed packages: npm/@types/keyv@3.1.4, npm/boolbase@1.0.0, npm/css-color-names@0.0.4, npm/decamelize@1.2.0, npm/deep-extend@0.6.0, npm/domhandler@4.3.1, npm/domutils@2.8.0, npm/extsprintf@1.3.0, npm/has-bigints@1.0.2, npm/icss-replace-symbols@1.1.0

View full report↗︎

Copy link

socket-security bot commented Jun 19, 2024

👍 Dependency issues cleared. Learn more about Socket for GitHub ↗︎

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report↗︎

@ValentinH ValentinH added the skip-release Preserve the current version when merged label Jun 19, 2024
Copy link

codesandbox-ci bot commented Jun 19, 2024

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

Bumps [socket.io](https://github.com/socketio/socket.io) from 2.4.1 to 2.5.1.
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/2.5.1/CHANGELOG.md)
- [Commits](socketio/socket.io@2.4.1...2.5.1)

---
updated-dependencies:
- dependency-name: socket.io
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@ValentinH ValentinH force-pushed the dependabot/npm_and_yarn/docs/socket.io-2.5.1 branch from eea0371 to 8e502b5 Compare June 19, 2024 20:34
@ValentinH ValentinH merged commit c8d889b into main Jun 19, 2024
5 checks passed
@ValentinH ValentinH deleted the dependabot/npm_and_yarn/docs/socket.io-2.5.1 branch June 19, 2024 20:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Update one or more dependencies version skip-release Preserve the current version when merged
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant