Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Snyk] Upgrade socket.io from 1.4.8 to 1.7.4#21

Open
snyk-bot wants to merge 1 commit into
master from
snyk-upgrade-a6ce293ac51ac0ed646df23114ca5dfd
Open

[Snyk] Upgrade socket.io from 1.4.8 to 1.7.4 #21
snyk-bot wants to merge 1 commit into
master from
snyk-upgrade-a6ce293ac51ac0ed646df23114ca5dfd

Conversation

@snyk-bot

@snyk-bot snyk-bot commented May 12, 2021

Copy link
Copy Markdown

Snyk has created this PR to upgrade socket.io from 1.4.8 to 1.7.4.

merge advice
i️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 8 versions ahead of your current version.
  • The recommended version was released 4 years ago, on 2017年05月07日.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Denial of Service (DoS)
npm:ws:20171108
761/1000
Why? Mature exploit, Has a fix available, CVSS 7.5
Mature
Denial of Service (DoS)
npm:ws:20160624
761/1000
Why? Mature exploit, Has a fix available, CVSS 7.5
No Known Exploit
Denial of Service (DoS)
npm:ws:20171108
761/1000
Why? Mature exploit, Has a fix available, CVSS 7.5
Mature
Denial of Service (DoS)
npm:ws:20160624
761/1000
Why? Mature exploit, Has a fix available, CVSS 7.5
No Known Exploit
Insecure Randomness
npm:ws:20160920
761/1000
Why? Mature exploit, Has a fix available, CVSS 7.5
No Known Exploit
Insecure Randomness
npm:ws:20160920
761/1000
Why? Mature exploit, Has a fix available, CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: socket.io
  • 1.7.4 - 2017年05月07日
  • 1.7.3 - 2017年02月17日
  • 1.7.2 - 2016年12月11日
  • 1.7.1 - 2016年11月27日
  • 1.7.0 - 2016年11月27日
  • 1.6.0 - 2016年11月20日
  • 1.5.1 - 2016年10月24日
  • 1.5.0 - 2016年10月06日
  • 1.4.8 - 2016年06月24日
from socket.io GitHub release notes
Commit messages
Package name: socket.io
  • 0abbd4d [chore] Release 1.7.4
  • c89ccd9 [chore] Bump engine.io to version 1.8.4
  • a646044 [chore] Release 1.7.3
  • 751a6fc [chore] Bump engine.io to version 1.8.3
  • 1f59e45 [chore] Release 1.7.2 (#2783)
  • 0a7afa8 [chore] Bump engine.io to version 1.8.2 (#2782)
  • 1e31769 [fix] Fixes socket.use error packet (#2772)
  • 797c9a3 [chore] Release 1.7.1 (#2768)
  • 4f93a0b [chore] Release 1.7.0 (#2767)
  • 3c98130 [chore] Update client location and serve minified file (#2766)
  • 9c23308 [chore] Bump engine.io to version 1.8.1 (#2765)
  • 955e5e0 [feature] Add a `local` flag (#2628)
  • 0ef55b2 [feature] serve sourcemap for socket.io-client (#2482)
  • 4d8e2d3 [docs] Fixed grammar issues in the README.md (#2159)
  • d48f848 [docs] Comment connected socket availability for adapters (#2081)
  • 57b3863 [chore] Release 1.6.0 (#2757)
  • 9e7567d [chore] Bump socket.io-adapter to version 0.5.0 (#2756)
  • 2e36799 [chore] Bump engine.io to version 1.8.0 (#2755)
  • 9bb5e9d [chore] Bump debug to version 2.3.3 (#2754)
  • ff2c15d [perf] Minor code optimizations (#2219)
  • a483658 [example] Add disconnection/reconnection logs to the chat example (#2675)
  • 4c5dbd8 [fix] Don't drop query variables on handshake (#2745)
  • e14a10b [feature] add support for Server#close(callback) (#2748)
  • 5a123be [feature] Add support for socket middleware (#2306)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

1 participant

AltStyle によって変換されたページ (->オリジナル) /