[Snyk] Upgrade socket.io from 4.7.2 to 4.7.4 #1173

Closed
opened 2026-04-05 16:25:47 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @simlarsen on 2/28/2024

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade socket.io from 4.7.2 to 4.7.4.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 2 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2024-01-12.
Release notes
Package name: socket.io from socket.io GitHub release notes
Commit messages
Package name: socket.io
  • 6ab2509 chore(release): 4.7.4
  • d9fb2f6 chore(tests): add a test for noArgs in a namespace
  • 2c0a81c chore(tests): fix issues due to client#id type change
  • f8d2644 chore(tests): add type defs for expectjs and fix invalid expectations
  • 04640d6 chore(tests): indicate a future ts error with version
  • cb6d2e0 fix(typings): calling io.emit with no arguments incorrectly errored
  • 80b2c34 chore: bump socket.io-client version
  • 0d89319 chore(release): 4.7.3
  • df8e70f fix: return the first response when broadcasting to a single socket (#4878)
  • 8c9ebc3 fix(typings): allow to bind to a non-secure Http2Server (#4853)
  • efb5c21 docs(examples): add Vue client with CRUD example
  • 3848280 docs(examples): upgrade basic-crud-application to Angular v17
  • 9a2a83f refactor: cleanup after merge
  • f6ef267 refactor(typings): improve emit types (#4817)
  • 1cdf36b test: build examples in the CI (#3856)
  • bbf1fdc docs: add Elephant.IO as PHP client library (#4779)
  • b4dc83e docs(examples): add codesandbox configuration
  • ccbb4c0 docs: add example with connection state recovery
  • d744fda docs: improve example with express-session
  • 8259cda docs: use io.engine.use() with express-session
  • fd9dd74 docs: use "connection" instead of "connect"

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

*Originally created by @simlarsen on 2/28/2024* <p>This PR was automatically created by Snyk using the credentials of a real user.</p><br /><h3>Snyk has created this PR to upgrade socket.io from 4.7.2 to 4.7.4.</h3> :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project. <hr/> - The recommended version is **2 versions** ahead of your current version. - The recommended version was released **2 months ago**, on 2024-01-12. <details> <summary><b>Release notes</b></summary> <br/> <details> <summary>Package name: <b>socket.io</b></summary> <ul> <li> <b>4.7.4</b> - <a href="https://snyk.io/redirect/github/socketio/socket.io/releases/tag/4.7.4">2024-01-12</a></br><h3>Bug Fixes</h3> <ul> <li><strong>typings:</strong> calling io.emit with no arguments incorrectly errored (<a href="https://snyk.io/redirect/github/socketio/socket.io/commit/cb6d2e02aa7ec03c2de1817d35cffa1128b107ef">cb6d2e0</a>), closes <a href="https://snyk.io/redirect/github/socketio/socket.io/issues/4914" data-hovercard-type="issue" data-hovercard-url="/socketio/socket.io/issues/4914/hovercard">#4914</a></li> </ul> <h4>Links</h4> <ul> <li>Diff: <a class="commit-link" href="https://snyk.io/redirect/github/socketio/socket.io/compare/4.7.3...4.7.4"><tt>4.7.3...4.7.4</tt></a></li> <li>Client release: <a href="https://snyk.io/redirect/github/socketio/socket.io-client/releases/tag/4.7.4">4.7.4</a></li> <li><a href="https://snyk.io/redirect/github/socketio/engine.io/releases/tag/6.5.2"><code>engine.io@~6.5.2</code></a> (no change)</li> <li><a href="https://snyk.io/redirect/github/websockets/ws/releases/tag/8.11.0"><code>ws@~8.11.0</code></a> (no change)</li> </ul> </li> <li> <b>4.7.3</b> - <a href="https://snyk.io/redirect/github/socketio/socket.io/releases/tag/4.7.3">2024-01-03</a></br><h3>Bug Fixes</h3> <ul> <li>return the first response when broadcasting to a single socket (<a href="https://snyk.io/redirect/github/socketio/socket.io/issues/4878" data-hovercard-type="pull_request" data-hovercard-url="/socketio/socket.io/pull/4878/hovercard">#4878</a>) (<a href="https://snyk.io/redirect/github/socketio/socket.io/commit/df8e70f79822e3887b4f21ca718af8a53bbda2c4">df8e70f</a>)</li> <li><strong>typings:</strong> allow to bind to a non-secure Http2Server (<a href="https://snyk.io/redirect/github/socketio/socket.io/issues/4853" data-hovercard-type="pull_request" data-hovercard-url="/socketio/socket.io/pull/4853/hovercard">#4853</a>) (<a href="https://snyk.io/redirect/github/socketio/socket.io/commit/8c9ebc30e5452ff9381af5d79f547394fa55633c">8c9ebc3</a>)</li> </ul> <h4>Links</h4> <ul> <li>Diff: <a class="commit-link" href="https://snyk.io/redirect/github/socketio/socket.io/compare/4.7.2...4.7.3"><tt>4.7.2...4.7.3</tt></a></li> <li>Client release: <a href="https://snyk.io/redirect/github/socketio/socket.io-client/releases/tag/4.7.3">4.7.3</a></li> <li><a href="https://snyk.io/redirect/github/socketio/engine.io/releases/tag/6.5.2"><code>engine.io@~6.5.2</code></a> (no change)</li> <li><a href="https://snyk.io/redirect/github/websockets/ws/releases/tag/8.11.0"><code>ws@~8.11.0</code></a> (no change)</li> </ul> </li> <li> <b>4.7.2</b> - <a href="https://snyk.io/redirect/github/socketio/socket.io/releases/tag/4.7.2">2023-08-02</a></br><h3>Bug Fixes</h3> <ul> <li>clean up child namespace when client is rejected in middleware (<a href="https://snyk.io/redirect/github/socketio/socket.io/issues/4773" data-hovercard-type="pull_request" data-hovercard-url="/socketio/socket.io/pull/4773/hovercard">#4773</a>) (<a href="https://snyk.io/redirect/github/socketio/socket.io/commit/0731c0d2f497d5cce596ea1ec32a67c08bcccbcd">0731c0d</a>)</li> <li><strong>webtransport:</strong> properly handle WebTransport-only connections (<a href="https://snyk.io/redirect/github/socketio/socket.io/commit/3468a197afe87e65eb0d779fabd347fe683013ab">3468a19</a>)</li> <li><strong>webtransport:</strong> add proper framing (<a href="https://snyk.io/redirect/github/socketio/engine.io/commit/a306db09e8ddb367c7d62f45fec920f979580b7c">a306db0</a>)</li> </ul> <h4>Links</h4> <ul> <li>Diff: <a class="commit-link" href="https://snyk.io/redirect/github/socketio/socket.io/compare/4.7.1...4.7.2"><tt>4.7.1...4.7.2</tt></a></li> <li>Client release: <a href="https://snyk.io/redirect/github/socketio/socket.io-client/releases/tag/4.7.2">4.7.2</a></li> <li><a href="https://snyk.io/redirect/github/socketio/engine.io/releases/tag/6.5.2"><code>engine.io@~6.5.2</code></a> (<a href="https://snyk.io/redirect/github/socketio/engine.io/compare/6.5.0...6.5.2">diff</a>)</li> <li><a href="https://snyk.io/redirect/github/websockets/ws/releases/tag/8.11.0"><code>ws@~8.11.0</code></a> (no change)</li> </ul> </li> </ul> from <a href="https://snyk.io/redirect/github/socketio/socket.io/releases">socket.io GitHub release notes</a> </details> </details> <details> <summary><b>Commit messages</b></summary> </br> <details> <summary>Package name: <b>socket.io</b></summary> <ul> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/6ab2509d529d438e25b6c3a701444aa6585fa153">6ab2509</a> chore(release): 4.7.4</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/d9fb2f64b618af2d50adae83b17d6d757b05600a">d9fb2f6</a> chore(tests): add a test for noArgs in a namespace</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/2c0a81cd8737388f92a87afe51deb1e92b4aba45">2c0a81c</a> chore(tests): fix issues due to client#id type change</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/f8d2644921cdcaf877d07d68a2ad61c13d586663">f8d2644</a> chore(tests): add type defs for expectjs and fix invalid expectations</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/04640d68cfd0469c04ecce63b86801625402c691">04640d6</a> chore(tests): indicate a future ts error with version</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/cb6d2e02aa7ec03c2de1817d35cffa1128b107ef">cb6d2e0</a> fix(typings): calling io.emit with no arguments incorrectly errored</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/80b2c34478892e266abdc22318cf993ac4efef22">80b2c34</a> chore: bump socket.io-client version</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/0d893196f8e86ccba3a7a1ab728d00593d7aa238">0d89319</a> chore(release): 4.7.3</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/df8e70f79822e3887b4f21ca718af8a53bbda2c4">df8e70f</a> fix: return the first response when broadcasting to a single socket (#4878)</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/8c9ebc30e5452ff9381af5d79f547394fa55633c">8c9ebc3</a> fix(typings): allow to bind to a non-secure Http2Server (#4853)</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/efb5c21e856f114f7366ec17282ab686ff06c24c">efb5c21</a> docs(examples): add Vue client with CRUD example</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/3848280125f35768e74be4d778d7b55acf82f7df">3848280</a> docs(examples): upgrade basic-crud-application to Angular v17</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/9a2a83fdd42faa840d4f11fd223349e5d8e4d52c">9a2a83f</a> refactor: cleanup after merge</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/f6ef267b035a4db49b7d0fce438ca5c5b686f547">f6ef267</a> refactor(typings): improve emit types (#4817)</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/1cdf36bfea581b2de00da94172637cecf4208ad6">1cdf36b</a> test: build examples in the CI (#3856)</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/bbf1fdc7a62be13c68f3061e7618cef99c2ec053">bbf1fdc</a> docs: add Elephant.IO as PHP client library (#4779)</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/b4dc83eb9b85e26f09f25e1b5320fe3f49b521d3">b4dc83e</a> docs(examples): add codesandbox configuration</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/ccbb4c077375ec2cb0d1c472a902e52f1d9a7dfc">ccbb4c0</a> docs: add example with connection state recovery</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/d744fda77207ecf1fa4bc1cd3d32eaa403deca9f">d744fda</a> docs: improve example with express-session</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/8259cdac8439400d8815d6830d13bdd22bb6390f">8259cda</a> docs: use io.engine.use() with express-session</li> <li><a href="https://snyk.io/redirect/github/socketio/socket.io/commit/fd9dd74eeed3fa6a15c63240df30cc3b7357102f">fd9dd74</a> docs: use &quot;connection&quot; instead of &quot;connect&quot;</li> </ul> <a href="https://snyk.io/redirect/github/socketio/socket.io/compare/c332643ad8b2eff3a9edee432bfd53fb37559280...6ab2509d529d438e25b6c3a701444aa6585fa153">Compare</a> </details> </details> <hr/> **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.* For more information: <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6InJyWmxZcEdHY2RyTHZsb0lYd0dUcVg4WkFRTnNCOUEwIiwiYW5vbnltb3VzSWQiOiI4YmVjYTU1YS02YTE5LTRkYjgtODY3MS05YzliNzgzNDFlNGQiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjhiZWNhNTVhLTZhMTktNGRiOC04NjcxLTljOWI3ODM0MWU0ZCJ9fQ==" width="0" height="0"/> 🧐 [View latest project report](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🛠 [Adjust upgrade PR settings](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr) 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa/settings/integration?pkg&#x3D;socket.io&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades) <!--- (snyk:metadata:{"prId":"8beca55a-6a19-4db8-8671-9c9b78341e4d","prPublicId":"8beca55a-6a19-4db8-8671-9c9b78341e4d","dependencies":[{"name":"socket.io","from":"4.7.2","to":"4.7.4"}],"packageManager":"npm","type":"auto","projectUrl":"https://app.snyk.io/org/oneuptime-RsC2nshvQ2Vnr35jHvMnMP/project/a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa?utm_source=github&utm_medium=referral&page=upgrade-pr","projectPublicId":"a2fb4fe1-f25f-4ff9-a58c-e78277b0a7fa","env":"prod","prType":"upgrade","vulns":[],"issuesToFix":[],"upgrade":[],"upgradeInfo":{"versionsDiff":2,"publishedDate":"2024-01-12T10:09:58.860Z"},"templateVariants":[],"hasFixes":false,"isMajorUpgrade":false,"isBreakingChange":false,"priorityScoreList":[]}) --->
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#1173