granite-clipboard
granite-clipboard copied to clipboard
Bump engine.io and @open-wc/testing-karma
Bumps engine.io to 3.6.1 and updates ancestor dependency @open-wc/testing-karma. These dependencies need to be updated together.
Updates engine.io
from 3.2.1 to 3.6.1
Release notes
Sourced from engine.io's releases.
3.6.1
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
Error: read ECONNRESET at TCP.onStreamRead (internal/stream_base_commons.js:209:20) Emitted 'error' event on Socket instance at: at emitErrorNT (internal/streams/destroy.js:106:8) at emitErrorCloseNT (internal/streams/destroy.js:74:3) at processTicksAndRejections (internal/process/task_queues.js:80:21) { errno: -104, code: 'ECONNRESET', syscall: 'read' }
Please upgrade as soon as possible.
Bug Fixes
- catch errors when destroying invalid upgrades (83c4071)
3.6.0
Bug Fixes
- add extension in the package.json main entry (#608) (3ad0567)
- do not reset the ping timer after upgrade (1f5d469)
Features
- decrease the default value of maxHttpBufferSize (58e274c)
This change reduces the default value from 100 mb to a more sane 1 mb.
This helps protect the server against denial of service attacks by malicious clients sending huge amounts of data.
See also: https://github.com/advisories/GHSA-j4f2-536g-r55m
- increase the default value of pingTimeout (f55a79a)
Links
- Diff: https://github.com/socketio/engine.io/compare/3.5.0...3.6.0
- Client release: -
... (truncated)
Changelog
Sourced from engine.io's changelog.
3.6.1 (2022-11-20)
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
Error: read ECONNRESET at TCP.onStreamRead (internal/stream_base_commons.js:209:20) Emitted 'error' event on Socket instance at: at emitErrorNT (internal/streams/destroy.js:106:8) at emitErrorCloseNT (internal/streams/destroy.js:74:3) at processTicksAndRejections (internal/process/task_queues.js:80:21) { errno: -104, code: 'ECONNRESET', syscall: 'read' }
Please upgrade as soon as possible.
Bug Fixes
- catch errors when destroying invalid upgrades (83c4071)
6.2.1 (2022-11-20)
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
Error: read ECONNRESET at TCP.onStreamRead (internal/stream_base_commons.js:209:20) Emitted 'error' event on Socket instance at: at emitErrorNT (internal/streams/destroy.js:106:8) at emitErrorCloseNT (internal/streams/destroy.js:74:3) at processTicksAndRejections (internal/process/task_queues.js:80:21) { errno: -104, code: 'ECONNRESET', syscall: 'read' }
Please upgrade as soon as possible.
Bug Fixes
... (truncated)
Commits
67a3a87
chore(release): 3.6.183c4071
fix: catch errors when destroying invalid upgradesf62f265
chore(release): 3.6.0f55a79a
feat: increase the default value of pingTimeout1f5d469
fix: do not reset the ping timer after upgrade3ad0567
fix: add extension in the package.json main entry (#608)58e274c
feat: decrease the default value of maxHttpBufferSizeb9dee7b
chore(release): 3.5.019cc582
feat: add support for all cookie options5ad2736
feat: disable perMessageDeflate by default- Additional commits viewable in compare view
Updates @open-wc/testing-karma
from 3.4.8 to 4.0.9
Release notes
Sourced from @open-wc/testing-karma
's releases.
[email protected]
Minor Changes
- 6525833a: Update aria-query to v5, fix switch role rules
[email protected]
Patch Changes
- fc3e9317: Fix bug #2490 in scope rule
[email protected]
Patch Changes
- 61e2668f: update eslint, eslint-config-airbnb-base and eslint-plugin-import
[email protected]
Patch Changes
- c7997ff2: Fix bug #2466 issue in role-supports-aria-attr
[email protected]
Minor Changes
- c4e8ab99: Added ignoredTags configuration option
[email protected]
Minor Changes
- f5e728d7: Add valid-lang rule
[email protected]
Minor Changes
- 45e0c17e: eslint-plugin-lit-a11y: use template-analyzer directly from lit plugin
[email protected]
Major Changes
- ed2b36e8: chore: remove intl list format
- ed2b36e8: Remove
eslint
dependency (in favour of peer dependency)[email protected]
Patch Changes
- 6940a3cb: fix: override bad publication
Changelog
Sourced from @open-wc/testing-karma
's changelog.
4.0.9 (2020-10-11)
Note: Version bump only for package
@open-wc/testing-karma
4.0.8 (2020-10-03)
Note: Version bump only for package
@open-wc/testing-karma
4.0.7 (2020-10-01)
Note: Version bump only for package
@open-wc/testing-karma
4.0.6 (2020-09-25)
Note: Version bump only for package
@open-wc/testing-karma
4.0.5 (2020-08-27)
Note: Version bump only for package
@open-wc/testing-karma
4.0.4 (2020-08-19)
Note: Version bump only for package
@open-wc/testing-karma
4.0.3 (2020-08-10)
... (truncated)
Commits
59e56d7
chore: release new versions16f4fb0
chore(testing-karma): release to update NPM readmede68e7b
docs: recommend WTR over karma (#1862)bbd5fa3
docs: coverageReporter global is defined on check instead of thresholdsfe8d529
chore: release new versionsb473d3e
chore: release new versions8017ebb
chore: release new versions5df01c8
chore: update axe-core to 4.x53b9d43
chore: release new versions2747a5b
chore: release new versions- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.