Bump ws and socket.io
Bumps ws and socket.io. These dependencies needed to be updated together.
Updates ws from 6.1.3 to 6.2.3
Release notes
Sourced from ws's releases.
6.2.3
Bug fixes
- Backported e55e5106 to the 6.x release line (eeb76d31).
6.2.2
Bug fixes
- Backported 00c425ec to the 6.x release line (78c676d2).
6.2.1
Bug fixes
- Fixed a bug that, under certain circumstances, prevented the close timer from being set (aa1dcd5).
6.2.0
Features
- Added ability to follow redirects (#1490).
Bug fixes
- The opening handshake is now aborted if the
Sec-WebSocket-Keyheader field value is invalid (160af45b).6.1.4
Bug fixes
- Fixed an issue that caused the
Hostheader to always include a port (#1510).
Commits
d87f3b6[dist] 6.2.3eeb76d3[security] Fix crash when the Upgrade header cannot be read (#2231)9bdb580[dist] 6.2.278c676d[security] Fix ReDoS vulnerabilityd57db27[dist] 6.2.140734d8[minor] Add missing option in JSDoc comment0556f31[doc] Add TOC to ws.md (#1539)aa1dcd5[fix] MakeWebSocket#close()set the close timer immediately297f56d[minor] Remove unneededifstatementbcab373[test] Increase code coverage- Additional commits viewable in compare view
Updates socket.io from 2.2.0 to 2.5.0
Release notes
Sourced from socket.io's releases.
2.5.0
:warning: WARNING :warning:
The default value of the
maxHttpBufferSizeoption has been decreased from 100 MB to 1 MB, in order to prevent attacks by denial of service.Security advisory: https://github.com/advisories/GHSA-j4f2-536g-r55m
Bug Fixes
- fix race condition in dynamic namespaces (05e1278)
- ignore packet received after disconnection (22d4bdf)
- only set 'connected' to true after middleware execution (226cc16)
- prevent the socket from joining a room after disconnection (f223178)
Links:
- Diff: https://github.com/socketio/socket.io/compare/2.4.1...2.5.0
- Client release: 2.5.0
- engine.io version:
~3.6.0(diff)- ws version:
~7.4.22.4.1
This release reverts the breaking change introduced in
2.4.0(https://github.com/socketio/socket.io/commit/f78a575f66ab693c3ea96ea88429ddb1a44c86c7).If you are using Socket.IO v2, you should explicitly allow/disallow cross-origin requests:
- without CORS (server and client are served from the same domain):
const io = require("socket.io")(httpServer, { allowRequest: (req, callback) => { callback(null, req.headers.origin === undefined); // cross-origin requests will not be allowed } });
- with CORS (server and client are served from distinct domains):
io.origins(["http://localhost:3000"]); // for local development io.origins(["https://example.com"]);In any case, please consider upgrading to Socket.IO v3, where this security issue is now fixed (CORS is disabled by default).
Reverts
- fix(security): do not allow all origins by default (a169050)
Links:
... (truncated)
Changelog
Sourced from socket.io's changelog.
2.5.0 (2022-06-26)
⚠️ WARNING ⚠️
The default value of the
maxHttpBufferSizeoption has been decreased from 100 MB to 1 MB, in order to prevent attacks by denial of service.Security advisory: GHSA-j4f2-536g-r55m
Bug Fixes
- fix race condition in dynamic namespaces (05e1278)
- ignore packet received after disconnection (22d4bdf)
- only set 'connected' to true after middleware execution (226cc16)
- prevent the socket from joining a room after disconnection (f223178)
Dependencies
engine.io@~3.6.0(https://github.com/socketio/engine.io/compare/3.5.0...3.6.0)ws@~7.4.2(no change)4.5.1 (2022-05-17)
Bug Fixes
- forward the local flag to the adapter when using fetchSockets() (30430f0)
- typings: add HTTPS server to accepted types (#4351) (9b43c91)
Dependencies
engine.io@~6.2.0(no change)ws@~8.2.3(no change)4.5.0 (2022-04-23)
Bug Fixes
Features
Catch-all listeners for outgoing packets
... (truncated)
Commits
baa6804chore(release): 2.5.0f223178fix: prevent the socket from joining a room after disconnection226cc16fix: only set 'connected' to true after middleware execution05e1278fix: fix race condition in dynamic namespaces22d4bdffix: ignore packet received after disconnectiondfded53chore: update engine.io version to 3.6.0e6b8697chore(release): 2.4.1a169050revert: fix(security): do not allow all origins by default873fdc5chore(release): 2.4.0f78a575fix(security): do not allow all origins by default- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.