pbchess
pbchess copied to clipboard
[Snyk] Security upgrade socket.io from 2.3.0 to 3.0.0
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- server/package.json
- server/package-lock.json
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
![]() |
776/1000 Why? Recently disclosed, Has a fix available, CVSS 9.8 |
Improper Input Validation SNYK-JS-SOCKETIOPARSER-3091012 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: socket.io
The new version differs by 57 commits.- 1af3267 chore(release): 3.0.0
- 02951c4 chore(release): 3.0.0-rc4
- 54bf4a4 feat: emit an Error object upon middleware error
- aa7574f feat: serve msgpack bundle
- 64056d6 docs(examples): update TypeScript example
- cacad70 chore(release): 3.0.0-rc3
- d16c035 refactor: rename ERROR to CONNECT_ERROR
- 5c73733 feat: add support for catch-all listeners
- 129c641 feat: make Socket#join() and Socket#leave() synchronous
- 0d74f29 refactor(typings): export Socket class
- 7603da7 feat: remove prod dependency to socket.io-client
- a81b9f3 docs(examples): add example with TypeScript
- 20ea6bd docs(examples): add example with ES modules
- 0ce5b4c chore(release): 3.0.0-rc2
- 8a5db7f refactor: remove duplicate _sockets map
- 2a05042 refactor: add additional typings
- 91cd255 fix: close clients with no namespace
- 58b66f8 refactor: hide internal methods and properties
- 669592d feat: move binary detection back to the parser
- 2d2a31e chore: publish the wrapper.mjs file
- ebb0575 chore(release): 3.0.0-rc1
- c0d171f test: use the reconnect event of the Manager
- 9c7a48d test: use the complete export name
- 4bd5b23 feat: throw upon reserved event names
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
Codecov Report
Base: 15.86% // Head: 15.86% // No change to project coverage :thumbsup:
Coverage data is based on head (
d966a9a
) compared to base (2c8ed29
). Patch has no changes to coverable lines.
Additional details and impacted files
@@ Coverage Diff @@
## develop #159 +/- ##
========================================
Coverage 15.86% 15.86%
========================================
Files 56 56
Lines 1305 1305
Branches 227 227
========================================
Hits 207 207
Misses 1098 1098
Flag | Coverage Δ | |
---|---|---|
unittest | 15.86% <ø> (ø) |
Flags with carried forward coverage won't be shown. Click here to find out more.
Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.
:umbrella: View full report at Codecov.
:loudspeaker: Do you have feedback about the report comment? Let us know in this issue.