nestjs-status-monitor
nestjs-status-monitor copied to clipboard
Build(deps): bump engine.io and @nestjs/platform-socket.io
Bumps engine.io to 6.4.2 and updates ancestor dependency @nestjs/platform-socket.io. These dependencies need to be updated together.
Updates engine.io
from 3.5.0 to 6.4.2
Release notes
Sourced from engine.io's releases.
6.4.2
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
TypeError: Cannot read properties of undefined (reading 'handlesUpgrades') at Server.onWebSocket (build/server.js:515:67)
Please upgrade as soon as possible.
Bug Fixes
- include error handling for Express middlewares (#674) (9395782)
- prevent crash when provided with an invalid query param (fc480b4)
- typings: make clientsCount public (#675) (bd6d471)
- uws: prevent crash when using with middlewares (8b22162)
Credits
Huge thanks to
@tyilo
and@cieldeville
for helping!Links
- Diff: https://github.com/socketio/engine.io/compare/6.4.1...6.4.2
- Client release: -
- ws version: ~8.11.0 (no change)
6.4.1
This release contains 6e78489, which exports the
BaseServer
class in order to restore the compatibility with thenodenext
module resolution strategy of TypeScript.Reference: https://www.typescriptlang.org/tsconfig/#moduleResolution
Related: socketio/socket.io#4621
Links
- Diff: https://github.com/socketio/engine.io/compare/6.4.0...6.4.1
- Client release: -
- ws version: ~8.11.0 (no change)
6.4.0
Features
- add support for Express middlewares (24786e7)
This commit implements middlewares at the Engine.IO level, because Socket.IO middlewares are meant for namespace authorization and are not executed during a classic HTTP request/response cycle.
... (truncated)
Changelog
Sourced from engine.io's changelog.
6.4.2 (2023-05-02)
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
TypeError: Cannot read properties of undefined (reading 'handlesUpgrades') at Server.onWebSocket (build/server.js:515:67)
Please upgrade as soon as possible.
Bug Fixes
- include error handling for Express middlewares (#674) (9395782)
- prevent crash when provided with an invalid query param (fc480b4)
- typings: make clientsCount public (#675) (bd6d471)
- uws: prevent crash when using with middlewares (8b22162)
Credits
Huge thanks to
@tyilo
and@cieldeville
for helping!Dependencies
ws@~8.11.0
(no change)6.4.1 (2023-02-20)
This release contains 6e78489, which exports the
BaseServer
class in order to restore the compatibility with thenodenext
module resolution strategy of TypeScript.Reference: https://www.typescriptlang.org/tsconfig/#moduleResolution
Related: socketio/socket.io#4621
Dependencies
ws@~8.11.0
(no change)6.4.0 (2023-02-06)
... (truncated)
Commits
95e2153
chore(release): 6.4.2fc480b4
fix: prevent crash when provided with an invalid query param0141951
refactor(types): ensure compatibility with Express middlewares8b22162
fix(uws): prevent crash when using with middlewares9395782
fix: include error handling for Express middlewares (#674)911d0e3
refactor: return HTTP 400 upon invalid request overlapbd6d471
fix(typings): make clientsCount public (#675)7033c0e
chore(release): 6.4.16e78489
refactor: export BaseServer class (#669)535b068
docs: add upgrade event in the documentation- Additional commits viewable in compare view
Updates @nestjs/platform-socket.io
from 7.6.17 to 9.4.0
Release notes
Sourced from @nestjs/platform-socket
.io's releases.
v9.4.0 (2023-04-05)
Features
Bug fixes
platform-ws
- #11188 fix(ws): mount multi
ws
servers on different paths (@CodyTseng
)platform-express
Enhancements
microservices
- #11426 feat: allow extension of microservice event and message extras (
@effervescentia
)Dependencies
- Other
- #11394 chore(deps-dev): bump sinon from 15.0.2 to 15.0.3 (
@dependabot[bot]
)- #11406 chore(deps-dev): bump
@types/node
from 18.15.6 to 18.15.11 (@dependabot[bot]
)- #11418 chore(deps-dev): bump
@fastify/static
from 6.9.0 to 6.10.0 (@dependabot[bot]
)- #11419 chore(deps): bump fast-json-stringify from 5.6.2 to 5.7.0 (
@dependabot[bot]
)- #11422 chore(deps-dev): bump
@apollo/server
from 4.5.0 to 4.6.0 (@dependabot[bot]
)- #11423 chore(deps-dev): bump amqp-connection-manager from 4.1.11 to 4.1.12 (
@dependabot[bot]
)- #11424 chore(deps-dev): bump core-js from 3.29.1 to 3.30.0 (
@dependabot[bot]
)- #11405 chore(deps-dev): bump ts-morph from 17.0.1 to 18.0.0 (
@dependabot[bot]
)- #11403 fix(deps): update dependency
@nestjs/apollo
to v11.0.4 (@renovate[bot]
)- #11402 chore(deps): update dependency
@types/cache-manager
to v4.0.2 (@renovate[bot]
)- #11401 chore(deps): update dependency
@babel/core
to v7.21.3 (@renovate[bot]
)- #11407 chore(deps-dev): bump concurrently from 7.6.0 to 8.0.1 (
@dependabot[bot]
)- #11408 chore(deps-dev): bump
@commitlint/cli
from 17.5.0 to 17.5.1 (@dependabot[bot]
)- #11347 fix(deps): update dependency sequelize-typescript to v2.1.5 (
@renovate[bot]
)- #11344 fix(deps): update dependency
@nestjs/typeorm
to v9.0.1 (@renovate[bot]
)- #11343 fix(deps): update dependency
@nestjs/serve-static
to v3.0.1 (@renovate[bot]
)- #11342 fix(deps): update dependency
@nestjs/mongoose
to v9.2.2 (@renovate[bot]
)- #11340 fix(deps): update dependency
@nestjs/bull
to v0.6.3 (@renovate[bot]
)- #11351 chore(deps): update dependency
@types/amqplib
to v0.10.1 (@renovate[bot]
)- #11323 chore(deps-dev): bump
@grpc/proto-loader
from 0.7.5 to 0.7.6 (@dependabot[bot]
)- #11395 chore(deps-dev): bump prettier from 2.8.6 to 2.8.7 (
@dependabot[bot]
)- #11336 chore(deps): update dependency nodemon to v2.0.22 (
@renovate[bot]
)- #11339 chore(deps): update mysql docker tag to v8.0.32 (
@renovate[bot]
)- #11348 fix(deps): update dependency typeorm to v0.3.12 (
@renovate[bot]
)- #11349 chore(deps): update confluentinc/cp-kafka docker tag to v7.3.2 (
@renovate[bot]
)- #11366 fix(deps): update dependency
@fastify/view
to v7.4.1 (@renovate[bot]
)- #11376 fix(deps): update dependency socket.io to v4.6.1 (
@renovate[bot]
)- #11381 chore(deps): update mongo docker tag to v6 (
@renovate[bot]
)- #11384 fix(deps): update dependency mercurius to v12 (
@renovate[bot]
)- #11385 fix(deps): update dependency mongodb to v5 (
@renovate[bot]
)- #11387 fix(deps): update dependency mysql2 to v3 (
@renovate[bot]
)- #11389 fix(deps): update dependency rimraf to v4.4.1 (
@renovate[bot]
)
... (truncated)
Commits
676c98c
chore(@nestjs
) publish v9.4.0 release11f512c
sample: update 20-cache sample4be791f
Merge pull request #11426 from voiceflow/feat/extend-microservice-extrase990336
Merge branch 'master' of https://github.com/nestjs/nest06da94b
chore: assert type of route info objects402a389
Merge pull request #10228 from nathanArseneau/test/sample-02-gatewaysc885a89
Merge pull request #11188 from CodyTseng/fix-ws-multi-servers-on-different-paths718e704
chore: upgrade typescript9b6b00f
Merge branch 'master' into test/sample-02-gatewayse46147e
Merge branch 'master' into fix-ws-multi-servers-on-different-paths- Additional commits viewable in compare view
You can trigger a rebase of this PR by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.