koa.io
koa.io copied to clipboard
[Snyk] Security upgrade socket.io from 1.3.7 to 2.0.0
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Denial of Service (DoS) SNYK-JS-SOCKETIOPARSER-1056752 |
Yes | Proof of Concept | |
| 704/1000 Why? Has a fix available, CVSS 9.8 |
Improper Input Validation SNYK-JS-SOCKETIOPARSER-3091012 |
Yes | No Known Exploit | |
| 589/1000 Why? Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) npm:parsejson:20170908 |
Yes | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: socket.io
The new version differs by 250 commits.- 3367eaa [chore] Release 2.0.0
- 6c0705f [docs] Add an example of custom parser (#2929)
- 1980fb4 [chore] Merge history of 1.7.x and 0.9.x branches (#2930)
- 0d07c47 [chore] Added backers and sponsors on the README (#2933)
- a086588 [chore] Bump dependencies (#2926)
- 87b06ad [feat] Move binary detection to the parser (#2923)
- 199eec6 [docs] Replace non-breaking space with proper whitespace (#2913)
- f1b39a6 [docs] Update emit cheatsheet (#2906)
- 240b154 [docs] Explicitly document that Server extends EventEmitter (#2874)
- c5b7738 [docs] Add server.engine.generateId attribute (#2880)
- 03f3bc9 [docs] Fix wrong space character in README (#2900)
- e40accf [docs] Fix documentation for 'connect' event (#2898)
- 01a4623 [feat] Allow to join several rooms at once (#2879)
- 2d5b002 [docs] Add webpack build example (#2828)
- 5ae06e6 [chore] Bump socket.io-adapter to version 1.0.0 (#2867)
- 4d8f68c [chore] Bump engine.io to version 2.0.2 (#2864)
- 5b79ab1 [docs] Update the wording to match the code example (#2853)
- 54ff591 [feature] Merge Engine.IO and Socket.IO handshake packets (#2833)
- e1facd5 [docs] Small addition to the Express Readme Part (#2846)
- 3b92cc2 [feature] Allow the use of custom parsers (#2829)
- 3d695c6 [chore] Bump engine.io to version 2.0.0 (#2832)
- 3b5f433 [fix] Use path.resolve by default and require.resolve as a fallback (#2797)
- 23c9dd3 [docs] Add a 'Features' section in the README (#2824)
- e28b475 [docs] Add httpd cluster example (#2819)
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
New dependencies detected. Learn more about Socket for GitHub ↗︎
| Packages | Version | New capabilities | Transitives | Size | Publisher |
|---|---|---|---|---|---|
| socket.io | 2.0.0 | network, filesystem, environment | +30 |
16.3 MB | darrachequesne |