socket.io-redis-emitter
socket.io-redis-emitter copied to clipboard
build(deps): bump engine.io from 6.2.1 to 6.4.2
Bumps engine.io from 6.2.1 to 6.4.2.
Release notes
Sourced from engine.io's releases.
6.4.2
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
TypeError: Cannot read properties of undefined (reading 'handlesUpgrades') at Server.onWebSocket (build/server.js:515:67)
Please upgrade as soon as possible.
Bug Fixes
- include error handling for Express middlewares (#674) (9395782)
- prevent crash when provided with an invalid query param (fc480b4)
- typings: make clientsCount public (#675) (bd6d471)
- uws: prevent crash when using with middlewares (8b22162)
Credits
Huge thanks to
@tyilo
and@cieldeville
for helping!Links
- Diff: https://github.com/socketio/engine.io/compare/6.4.1...6.4.2
- Client release: -
- ws version: ~8.11.0 (no change)
6.4.1
This release contains 6e78489, which exports the
BaseServer
class in order to restore the compatibility with thenodenext
module resolution strategy of TypeScript.Reference: https://www.typescriptlang.org/tsconfig/#moduleResolution
Related: socketio/socket.io#4621
Links
- Diff: https://github.com/socketio/engine.io/compare/6.4.0...6.4.1
- Client release: -
- ws version: ~8.11.0 (no change)
6.4.0
Features
- add support for Express middlewares (24786e7)
This commit implements middlewares at the Engine.IO level, because Socket.IO middlewares are meant for namespace authorization and are not executed during a classic HTTP request/response cycle.
... (truncated)
Changelog
Sourced from engine.io's changelog.
6.4.2 (2023-05-02)
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
TypeError: Cannot read properties of undefined (reading 'handlesUpgrades') at Server.onWebSocket (build/server.js:515:67)
Please upgrade as soon as possible.
Bug Fixes
- include error handling for Express middlewares (#674) (9395782)
- prevent crash when provided with an invalid query param (fc480b4)
- typings: make clientsCount public (#675) (bd6d471)
- uws: prevent crash when using with middlewares (8b22162)
Credits
Huge thanks to
@tyilo
and@cieldeville
for helping!Dependencies
ws@~8.11.0
(no change)6.4.1 (2023-02-20)
This release contains 6e78489, which exports the
BaseServer
class in order to restore the compatibility with thenodenext
module resolution strategy of TypeScript.Reference: https://www.typescriptlang.org/tsconfig/#moduleResolution
Related: socketio/socket.io#4621
Dependencies
ws@~8.11.0
(no change)6.4.0 (2023-02-06)
... (truncated)
Commits
95e2153
chore(release): 6.4.2fc480b4
fix: prevent crash when provided with an invalid query param0141951
refactor(types): ensure compatibility with Express middlewares8b22162
fix(uws): prevent crash when using with middlewares9395782
fix: include error handling for Express middlewares (#674)911d0e3
refactor: return HTTP 400 upon invalid request overlapbd6d471
fix(typings): make clientsCount public (#675)7033c0e
chore(release): 6.4.16e78489
refactor: export BaseServer class (#669)535b068
docs: add upgrade event in the documentation- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
@dependabot rebase
Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate
.