build(deps): bump engine.io and socket.io
Created by: dependabot[bot]
Bumps engine.io and socket.io. These dependencies needed to be updated together.
Updates engine.io
from 6.2.1 to 6.4.2
Release notes
Sourced from engine.io's releases.
6.4.2
⚠ This release contains an important security fix⚠ A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
TypeError: Cannot read properties of undefined (reading 'handlesUpgrades') at Server.onWebSocket (build/server.js:515:67)
Please upgrade as soon as possible.
Bug Fixes
- include error handling for Express middlewares (#674) (9395782)
- prevent crash when provided with an invalid query param (fc480b4)
- typings: make clientsCount public (#675) (bd6d471)
- uws: prevent crash when using with middlewares (8b22162)
Credits
Huge thanks to
@tyilo
and@cieldeville
for helping!Links
- Diff: https://github.com/socketio/engine.io/compare/6.4.1...6.4.2
- Client release: -
- ws version: ~8.11.0 (no change)
6.4.1
This release contains 6e78489, which exports the
BaseServer
class in order to restore the compatibility with thenodenext
module resolution strategy of TypeScript.Reference: https://www.typescriptlang.org/tsconfig/#moduleResolution
Related: socketio/socket.io#4621
Links
- Diff: https://github.com/socketio/engine.io/compare/6.4.0...6.4.1
- Client release: -
- ws version: ~8.11.0 (no change)
6.4.0
Features
- add support for Express middlewares (24786e7)
This commit implements middlewares at the Engine.IO level, because Socket.IO middlewares are meant for namespace authorization and are not executed during a classic HTTP request/response cycle.
... (truncated)
Changelog
Sourced from engine.io's changelog.
6.4.2 (2023-05-02)
⚠ This release contains an important security fix⚠ A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
TypeError: Cannot read properties of undefined (reading 'handlesUpgrades') at Server.onWebSocket (build/server.js:515:67)
Please upgrade as soon as possible.
Bug Fixes
- include error handling for Express middlewares (#674) (9395782)
- prevent crash when provided with an invalid query param (fc480b4)
- typings: make clientsCount public (#675) (bd6d471)
- uws: prevent crash when using with middlewares (8b22162)
Credits
Huge thanks to
@tyilo
and@cieldeville
for helping!Dependencies
ws@~8.11.0
(no change)6.4.1 (2023-02-20)
This release contains 6e78489, which exports the
BaseServer
class in order to restore the compatibility with thenodenext
module resolution strategy of TypeScript.Reference: https://www.typescriptlang.org/tsconfig/#moduleResolution
Related: socketio/socket.io#4621
Dependencies
ws@~8.11.0
(no change)6.4.0 (2023-02-06)
... (truncated)
Commits
-
95e2153
chore(release): 6.4.2 -
fc480b4
fix: prevent crash when provided with an invalid query param -
0141951
refactor(types): ensure compatibility with Express middlewares -
8b22162
fix(uws): prevent crash when using with middlewares -
9395782
fix: include error handling for Express middlewares (#674) -
911d0e3
refactor: return HTTP 400 upon invalid request overlap -
bd6d471
fix(typings): make clientsCount public (#675) -
7033c0e
chore(release): 6.4.1 -
6e78489
refactor: export BaseServer class (#669) -
535b068
docs: add upgrade event in the documentation - Additional commits viewable in compare view
Updates socket.io
from 4.5.4 to 4.6.1
Release notes
Sourced from socket.io's releases.
4.6.1
Bug Fixes
- properly handle manually created dynamic namespaces (0d0a7a2)
- types: fix nodenext module resolution compatibility (#4625) (d0b22c6)
Links
- Diff: https://github.com/socketio/socket.io/compare/4.6.0...4.6.1
- Client release: 4.6.1
engine.io@~6.4.1
(diff)ws@~8.11.0
(no change)4.6.0
Bug Fixes
- add timeout method to remote socket (#4558) (0c0eb00)
- typings: properly type emits with timeout (f3ada7d)
Features
Promise-based acknowledgements
This commit adds some syntactic sugar around acknowledgements:
emitWithAck()
try { const responses = await io.timeout(1000).emitWithAck("some-event"); console.log(responses); // one response per client } catch (e) { // some clients did not acknowledge the event in the given delay } io.on("connection", async (socket) => { // without timeout const response = await socket.emitWithAck("hello", "world"); // with a specific timeout try { const response = await socket.timeout(1000).emitWithAck("hello", "world"); } catch (err) { // the client did not acknowledge the event in the given delay } });
serverSideEmitWithAck()
... (truncated)
Changelog
Sourced from socket.io's changelog.
4.6.1 (2023-02-20)
Bug Fixes
- properly handle manually created dynamic namespaces (0d0a7a2)
- types: fix nodenext module resolution compatibility (#4625) (d0b22c6)
Dependencies
engine.io@~6.4.0
(no change)ws@~8.11.0
(no change)4.6.0 (2023-02-07)
Bug Fixes
- add timeout method to remote socket (#4558) (0c0eb00)
- typings: properly type emits with timeout (f3ada7d)
Features
Promise-based acknowledgements
This commit adds some syntactic sugar around acknowledgements:
emitWithAck()
try { const responses = await io.timeout(1000).emitWithAck("some-event"); console.log(responses); // one response per client } catch (e) { // some clients did not acknowledge the event in the given delay } io.on("connection", async (socket) => { // without timeout const response = await socket.emitWithAck("hello", "world"); // with a specific timeout try { const response = await socket.timeout(1000).emitWithAck("hello", "world"); } catch (err) { // the client did not acknowledge the event in the given delay </tr></table>
... (truncated)
Commits
-
7952312
chore(release): 4.6.1 -
0d0a7a2
fix: properly handle manually created dynamic namespaces -
2a8565f
refactor: catch errors when trying to restore the connection state -
d0b22c6
fix(types): fix nodenext module resolution compatibility (#4625) -
e71f3d7
docs: minor style fix (#4619) -
a2e5d1f
chore(release): 4.6.0 -
d8143cc
refactor: do not persist session if connection state recovery if disabled -
b2dd7cf
chore: bump engine.io to version 6.4.0 -
3734b74
revert: feat: expose current offset to allow deduplication -
8aa9499
feat: add description to the disconnecting and disconnect events (#4622) - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.