Bump socket.io-parser and browser-sync in /2020
Type: Pull Request
State: Open
![dependabot[bot]](https://github.com/dependabot.png)
Association: None
Comments: 0
(5 days ago)
(5 days ago)
dependencies javascript
Bumps socket.io-parser to 4.2.4 and updates ancestor dependency browser-sync. These dependencies need to be updated together.
Updates socket.io-parser
from 3.2.0 to 4.2.4
Release notes
Sourced from socket.io-parser's releases.
4.2.4
Bug Fixes
- ensure reserved events cannot be used as event names (d9db473)
- properly detect plain objects (b0e6400)
Links
4.2.3
:warning: This release contains an important security fix :warning:
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
TypeError: Cannot convert object to primitive value at Socket.emit (node:events:507:25) at .../node_modules/socket.io/lib/socket.js:531:14
Please upgrade as soon as possible.
Bug Fixes
- check the format of the event name (3b78117)
Links
4.2.2
Bug Fixes
- calling destroy() should clear all internal state (22c42e3)
- do not modify the input packet upon encoding (ae8dd88)
Links
4.2.1
Bug Fixes
- check the format of the index of each attachment (b5d0cb7)
Links
... (truncated)
Changelog
Sourced from socket.io-parser's changelog.
4.2.4 (2023-05-31)
Bug Fixes
- ensure reserved events cannot be used as event names (d9db473)
- properly detect plain objects (b0e6400)
3.4.3 (2023-05-22)
Bug Fixes
- check the format of the event name (2dc3c92)
4.2.3 (2023-05-22)
Bug Fixes
- check the format of the event name (3b78117)
4.2.2 (2023-01-19)
Bug Fixes
- calling destroy() should clear all internal state (22c42e3)
- do not modify the input packet upon encoding (ae8dd88)
3.3.3 (2022-11-09)
Bug Fixes
- check the format of the index of each attachment (fb21e42)
3.4.2 (2022-11-09)
... (truncated)
Commits
164ba2a
chore(release): 4.2.4b0e6400
fix: properly detect plain objectsd9db473
fix: ensure reserved events cannot be used as event names6a5a004
docs(changelog): include changelog for release 3.4.3b6c824f
chore(release): 4.2.3dcc70d9
refactor: export typescript declarations for the commonjs build3b78117
fix: check the format of the event name0841bd5
chore: bump ua-parser-js from 1.0.32 to 1.0.33 (#121)28dd668
chore(release): 4.2.222c42e3
fix: calling destroy() should clear all internal state- Additional commits viewable in compare view
Updates browser-sync
from 2.26.12 to 2.29.3
Release notes
Sourced from browser-sync's releases.
The one that fixes snippetOptions
What's Changed
- fix: append to head if body not present yet - fixes #2031 by
@shakyShane
in BrowserSync/browser-sync#2041Full Changelog: https://github.com/BrowserSync/browser-sync/compare/v2.29.2...v2.29.3
v2.29.1
What's Changed
- trim-deps by
@shakyShane
in BrowserSync/browser-sync#2028Full Changelog: https://github.com/BrowserSync/browser-sync/compare/v2.29.0...v2.29.1
The one that restores IE11 support 💪
What's Changed
- fix ie11 by
@shakyShane
in BrowserSync/browser-sync#2024esbuild does not support down-level transpiling as far as IE11 - so when I switched to it, it accidentally broke
IE11
support 😢This is an important issue for me - many devs that support old browsers like IE11 are doing so because their projects are used in public services, or internal applications. Not every developer out there has the luxury of supporting evergreen-only browsers.
So, IE11 will work once again 🎉. Please use the issues thread to make me aware of any problem that's preventing you from using Browsersync in your day job 💪 (and be sure to thumbs-up the issues you want to see resolved)
# IE11 works, again npm install browser-sync@latest
Full Changelog: https://github.com/BrowserSync/browser-sync/compare/v2.28.3...v2.29.0
the one that finally removes
document.write
What's Changed
- browser-sync-2017 use chalk everywhere by
@shakyShane
in BrowserSync/browser-sync#2018- fix: remove document.write by
@shakyShane
in BrowserSync/browser-sync#2019Full Changelog: https://github.com/BrowserSync/browser-sync/compare/v2.27.12...v2.28.0
2.27.9
What's Changed
- fix(cli): Where's the command help? fixes #1929 by
@shakyShane
in BrowserSync/browser-sync#1945A bug prevented the help output from displaying - it was introduced when the CLI parser
yargs
was updated, and is now fixed :)Full Changelog: https://github.com/BrowserSync/browser-sync/compare/v2.27.8...v2.27.9
... (truncated)
Commits
02efdff
v2.29.362d906e
fix: append to head if body not present yet - fixes #2031 (#2041)f91440e
v2.29.2d0c50e0
deps: drop qs (#2040)6ffc212
v2.29.17b07798
v2.29.1-alpha.0497f216
remove client depsbed04d4
v2.29.087421b5
fix: ie11 support (#2024)59eb01a
v2.28.3- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Pull Request Statistics
1
1
+2604
-1752
Package Dependencies
browser-sync
npm
2.26.12 → 2.29.3
Minor
/2020
socket.io-parser
npm
3.2.0 → 4.2.4
Major
/2020
Technical Details
ID: | 6886934 |
UUID: | 2792794846 |
Node ID: | PR_kwDOBQltU86mdqre |
Host: | GitHub |
Repository: | Daniel528/daniel528.github.io |
Merge State: | Unknown |