Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[Snyk] Upgrade engine.io from 1.4.0 to 1.8.5 #4

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade engine.io from 1.4.0 to 1.8.5.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 29 versions ahead of your current version.
  • The recommended version was released 4 years ago, on 2017-12-27.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
npm:ms:20151024
479/1000
Why? Has a fix available, CVSS 5.3
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: engine.io
  • 1.8.5 - 2017-12-27
  • 1.8.4 - 2017-04-28
  • 1.8.3 - 2017-02-16
  • 1.8.2 - 2016-12-10
  • 1.8.1 - 2016-11-27
  • 1.8.0 - 2016-11-20
  • 1.7.2 - 2016-10-23
  • 1.7.1 - 2016-10-20
  • 1.7.0 - 2016-10-05
  • 1.6.11 - 2016-06-24
  • 1.6.10 - 2016-06-24
  • 1.6.9 - 2016-05-03
  • 1.6.8 - 2016-01-25
  • 1.6.7 - 2016-01-11
  • 1.6.6 - 2016-01-08
  • 1.6.5 - 2016-01-05
  • 1.6.4 - 2015-12-04
  • 1.6.3 - 2015-12-01
  • 1.6.2 - 2015-11-30
  • 1.6.1 - 2015-11-29
  • 1.6.0 - 2015-11-28
  • 1.5.4 - 2015-09-09
  • 1.5.3 - 2015-09-09
  • 1.5.2 - 2015-07-09
  • 1.5.1 - 2015-01-19
  • 1.5.0 - 2015-01-18
  • 1.4.3 - 2014-11-21
  • 1.4.2 - 2014-10-27
  • 1.4.1 - 2014-10-03
  • 1.4.0 - 2014-09-03
from engine.io GitHub release notes
Commit messages
Package name: engine.io

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant