Skip to content

Npm audit changes to fix engine.io vulnerability CVE-2022-21676#4262

Merged
darrachequesne merged 2 commits intosocketio:masterfrom
adamszegedi:npm-audit-engine-io-vulnerability
Jan 25, 2022
Merged

Npm audit changes to fix engine.io vulnerability CVE-2022-21676#4262
darrachequesne merged 2 commits intosocketio:masterfrom
adamszegedi:npm-audit-engine-io-vulnerability

Conversation

@adamszegedi
Copy link
Copy Markdown
Contributor

The kind of change this PR does introduce

  • a bug fix
  • a new feature
  • an update to the documentation
  • a code change that improves performance
  • other

Current behavior

New behavior

Other information (e.g. related issues)

Runned npm audit fix in order to update the engine.io dependency version. The new version fixes the vulnerability CVE-2022-21676

@darrachequesne darrachequesne merged commit 2f96438 into socketio:master Jan 25, 2022
@darrachequesne
Copy link
Copy Markdown
Member

@adamszegedi thanks a lot 👍

@ericmandel
Copy link
Copy Markdown

@darrachequesne Do you recommend that users do 'npm audit fix' on their v4.4.1 installed versions of socket.io to get the updated engine.io, or should we wait for the next release of socket.io containing the updated version?

@darrachequesne
Copy link
Copy Markdown
Member

@ericmandel yes, npm audit fix is the way to go 👍

@ericmandel
Copy link
Copy Markdown

Thanks, I just needed to know that the updated engine.io could be dropped in without code changes elsewhere in socket.io ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants