Skip to content

Bump socket.io-parser from 4.2.5 to 4.2.7 - #69

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/socket.io-parser-4.2.7
Open

Bump socket.io-parser from 4.2.5 to 4.2.7#69
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/socket.io-parser-4.2.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown

Bumps socket.io-parser from 4.2.5 to 4.2.7.

Release notes

Sourced from socket.io-parser's releases.

socket.io-parser@4.2.7

Bug Fixes

  • honor toJSON() when deconstructing a binary packet (#5518) (57f1114)
  • reject binary packets with zero attachments (7c6ef57)

New Contributors

socket.io-parser@4.2.6

This release includes a fix for CVE-2026-33151. Please upgrade as soon as possible.

Bug Fixes

  • add a limit to the number of binary attachments (b25738c)
Commits
  • 4054894 chore(release): socket.io-parser@4.2.7
  • 7c6ef57 fix(parser): reject binary packets with zero attachments
  • 57f1114 fix(parser): honor toJSON() when deconstructing a binary packet (#5518)
  • 8d2e4f7 docs(security): add CVE-2026-59724 and CVE-2026-59725
  • d2d753f refactor(sio): align client file matching in Node.js HTTP server
  • dfb5ab3 fix(sio): prevent uWebSockets.js from serving missing client files
  • dcbd961 perf(eio): optimize polling request body buffering
  • 6bb2e7f refactor(sio): internalize base64id dependency
  • a80711a refactor(eio): internalize base64id dependency
  • 8bead0f chore: upgrade to TypeScript 6
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/socket.io-parser-4.2.7 branch from 3eb22f2 to 2e97e39 Compare August 6, 2026 02:28
@TheTrunk

TheTrunk commented Aug 6, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/socket.io-parser-4.2.7 branch from 2e97e39 to bed90d7 Compare August 6, 2026 10:18
Bumps [socket.io-parser](https://github.com/socketio/socket.io) from 4.2.5 to 4.2.7.
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/socket.io-parser@4.2.5...socket.io-parser@4.2.7)

---
updated-dependencies:
- dependency-name: socket.io-parser
  dependency-version: 4.2.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/socket.io-parser-4.2.7 branch from bed90d7 to 8016f12 Compare August 13, 2026 08:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant