Closed
Description
Issue details
There is a security issue with the current version of socket.io
https://www.npmjs.com/advisories/1609
The advisory from npm is to "Update to version 2.4.0 or later."
Steps to reproduce/test case
Simply npm install and you will get the security issue reported
https://www.npmjs.com/advisories/1609
Please specify which version of Browsersync, node and npm you're running
- Browsersync [ X ]
- Node [ ]
- Npm [ ]
Affected platforms
- linuxwindowsOS Xfreebsdsolarisother (please specify which)
Metadata
Metadata
Assignees
Labels
No labels
Activity
abbyblachman commentedon Mar 12, 2021
+1
mef commentedon Mar 19, 2021
The latest version of browser-sync already uses socket.io v2.4.0 (source), you might want to update browser-sync in your app.
casingh1990 commentedon May 13, 2021
Please see
I think based on these we may need to consider:
rishi241424 commentedon Jun 2, 2021
My browser-synch version is 2.26.14 (latest version), but still my my scan reports says HIGH Serverity for this engine and socket packages.
engine.io:3.5.0
socket.io-parser:3.3.2
lachieh commentedon Feb 24, 2022
There are a number of issues that keep getting created for this security warning. What is required to get the updated socket.io package merged?
abbyblachman commentedon Mar 2, 2022
+1
stratboy commentedon Mar 4, 2022
Same problem here
256 remaining items