Skip to content

build(deps): bump socket.io-parser from 4.2.6 to 4.2.7 in /plugins/draw - #130

Merged
mldangelo-oai merged 3 commits into
mainfrom
dependabot/npm_and_yarn/plugins/draw/socket.io-parser-4.2.7
Sep 16, 2026
Merged

mldangelo-oai merged 3 commits into
mainfrom
dependabot/npm_and_yarn/plugins/draw/socket.io-parser-4.2.7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps socket.io-parser from 4.2.6 to 4.2.7.

Release notes

Sourced from socket.io-parser's releases.

socket.io-parser@4.2.7

Bug Fixes

  • honor toJSON() when deconstructing a binary packet (#5518) (57f1114)
  • reject binary packets with zero attachments (7c6ef57)

New Contributors

Commits
  • 4054894 chore(release): socket.io-parser@4.2.7
  • 7c6ef57 fix(parser): reject binary packets with zero attachments
  • 57f1114 fix(parser): honor toJSON() when deconstructing a binary packet (#5518)
  • 8d2e4f7 docs(security): add CVE-2026-59724 and CVE-2026-59725
  • d2d753f refactor(sio): align client file matching in Node.js HTTP server
  • dfb5ab3 fix(sio): prevent uWebSockets.js from serving missing client files
  • dcbd961 perf(eio): optimize polling request body buffering
  • 6bb2e7f refactor(sio): internalize base64id dependency
  • a80711a refactor(eio): internalize base64id dependency
  • 8bead0f chore: upgrade to TypeScript 6
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Compatibility and validation

Also update the Draw UI's socket.io-parser copy from 4.2.6 to 4.2.7. Both lockfiles change only that package record; versions of Socket.IO and its client stay at 4.8.3. Exact shipped package/source/type comparisons confirm the patch's malformed-header rejection and binary toJSON fixes without a protocol or type migration.

Add eight parser contract/regression tests across CommonJS and ESM and two integration tests connecting the actual UI client to the Draw room server over loopback WebSocket and polling. These cover joining, participant notifications, scene/cursor updates, state requests, and disconnects. CI runs the integration tests alongside the existing Draw, Bats, and Shellcheck gates. An additive merge of main preserves the earlier Draw validation and lockfile fixes; the Dependabot commit is retained.

Validation: reproducible server/UI installs, server/UI builds, 10 unit tests, both room integration tests, and actual Draw CLI smoke pass on Node 20.20.2, 22.23.2, and 24.21.0. UI TypeScript check, 39 Bats tests, and CI-equivalent Shellcheck pass. The same parser regression suite against shipped 4.2.6 fails four cases and passes the other four; the malformed-input tests use one short in-process header with no attachment stream or external target.

Bumps [socket.io-parser](https://github.com/socketio/socket.io) from 4.2.6 to 4.2.7.
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/socket.io-parser@4.2.6...socket.io-parser@4.2.7)

---
updated-dependencies:
- dependency-name: socket.io-parser
  dependency-version: 4.2.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 5, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-16T03:51:59.589046Z 32451a1 Manual request
🔒 Security Review ✅ Completed 2026-09-16T03:54:23.463289Z 32451a1 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@mldangelo-oai

Copy link
Copy Markdown
Contributor

@codex review

@mldangelo-oai

Copy link
Copy Markdown
Contributor

@codex security review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

Reviewed commit: 32451a1549

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review

Security review completed. No security issues were found in this pull request.

Reviewed commit: 32451a1549

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@mldangelo-oai
mldangelo-oai merged commit 35386f4 into main Sep 16, 2026
10 checks passed
@mldangelo-oai
mldangelo-oai deleted the dependabot/npm_and_yarn/plugins/draw/socket.io-parser-4.2.7 branch September 16, 2026 03:56
mldangelo-oai added a commit that referenced this pull request Oct 3, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.14.1](v0.14.0...v0.14.1)
(2026-10-03)

### Features

- Add `crab version` as an alias for checking the installed version
([#128](#128)).
- Add `crab env encrypt <staging-dir> [output-file]` to retry snapshot
encryption without rerunning the agent. Preserve staging on failure,
reject existing backups and output inside staging, and handle relative
paths and names beginning with a dash
([#68](#68)).

### Bug Fixes

- Restore Draw canvas styling, initialize collaboration after the
Excalidraw API is ready, and display collaborator cursors. Browser
checks cover Mermaid conversion, shared edits, and scene reloads
([#118](#118)).
- Patch Nano ID and lodash-es versions pinned inside Excalidraw
dependencies, and update Sass to remove the vulnerable Chokidar/Braces
chain ([#118](#118)).
- Upgrade Zod to v4
([#50](#50)), Excalidraw to
v0.18.1 ([#104](#104)), and
React to v19 ([#105](#105)).
- Address Draw UI dependency alerts
([#102](#102)) and refresh
plugin locks with patched Engine.IO, Socket.IO parser, Immutable,
DOMPurify, Mermaid, PostCSS, Vite, and Vitest dependencies
([#116](#116),
[#130](#130)).
- Load Node type definitions explicitly so the Tax plugin compiles, and
keep the Draw UI lockfile installable with npm 10 and 11
([#116](#116)).

### Development

- Upgrade all plugin compilers to TypeScript 7.0.2 and require at least
Vite 8.0.16 and Vitest 4.1.11, while retaining Node 20/22/24 support
([#125](#125)).
- Build and test every plugin on Node 20, 22, and 24; add Draw UI type
checking and Promptfoo parser/configuration smoke tests
([#116](#116),
[#125](#125)).
- Update the pinned checkout, setup-node, and CI aggregation actions
([#124](#124),
[#153](#153),
[#154](#154)).

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: Michael D'Angelo <mdangelo@openai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant