build(deps): bump socket.io-parser from 4.2.6 to 4.2.7 in /plugins/draw - #130
mldangelo-oai merged 3 commits into
Conversation
Bumps [socket.io-parser](https://github.com/socketio/socket.io) from 4.2.6 to 4.2.7. - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/compare/socket.io-parser@4.2.6...socket.io-parser@4.2.7) --- updated-dependencies: - dependency-name: socket.io-parser dependency-version: 4.2.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review |
|
@codex security review |
|
Codex Review: Didn't find any major issues. Swish! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
🛡️ Codex Security ReviewSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
🤖 I have created a release *beep* *boop* --- ## [0.14.1](v0.14.0...v0.14.1) (2026-10-03) ### Features - Add `crab version` as an alias for checking the installed version ([#128](#128)). - Add `crab env encrypt <staging-dir> [output-file]` to retry snapshot encryption without rerunning the agent. Preserve staging on failure, reject existing backups and output inside staging, and handle relative paths and names beginning with a dash ([#68](#68)). ### Bug Fixes - Restore Draw canvas styling, initialize collaboration after the Excalidraw API is ready, and display collaborator cursors. Browser checks cover Mermaid conversion, shared edits, and scene reloads ([#118](#118)). - Patch Nano ID and lodash-es versions pinned inside Excalidraw dependencies, and update Sass to remove the vulnerable Chokidar/Braces chain ([#118](#118)). - Upgrade Zod to v4 ([#50](#50)), Excalidraw to v0.18.1 ([#104](#104)), and React to v19 ([#105](#105)). - Address Draw UI dependency alerts ([#102](#102)) and refresh plugin locks with patched Engine.IO, Socket.IO parser, Immutable, DOMPurify, Mermaid, PostCSS, Vite, and Vitest dependencies ([#116](#116), [#130](#130)). - Load Node type definitions explicitly so the Tax plugin compiles, and keep the Draw UI lockfile installable with npm 10 and 11 ([#116](#116)). ### Development - Upgrade all plugin compilers to TypeScript 7.0.2 and require at least Vite 8.0.16 and Vitest 4.1.11, while retaining Node 20/22/24 support ([#125](#125)). - Build and test every plugin on Node 20, 22, and 24; add Draw UI type checking and Promptfoo parser/configuration smoke tests ([#116](#116), [#125](#125)). - Update the pinned checkout, setup-node, and CI aggregation actions ([#124](#124), [#153](#153), [#154](#154)). --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Michael D'Angelo <mdangelo@openai.com>
Bumps socket.io-parser from 4.2.6 to 4.2.7.
Release notes
Sourced from socket.io-parser's releases.
Commits
4054894chore(release): socket.io-parser@4.2.77c6ef57fix(parser): reject binary packets with zero attachments57f1114fix(parser): honor toJSON() when deconstructing a binary packet (#5518)8d2e4f7docs(security): add CVE-2026-59724 and CVE-2026-59725d2d753frefactor(sio): align client file matching in Node.js HTTP serverdfb5ab3fix(sio): prevent uWebSockets.js from serving missing client filesdcbd961perf(eio): optimize polling request body buffering6bb2e7frefactor(sio): internalize base64id dependencya80711arefactor(eio): internalize base64id dependency8bead0fchore: upgrade to TypeScript 6Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Compatibility and validation
Also update the Draw UI's socket.io-parser copy from 4.2.6 to 4.2.7. Both lockfiles change only that package record; versions of Socket.IO and its client stay at 4.8.3. Exact shipped package/source/type comparisons confirm the patch's malformed-header rejection and binary
toJSONfixes without a protocol or type migration.Add eight parser contract/regression tests across CommonJS and ESM and two integration tests connecting the actual UI client to the Draw room server over loopback WebSocket and polling. These cover joining, participant notifications, scene/cursor updates, state requests, and disconnects. CI runs the integration tests alongside the existing Draw, Bats, and Shellcheck gates. An additive merge of main preserves the earlier Draw validation and lockfile fixes; the Dependabot commit is retained.
Validation: reproducible server/UI installs, server/UI builds, 10 unit tests, both room integration tests, and actual Draw CLI smoke pass on Node 20.20.2, 22.23.2, and 24.21.0. UI TypeScript check, 39 Bats tests, and CI-equivalent Shellcheck pass. The same parser regression suite against shipped 4.2.6 fails four cases and passes the other four; the malformed-input tests use one short in-process header with no attachment stream or external target.