Skip to content

Conversation

@andrew
Copy link
Contributor

@andrew andrew commented Dec 21, 2017

The kind of change this PR does introduce

  • a bug fix
  • a new feature
  • an update to the documentation
  • a code change that improves performance
  • other

Current behaviour

accepts locked to 1.3.3 in package.json

New behaviour

accepts locked to 1.3.4 in package.json

Other information (e.g. related issues)

I stumbled upon this whilst trying to reduce the number of dependencies that require multiple different versions of the same dependency within the tree

@darrachequesne darrachequesne merged commit 3b0aef0 into socketio:master Dec 27, 2017
@darrachequesne
Copy link
Member

Thanks!

@andrew andrew deleted the bump-accepts branch December 28, 2017 20:45
@darrachequesne darrachequesne added this to the 3.1.5 milestone Feb 25, 2018
darrachequesne pushed a commit that referenced this pull request May 8, 2020
The package concat-stream is known to be vulnerable prior 1.5.2.
 
Source: https://snyk.io/vuln/npm:concat-stream:20160901
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants