Skip to content

fix: override socket.io-parser to >=4.2.6 (GHSA-677m-j7p3-52f9)#204

Merged
tmm merged 1 commit intomainfrom
fix/socket-audit
Mar 19, 2026
Merged

fix: override socket.io-parser to >=4.2.6 (GHSA-677m-j7p3-52f9)#204
tmm merged 1 commit intomainfrom
fix/socket-audit

Conversation

@brendanjryan
Copy link
Collaborator

Adds a pnpm override for socket.io-parser@>=4.0.0 <4.2.64.2.6 to resolve the high-severity advisory GHSA-677m-j7p3-52f9 (unbounded binary attachments in socket.io). Transitive dep via @metamask/sdk in examples/charge-wagmi. This was causing pnpm audit (and CI) to fail.

@brendanjryan brendanjryan requested a review from tmm March 19, 2026 15:27
@pkg-pr-new
Copy link

pkg-pr-new bot commented Mar 19, 2026

Open in StackBlitz

npm i https://pkg.pr.new/mppx@204

commit: 7fc0fef

@tmm tmm merged commit dd0684d into main Mar 19, 2026
9 of 11 checks passed
@tmm tmm deleted the fix/socket-audit branch March 19, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants