socket.io@4.8.4
- cleanup pending acks on timeout to prevent memory leak (37aad11)
- prevent uWebSockets.js from serving missing client files (dfb5ab3)
- reject stateful regexps for dynamic namespaces (59f4f24)
- types: allow emitWithAck() for events with void callbacks (#5453) (8b93a18)
- types: properly import http module (74599a6)
engine.io@~6.6.0(no change)ws@~8.21.0(diff)
socket.io-client@4.8.4
- types: export ExtendedError for connect_error event (#5548) (c0d5450)
- types: export reserved event interfaces (#5533) (03945df)
engine.io-client@~6.6.1(no change)ws@~8.21.0(diff)
engine.io-client@6.6.7
- types: export reserved event interfaces (#5533) (ced7dfd)
- restore default transport resolution (3df3fed)
ws@~8.21.0(no change)
@socket.io/cluster-engine@0.1.1
engine.io@6.6.10
- reject protocol mismatch for existing sessions (86db1fc)
- restore compatibility with Node.js 10 (ae7fb46)
- run the polling write callback when the client aborts a compressed response (#5540) (915a3ed)
ws@~8.21.0(no change)
socket.io-parser@3.3.6
- reject binary packets with zero attachments (9c6323e)
socket.io-parser@3.4.5
- reject binary packets with zero attachments (ced94ff)
socket.io-parser@4.2.7
- honor toJSON() when deconstructing a binary packet (#5518) (57f1114)
- reject binary packets with zero attachments (7c6ef57)
- @spokodev made their first contribution in https://github.com/socketio/socket.io/pull/5518
socket.io-adapter@2.5.8
The ws dependency was bumped to ~8.21.0 following CVE-2026-48779.