Skip to content

[Recovery] chore(deps)(deps): bump socket.io from 4.8.1 to 4.8.3 in /apps/api#35

Merged
LessUp merged 1 commit intomasterfrom
recovery/pr-16-chore-deps-deps-bump-socket-io-from-4-8--4634726
Apr 27, 2026
Merged

[Recovery] chore(deps)(deps): bump socket.io from 4.8.1 to 4.8.3 in /apps/api#35
LessUp merged 1 commit intomasterfrom
recovery/pr-16-chore-deps-deps-bump-socket-io-from-4-8--4634726

Conversation

@LessUp
Copy link
Copy Markdown
Owner

@LessUp LessUp commented Apr 27, 2026

Recovered from closed PR #16 because the original Dependabot branch was deleted.

Original PR: #16

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 27, 2026

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/socket.io 4.8.3 🟢 6.4
Details
CheckScoreReason
Code-Review⚠️ 1Found 5/30 approved changesets -- score normalized to 1
Maintained🟢 1021 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Security-Policy🟢 10security policy file detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 9binaries present in source code
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Packaging🟢 10packaging workflow detected
Pinned-Dependencies⚠️ 1dependency not pinned by hash detected -- score normalized to 1
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • apps/api/package-lock.json

@LessUp LessUp marked this pull request as ready for review April 27, 2026 11:06
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@LessUp LessUp force-pushed the recovery/pr-16-chore-deps-deps-bump-socket-io-from-4-8--4634726 branch from 4634726 to caa5c95 Compare April 27, 2026 11:09
@LessUp LessUp merged commit 450dedd into master Apr 27, 2026
3 of 4 checks passed
@LessUp LessUp deleted the recovery/pr-16-chore-deps-deps-bump-socket-io-from-4-8--4634726 branch April 27, 2026 11:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants