Skip to content

Invalid "heartbeat interval" option when using engine.io@^4.0.0 #1925

Description

@chris-allen

In attempting to comply with CVE-2020-36048, forcing engine.io to resolve to ^4.0.0 results in the following error:

Option heartbeat interval is not valid. Please refer to the README.

I don't see the removal of the heartbeat interval option called out in the enginge.io CHANGELOG, but there is this blog post about the engine.io 4 release (now on 6.1.2).

Browsersync Node Npm
2.27.7 4.18.3 6.14.15

Usage

gulp.task('watch', function() {
  browserSync.init({
    socket: {
      domain: 'myapp-sync.lndo.site'
    },
    logLevel: 'silent',
    notify: false,
    cors: true,
    server: {
      baseDir: '.',
    },
    open: false,
  });
  ...
});

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions