NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2359 most downloaded on npm
default socket.io in-memory adapter
Last release 3 months ago
16 Jun 2026
Release timing varies
gaps range from 9 days to 1.5 years
Most releases are documented
notes for 20 of 30 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
32 releases · first in 2014
The ws dependency was bumped to ~8.21.0 following CVE-2026-48779 .
The ws dependency was bumped to ~8.21.0 following CVE-2026-48779.
The ws dependency was bumped to ~8.20.1 following CVE-2026-45736 .
The ws dependency was bumped to ~8.20.1 following CVE-2026-45736.
Note from the ws maintainers:
Although the calculated CVSS severity is medium, the actual severity is believed to be low, as the flaw is only exploitable through misuse that is unlikely in practice.
One column per quarter.
This release contains a bump of:
This release contains a bump of:
ws from ~8.17.1 to ~8.18.3debug from ~4.3.1 to ~4.4.1This release contains a bump of the ws dependency, which includes an important security fix.
This release contains a bump of the ws dependency, which includes an important security fix.
Advisory: https://github.com/advisories/GHSA-3h5v-q93c-6h6q
ensure the order of the commands
Two abstract classes were imported from the Redis adapter repository:
Two abstract classes were imported from the Redis adapter repository:
ClusterAdapter class, which manages the messages sent between the server instances of the clusterClusterAdapterWithHeartbeat class, which extends the ClusterAdapter and adds a heartbeat mechanism in order to check the healthiness of the other instancesOther adapters can then just extend those classes and only have to implement the pub/sub mechanism (and not the internal chit-chat protocol):
class MyAdapter extends ClusterAdapterWithHeartbeat {
constructor(nsp, pubSub, opts) {
super(nsp, opts);
this.pubSub = pubSub;
pubSub.subscribe("main-channel", (message) => this.onMessage(message));
pubSub.subscribe("specific-channel#" + this.uid, (response) => this.onResponse(response));
}
doPublish(message) {
return this.pubSub.publish("main-channel", message);
}
doPublishResponse(requesterUid, response) {
return this.pubSub.publish("specific-channel#" + requesterUid, response);
}
}
Besides, the number of "timeout reached: only x responses received out of y" errors (which can happen when a server instance leaves the cluster) should be greatly reduced by this commit.
The ws dependency was moved from peerDependencies to dependencies, in order to prevent issues like this.
The ws dependency was moved from peerDependencies to dependencies, in order to prevent issues like this.
properly precompute the WebSocket frames
implement connection state recovery
broadcast and expect multiple acks
fix broadcasting volatile packets with binary attachments
fix race condition when leaving rooms
restore compatibility with binary parsers
add a serverSideEmit empty function
allow excluding all sockets in a room
### Features * add room events (155fa63) * make rooms and sids public
Encoder#encode() is now synchronous
### Features * add init() and close() methods
Nothing published for this version
The dist/ directory was not up-to-date when publishing the previous version...
The dist/ directory was not up-to-date when publishing the previous version...
Encoder#encode() is now synchronous
### Features * use ES6 Sets and Maps
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →