All engine.io-client versions

engine.io-client @3.5.6

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
25
Risk Score
MIT
License
No
Install Scripts
11
Dependencies
26
Dev Dependencies
45.6 KB
Package Size
Published

Client for the realtime Engine

Maintainers

rauchgdarrachequesne

Dependencies (11)

PackageConstraintRegistry Status
ws ~7.5.10 auto_approved
debug ~3.1.0 auto_approved
yeast 0.1.2 auto_approved
indexof 0.0.1 auto_approved
parseqs 0.0.6 auto_approved
has-cors 1.1.0 auto_approved
parseuri 0.0.6 auto_approved
engine.io-parser ~2.2.0 auto_approved
component-emitter ~1.3.0 auto_approved
component-inherit 0.0.3 auto_approved
xmlhttprequest-ssl ~1.6.2 auto_approved

Dev Dependencies (26)

PackageConstraintRegistry Status
del ^2.2.2 auto_approved
blob ^0.0.4 auto_approved
gulp 3.9.1 No greenflagged match
zuul 3.11.1 Not imported
mocha ^3.2.0 auto_approved
express 4.15.2 No greenflagged match
webpack 1.12.12 auto_approved
istanbul ^0.4.5 No greenflagged match
derequire ^2.0.6 No greenflagged match
engine.io 3.4.0 No greenflagged match
expect.js ^0.3.1 auto_approved
gulp-file ^0.3.0 Not imported
babel-core ^6.24.0 auto_approved
gulp-mocha ^4.3.0 No greenflagged match
zuul-ngrok 4.0.0 Not imported
gulp-eslint 1.1.1 No greenflagged match
babel-eslint 4.1.7 auto_approved
babel-loader ^6.4.1 No greenflagged match
concat-stream ^1.6.0 auto_approved
gulp-istanbul ^1.1.1 Not imported
webpack-stream ^3.2.0 No greenflagged match
gulp-task-listing 1.0.1 Not imported
babel-preset-es2015 ^6.24.0 auto_approved
zuul-builder-webpack ^1.2.0 Not imported
eslint-config-standard 4.4.0 auto_approved
eslint-plugin-standard 1.3.1 auto_approved

Transitive Dependency Tree

18 transitive deps max depth 3
  ├─ component-emitter ~1.3.0 → 1.3.1
  ├─ component-inherit 0.0.3 → 0.0.3
  ├─ debug ~3.1.0 → 3.1.0
  ├─ engine.io-parser ~2.2.0 → 2.2.1
  ├─ has-cors 1.1.0 → 1.1.0
  ├─ indexof 0.0.1 → 0.0.1
  ├─ parseqs 0.0.6 → 0.0.6
  ├─ parseuri 0.0.6 → 0.0.6
  ├─ ws ~7.5.10 → 7.5.11
  ├─ xmlhttprequest-ssl ~1.6.2 → 1.6.3
├─ yeast 0.1.2 → 0.1.2
  ├─ after 0.8.2 → 0.8.2
  ├─ arraybuffer.slice ~0.0.7 → 0.0.7
  ├─ base64-arraybuffer 0.1.4 → 0.1.4
  ├─ blob 0.0.5 → 0.0.5
  ├─ has-binary2 ~1.0.2 → 1.0.3
├─ ms 2.0.0 → 2.0.0
  ├─ isarray 2.0.1 → 2.0.1

Changes from v6.6.3

Dependency Changes

ChangePackageVersion
added yeast 0.1.2
added indexof 0.0.1
added parseqs 0.0.6
added has-cors 1.1.0
added parseuri 0.0.6
added component-emitter ~1.3.0
added component-inherit 0.0.3
removed @socket.io/component-emitter ~3.1.0
changed ws ~8.17.1 → ~7.5.10
changed debug ~4.3.1 → ~3.1.0
changed engine.io-parser ~5.2.1 → ~2.2.0
changed xmlhttprequest-ssl ~2.1.1 → ~1.6.2

Script Changes

- build- compile- prepack- test:node- format:fix- bundle-size- format:check- test:browser- test:node-fetch- test:node-builtin-ws

File Changes

14 added 117 removed 3 modified size delta: -665.9 KB

Risk Dispositions (0 applicable to this version, 1 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Show 1 disposition(s) that do not match any finding on this version
Rule Source Disposition Author Reason
osv:GHSA-4r4m-hjwj-43p8 osv reject AI AI (osv): Insecure TLS default (MITM vulnerability) affects all versions < 1.6.9; fix is available. Verdict generalizes to all versions in the affected range, including 0.1.0.

SAST Findings (1)

HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

Review Summary

Risk score: 25. Findings: 1 high (+25), 2 info (+0).

Commit: f322bde7c2f6 Browse source

Published to npm: