Skip to content

Update dependency express to v4.22.1#22

Open
renovate[bot] wants to merge 1 commit intomasterfrom
updates/express-4.x-lockfile
Open

Update dependency express to v4.22.1#22
renovate[bot] wants to merge 1 commit intomasterfrom
updates/express-4.x-lockfile

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate Bot commented Dec 1, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
express (source) 4.17.14.22.1 age adoption passing confidence
@types/express (source) 4.17.134.17.25 age adoption passing confidence

Release Notes

expressjs/express (express)

v4.22.1

Compare Source

v4.22.0

Compare Source

v4.21.2

Compare Source

What's Changed

Full Changelog: expressjs/express@4.21.1...4.21.2

v4.21.1

Compare Source

What's Changed

Full Changelog: expressjs/express@4.21.0...4.21.1

v4.21.0

Compare Source

What's Changed

New Contributors

Full Changelog: expressjs/express@4.20.0...4.21.0

v4.20.0

Compare Source

==========

  • deps: serve-static@​0.16.0
    • Remove link renderization in html while redirecting
  • deps: send@​0.19.0
    • Remove link renderization in html while redirecting
  • deps: body-parser@​0.6.0
    • add depth option to customize the depth level in the parser
    • IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)
  • Remove link renderization in html while using res.redirect
  • deps: path-to-regexp@​0.1.10
    • Adds support for named matching groups in the routes using a regex
    • Adds backtracking protection to parameters without regexes defined
  • deps: encodeurl@~2.0.0
    • Removes encoding of \, |, and ^ to align better with URL spec
  • Deprecate passing options.maxAge and options.expires to res.clearCookie
    • Will be ignored in v5, clearCookie will set a cookie with an expires in the past to instruct clients to delete the cookie

v4.19.2

Compare Source

==========

  • Improved fix for open redirect allow list bypass

v4.19.1

Compare Source

==========

  • Allow passing non-strings to res.location with new encoding handling checks

v4.19.0

Compare Source

==========

  • Prevent open redirect allow list bypass due to encodeurl
  • deps: cookie@​0.6.0

v4.18.3

Compare Source

==========

  • Fix routing requests without method
  • deps: body-parser@​1.20.2
    • Fix strict json error message on Node.js 19+
    • deps: content-type@~1.0.5
    • deps: raw-body@​2.5.2
  • deps: cookie@​0.6.0
    • Add partitioned option

v4.18.2

Compare Source

===================

  • Fix regression routing a large stack in a single route
  • deps: body-parser@​1.20.1
    • deps: qs@​6.11.0
    • perf: remove unnecessary object clone
  • deps: qs@​6.11.0

v4.18.1

Compare Source

===================

  • Fix hanging on large stack of sync routes

v4.18.0

Compare Source

===================

  • Add "root" option to res.download
  • Allow options without filename in res.download
  • Deprecate string and non-integer arguments to res.status
  • Fix behavior of null/undefined as maxAge in res.cookie
  • Fix handling very large stacks of sync middleware
  • Ignore Object.prototype values in settings through app.set/app.get
  • Invoke default with same arguments as types in res.format
  • Support proper 205 responses using res.send
  • Use http-errors for res.format error
  • deps: body-parser@​1.20.0
    • Fix error message for json parse whitespace in strict
    • Fix internal error when inflated body exceeds limit
    • Prevent loss of async hooks context
    • Prevent hanging when request already read
    • deps: depd@​2.0.0
    • deps: http-errors@​2.0.0
    • deps: on-finished@​2.4.1
    • deps: qs@​6.10.3
    • deps: raw-body@​2.5.1
  • deps: cookie@​0.5.0
    • Add priority option
    • Fix expires option to reject invalid dates
  • deps: depd@​2.0.0
    • Replace internal eval usage with Function constructor
    • Use instance methods on process to check for listeners
  • deps: finalhandler@​1.2.0
    • Remove set content headers that break response
    • deps: on-finished@​2.4.1
    • deps: statuses@​2.0.1
  • deps: on-finished@​2.4.1
    • Prevent loss of async hooks context
  • deps: qs@​6.10.3
  • deps: send@​0.18.0
    • Fix emitted 416 error missing headers property
    • Limit the headers removed for 304 response
    • deps: depd@​2.0.0
    • deps: destroy@​1.2.0
    • deps: http-errors@​2.0.0
    • deps: on-finished@​2.4.1
    • deps: statuses@​2.0.1
  • deps: serve-static@​1.15.0
    • deps: send@​0.18.0
  • deps: statuses@​2.0.1
    • Remove code 306
    • Rename 425 Unordered Collection to standard 425 Too Early

v4.17.3

Compare Source

===================

  • deps: accepts@~1.3.8
    • deps: mime-types@~2.1.34
    • deps: negotiator@​0.6.3
  • deps: body-parser@​1.19.2
    • deps: bytes@​3.1.2
    • deps: qs@​6.9.7
    • deps: raw-body@​2.4.3
  • deps: cookie@​0.4.2
  • deps: qs@​6.9.7
    • Fix handling of __proto__ keys
  • pref: remove unnecessary regexp for trust proxy

v4.17.2

Compare Source

===================

  • Fix handling of undefined in res.jsonp
  • Fix handling of undefined when "json escape" is enabled
  • Fix incorrect middleware execution with unanchored RegExps
  • Fix res.jsonp(obj, status) deprecation message
  • Fix typo in res.is JSDoc
  • deps: body-parser@​1.19.1
    • deps: bytes@​3.1.1
    • deps: http-errors@​1.8.1
    • deps: qs@​6.9.6
    • deps: raw-body@​2.4.2
    • deps: safe-buffer@​5.2.1
    • deps: type-is@~1.6.18
  • deps: content-disposition@​0.5.4
    • deps: safe-buffer@​5.2.1
  • deps: cookie@​0.4.1
    • Fix maxAge option to reject invalid values
  • deps: proxy-addr@~2.0.7
    • Use req.socket over deprecated req.connection
    • deps: forwarded@​0.2.0
    • deps: ipaddr.js@​1.9.1
  • deps: qs@​6.9.6
  • deps: safe-buffer@​5.2.1
  • deps: send@​0.17.2
    • deps: http-errors@​1.8.1
    • deps: ms@​2.1.3
    • pref: ignore empty http tokens
  • deps: serve-static@​1.14.2
    • deps: send@​0.17.2
  • deps: setprototypeof@​1.2.0

Configuration

📅 Schedule: Branch creation - "before 3am on the first day of the month" in timezone America/Sao_Paulo, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Dec 1, 2023
@renovate renovate Bot changed the title Update dependency express to v4.18.2 Update dependency express to v4.18.3 Mar 1, 2024
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from a07a6b7 to f32614c Compare March 1, 2024 20:30
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from f32614c to 0bafc1b Compare March 22, 2024 23:51
@renovate renovate Bot changed the title Update dependency express to v4.18.3 Update dependency express to v4.19.1 Mar 22, 2024
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 0bafc1b to 6ff9da8 Compare March 26, 2024 23:45
@renovate renovate Bot changed the title Update dependency express to v4.19.1 Update dependency express to v4.19.2 Mar 26, 2024
@renovate renovate Bot changed the title Update dependency express to v4.19.2 Update dependency express to v4.20.0 Sep 10, 2024
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch 2 times, most recently from c016616 to a0a09bb Compare September 12, 2024 23:41
@renovate renovate Bot changed the title Update dependency express to v4.20.0 Update dependency express to v4.21.0 Sep 12, 2024
@renovate renovate Bot changed the title Update dependency express to v4.21.0 Update dependency express to v4.21.1 Oct 9, 2024
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from a0a09bb to 66fa291 Compare October 9, 2024 08:58
@renovate renovate Bot changed the title Update dependency express to v4.21.1 Update dependency express to v4.21.2 Dec 6, 2024
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 66fa291 to 7eb1bf8 Compare December 6, 2024 05:48
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 7eb1bf8 to 615cd70 Compare January 25, 2025 14:50
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 615cd70 to 2dc3a88 Compare February 9, 2025 12:07
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 2dc3a88 to c986202 Compare March 4, 2025 08:21
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from c986202 to 3b23885 Compare May 17, 2025 03:47
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 3b23885 to acb392b Compare June 7, 2025 16:09
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch 2 times, most recently from 155d787 to ff1332c Compare October 26, 2025 04:10
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from ff1332c to 3f55e18 Compare November 1, 2025 12:08
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 3f55e18 to 107fca4 Compare December 2, 2025 22:59
@renovate renovate Bot changed the title Update dependency express to v4.21.2 Update dependency express to v4.22.1 Dec 2, 2025
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 107fca4 to 918e313 Compare January 1, 2026 11:39
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 918e313 to 2e7cc41 Compare January 20, 2026 12:01
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 2e7cc41 to 3097417 Compare February 13, 2026 20:10
@renovate renovate Bot force-pushed the updates/express-4.x-lockfile branch from 3097417 to 903e00f Compare April 15, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants