nodejs-error-reporting
nodejs-error-reporting copied to clipboard
chore(deps): update dependency express to v5
This PR contains the following updates:
| Package | Change | Age | Confidence |
|---|---|---|---|
| express (source) | ^4.17.1 -> ^5.0.0 |
||
| @types/express (source) | ^4.17.21 -> ^5.0.0 |
Release Notes
expressjs/express (express)
v5.2.1
=======================
- Revert security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
v5.2.0
========================
- Security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
- deps:
body-parser@^2.2.1 - A deprecation warning was added when using
res.redirectwith undefined arguments, Express now emits a warning to help detect calls that pass undefined as the status or URL and make them easier to fix.
v5.1.0
========================
- Add support for
Uint8Arrayinres.send() - Add support for ETag option in
res.sendFile() - Add support for multiple links with the same rel in
res.links() - Add funding field to package.json
- perf: use loop for acceptParams
- refactor: prefix built-in node module imports
- deps: remove
setprototypeof - deps: remove
safe-buffer - deps: remove
utils-merge - deps: remove
methods - deps: remove
depd - deps:
debug@^4.4.0 - deps:
body-parser@^2.2.0 - deps:
router@^2.2.0 - deps:
content-type@^1.0.5 - deps:
finalhandler@^2.1.0 - deps:
qs@^6.14.0 - deps:
[email protected] - deps:
[email protected]
v5.0.1
==========
- Update
cookiesemver lock to address CVE-2024-47764
v5.0.0
=========================
- remove:
-
path-is-absolutedependency - usepath.isAbsoluteinstead
-
- breaking:
-
res.status()accepts only integers, and input must be greater than 99 and less than 1000- will throw a
RangeError: Invalid status code: ${code}. Status code must be greater than 99 and less than 1000.for inputs outside this range - will throw a
TypeError: Invalid status code: ${code}. Status code must be an integer.for non integer inputs
- will throw a
- deps: send@1.0.0
-
res.redirect('back')andres.location('back')is no longer a supported magic string, explicitly usereq.get('Referrer') || '/'.
-
- change:
-
res.clearCookiewill ignore user providedmaxAgeandexpiresoptions
-
- deps: cookie-signature@^1.2.1
- deps: debug@4.3.6
- deps: merge-descriptors@^2.0.0
- deps: serve-static@^2.1.0
- deps: qs@6.13.0
- deps: accepts@^2.0.0
- deps: mime-types@^3.0.0
-
application/javascript=>text/javascript
-
- deps: type-is@^2.0.0
- deps: content-disposition@^1.0.0
- deps: finalhandler@^2.0.0
- deps: fresh@^2.0.0
- deps: body-parser@^2.0.1
- deps: send@^1.1.0
Configuration
📅 Schedule: Branch creation - "after 9am and before 3pm" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
- [ ] If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.