Skip to content

Conversation

mend-for-github.amrom.workers.dev[bot]
Copy link

@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot commented Mar 26, 2024

This PR contains the following updates:

Package Type Update Change
express (source) dependencies minor 4.18.2 -> 4.21.1

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability
High High 7.5 CVE-2024-45296
High High 7.5 CVE-2024-45590
High High 7.5 CVE-2024-52798
Medium Medium 6.1 CVE-2024-29041
Medium Medium 5.3 CVE-2024-47764
Medium Medium 5.0 CVE-2024-43796
Medium Medium 5.0 CVE-2024-43799
Medium Medium 5.0 CVE-2024-43800

Release Notes

expressjs/express (express)

v4.21.1

Compare Source

What's Changed

Full Changelog: expressjs/express@4.21.0...4.21.1

v4.21.0

Compare Source

What's Changed

New Contributors

Full Changelog: expressjs/express@4.20.0...4.21.0

v4.20.0

Compare Source

==========

  • deps: serve-static@​0.16.0
    • Remove link renderization in html while redirecting
  • deps: send@​0.19.0
    • Remove link renderization in html while redirecting
  • deps: body-parser@​0.6.0
    • add depth option to customize the depth level in the parser
    • IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)
  • Remove link renderization in html while using res.redirect
  • deps: path-to-regexp@​0.1.10
    • Adds support for named matching groups in the routes using a regex
    • Adds backtracking protection to parameters without regexes defined
  • deps: encodeurl@~2.0.0
    • Removes encoding of \, |, and ^ to align better with URL spec
  • Deprecate passing options.maxAge and options.expires to res.clearCookie
    • Will be ignored in v5, clearCookie will set a cookie with an expires in the past to instruct clients to delete the cookie

v4.19.2

Compare Source

==========

  • Improved fix for open redirect allow list bypass

v4.19.1

Compare Source

==========

  • Allow passing non-strings to res.location with new encoding handling checks

v4.19.0

Compare Source

==========

  • Prevent open redirect allow list bypass due to encodeurl
  • deps: cookie@​0.6.0

v4.18.3

Compare Source

==========

  • Fix routing requests without method
  • deps: body-parser@​1.20.2
    • Fix strict json error message on Node.js 19+
    • deps: content-type@~1.0.5
    • deps: raw-body@​2.5.2
  • deps: cookie@​0.6.0
    • Add partitioned option

  • If you want to rebase/retry this PR, check this box

@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot added the security fix Security fix generated by Mend label Mar 26, 2024
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 9695c00 to 92da282 Compare September 11, 2024 12:27
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.19.0 chore(deps): update dependency express to v4.20.0 Sep 11, 2024
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.20.0 chore(deps): update dependency express to v4.21.2 Dec 6, 2024
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 92da282 to a2acf02 Compare December 6, 2024 19:33
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from a2acf02 to 304107d Compare January 27, 2025 06:00
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 304107d to 5b91fe9 Compare February 5, 2025 02:49
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 5b91fe9 to dc1080c Compare February 13, 2025 11:12
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from dc1080c to 648920d Compare February 23, 2025 11:29
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 648920d to 3052244 Compare March 4, 2025 09:48
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.21.2 chore(deps): update dependency express to v4.21.1 Mar 11, 2025
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 3052244 to c288c53 Compare March 11, 2025 07:04
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.21.1 chore(deps): update dependency express to v4.21.1 - autoclosed Mar 20, 2025
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot deleted the whitesource-remediate/express-4.x-lockfile branch March 20, 2025 12:33
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.21.1 - autoclosed chore(deps): update dependency express to v4.21.1 Mar 24, 2025
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 7ca18d5 to c288c53 Compare March 24, 2025 06:37
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.21.1 chore(deps): update dependency express to v4.20.0 Mar 30, 2025
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from c288c53 to 688d860 Compare March 30, 2025 13:27
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.20.0 chore(deps): update dependency express to v4.21.1 Apr 15, 2025
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 688d860 to b82e4af Compare April 15, 2025 12:48
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.21.1 chore(deps): update dependency express to v4.20.0 Aug 18, 2025
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from b82e4af to 61d9c68 Compare August 18, 2025 16:43
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 61d9c68 to c919b1b Compare September 18, 2025 00:37
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot changed the title chore(deps): update dependency express to v4.20.0 chore(deps): update dependency express to v4.21.1 Sep 18, 2025
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from c919b1b to 82eb4b2 Compare September 30, 2025 11:46
@mend-for-github.amrom.workers.dev mend-for-github.amrom.workers.dev bot force-pushed the whitesource-remediate/express-4.x-lockfile branch from 82eb4b2 to 80cf75c Compare October 1, 2025 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants