Skip to content

fix(deps): update dependency express to v5 - #131

Open
renovate[bot] wants to merge 1 commit into
devfrom
renovate/express-5.x
Open

renovate[bot] wants to merge 1 commit into
devfrom
renovate/express-5.x

Conversation

@renovate

@renovate renovate Bot commented Aug 9, 2025 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
express (source) ^4.21.2 → ^5.0.0 age confidence

Release Notes

expressjs/express (express)

v5.2.1

Compare Source

=======================

  • Revert security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
    • The prior release (5.2.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.

v5.2.0

Compare Source

========================

  • Security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
  • deps: body-parser@^2.2.1
  • A deprecation warning was added when using res.redirect with undefined arguments, Express now emits a warning to help detect calls that pass undefined as the status or URL and make them easier to fix.

v5.1.0

Compare Source

========================

  • Add support for Uint8Array in res.send()
  • Add support for ETag option in res.sendFile()
  • Add support for multiple links with the same rel in res.links()
  • Add funding field to package.json
  • perf: use loop for acceptParams
  • refactor: prefix built-in node module imports
  • deps: remove setprototypeof
  • deps: remove safe-buffer
  • deps: remove utils-merge
  • deps: remove methods
  • deps: remove depd
  • deps: debug@^4.4.0
  • deps: body-parser@^2.2.0
  • deps: router@^2.2.0
  • deps: content-type@^1.0.5
  • deps: finalhandler@^2.1.0
  • deps: qs@^6.14.0
  • deps: server-static@2.2.0
  • deps: type-is@2.0.1

v5.0.1

Compare Source

==========

v5.0.0

Compare Source

=========================

  • remove:
    • path-is-absolute dependency - use path.isAbsolute instead
  • breaking:
    • res.status() accepts only integers, and input must be greater than 99 and less than 1000
      • will throw a RangeError: Invalid status code: ${code}. Status code must be greater than 99 and less than 1000. for inputs outside this range
      • will throw a TypeError: Invalid status code: ${code}. Status code must be an integer. for non integer inputs
    • deps: send@​1.0.0
    • res.redirect('back') and res.location('back') is no longer a supported magic string, explicitly use req.get('Referrer') || '/'.
  • change:
    • res.clearCookie will ignore user provided maxAge and expires options
  • deps: cookie-signature@^1.2.1
  • deps: debug@​4.3.6
  • deps: merge-descriptors@^2.0.0
  • deps: serve-static@^2.1.0
  • deps: qs@​6.13.0
  • deps: accepts@^2.0.0
  • deps: mime-types@^3.0.0
    • application/javascript => text/javascript
  • deps: type-is@^2.0.0
  • deps: content-disposition@^1.0.0
  • deps: finalhandler@^2.0.0
  • deps: fresh@^2.0.0
  • deps: body-parser@^2.0.1
  • deps: send@^1.1.0

v4.22.3

Compare Source

What's Changed

New Contributors

Full Changelog: expressjs/express@v4.22.2...v4.22.3

v4.22.2

Compare Source

What's Changed

  • fix: restore >20 array parsing for req.query repeated keys (8d09bfe6)
    • This also unifies array-cap behavior across notations. Indexed notation (a[0]=...) was historically capped at qs's default arrayLimit of 20 even in older qs versions; after this change it also allows up to 1000 items.
  • deps: qs@~6.15.1
  • deps: body-parser@~1.20.5

New Contributors

Full Changelog: expressjs/express@v4.22.1...v4.22.2

v4.22.1

Compare Source

What's Changed

[!IMPORTANT]
The prior release (4.22.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.

Full Changelog: expressjs/express@4.22.0...v4.22.1

v4.22.0

Compare Source

Important: Security

What's Changed

Full Changelog: expressjs/express@4.21.2...4.22.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "after 11pm every weekend,before 8am every weekend"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added package:npm Pull requests that update node.js deps type:dependencies Pull requests that update a dependency file update:major Major Updates of dependency labels Sep 9, 2025
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 32f7044 to ec6ba44 Compare September 9, 2025 01:19
@snyk-io

snyk-io Bot commented Sep 9, 2025 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@renovate
renovate Bot force-pushed the renovate/express-5.x branch from ec6ba44 to 8d49fca Compare September 25, 2025 16:58
@socket-security

socket-security Bot commented Sep 25, 2025 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedexpress@​4.21.2 ⏵ 5.2.197 +110010093 +6100

View full report

@renovate
renovate Bot force-pushed the renovate/express-5.x branch 4 times, most recently from eab5047 to 1d49afa Compare October 1, 2025 04:40
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 1d49afa to 9ae00f6 Compare October 22, 2025 00:35
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 9ae00f6 to 9570109 Compare November 10, 2025 20:52
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 9570109 to 28fe1b5 Compare December 3, 2025 17:12
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 2 times, most recently from dc1474f to 7f46e68 Compare December 15, 2025 22:45
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 7f46e68 to 3586e61 Compare December 31, 2025 13:58
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 2 times, most recently from 073c2ba to 48c3d78 Compare January 23, 2026 19:46
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 48c3d78 to fa88965 Compare March 5, 2026 19:49
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from fa88965 to 4a33c26 Compare April 29, 2026 13:44
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 4a33c26 to 036b8ce Compare May 12, 2026 10:35
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 2 times, most recently from 2fc1dfd to 1635df1 Compare June 1, 2026 17:34
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 1635df1 to 8109766 Compare July 12, 2026 12:58
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 8109766 to a4ceeeb Compare July 21, 2026 03:09
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from a4ceeeb to b057733 Compare August 11, 2026 22:30
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 2 times, most recently from 5a5b7ec to 8bc95c5 Compare September 3, 2026 23:12
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 8bc95c5 to 8d0b0c2 Compare September 15, 2026 17:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

package:npm Pull requests that update node.js deps type:dependencies Pull requests that update a dependency file update:major Major Updates of dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants