api.direkt.bahn.guru
api.direkt.bahn.guru copied to clipboard
[Snyk] Upgrade express from 4.18.2 to 4.21.2
Snyk has created this PR to upgrade express from 4.18.2 to 4.21.2.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
-
The recommended version is 8 versions ahead of your current version.
-
The recommended version was released 10 months ago.
Release notes
Package name: express
-
4.21.2 - 2024-12-05
What's Changed
- Add funding field (v4) by @ bjohansebas in #6065
- deps: [email protected] by @ blakeembrey in #5956
- deps: bump [email protected] by @ jonchurch in #6209
- Release: 4.21.2 by @ UlisesGascon in #6094
Full Changelog: 4.21.1...4.21.2
-
4.21.1 - 2024-10-08
What's Changed
- Backport a fix for CVE-2024-47764 to the 4.x branch by @ joshbuker in #6029
- Release: 4.21.1 by @ UlisesGascon in #6031
Full Changelog: 4.21.0...4.21.1
-
4.21.0 - 2024-09-11
What's Changed
- Deprecate
"back"magic string in redirects by @ blakeembrey in #5935 - [email protected] by @ wesleytodd in #5954
- fix(deps): [email protected] by @ wesleytodd in #5951
- Upgraded dependency qs to 6.13.0 to match qs in body-parser by @ agadzinski93 in #5946
New Contributors
- @ agadzinski93 made their first contribution in #5946
Full Changelog: 4.20.0...4.21.0
- Deprecate
-
4.20.0 - 2024-09-10
What's Changed
Important
- IMPORTANT: The default
depthlevel for parsing URL-encoded data is now32(previously wasInfinity) - Remove link renderization in html while using
res.redirect
Other Changes
- 4.19.2 Staging by @ wesleytodd in #5561
- remove duplicate location test for data uri by @ wesleytodd in #5562
- feat: document beta releases expectations by @ marco-ippolito in #5565
- Cut down on duplicated CI runs by @ jonchurch in #5564
- Add a Threat Model by @ UlisesGascon in #5526
- Assign captain of encodeurl by @ blakeembrey in #5579
- Nominate jonchurch as repo captain for
http-errors,expressjs.com,morgan,cors,body-parserby @ jonchurch in #5587 - docs: update Security.md by @ inigomarquinez in #5590
- docs: update triage nomination policy by @ UlisesGascon in #5600
- Add CodeQL (SAST) by @ UlisesGascon in #5433
- docs: add UlisesGascon as triage initiative captain by @ UlisesGascon in #5605
- deps: encodeurl@~2.0.0 by @ blakeembrey in #5569
- skip QUERY method test by @ jonchurch in #5628
- ignore ETAG query test on 21 and 22, reuse skip util by @ jonchurch in #5639
- add support Node.js@22 in the CI by @ mertcanaltin in #5627
- doc: add table of contents, tc/triager lists to readme by @ mertcanaltin in #5619
- List and sort all projects, add captains by @ blakeembrey in #5653
- docs: add @ UlisesGascon as captain for cookie-parser by @ UlisesGascon in #5666
- ✨ bring back query tests for node 21 by @ ctcpip in #5690
- [v4] Deprecate
res.clearCookieacceptingoptions.maxAgeandoptions.expiresby @ jonchurch in #5672 - skip QUERY tests for Node 21 only, still not supported by @ jonchurch in #5695
- 📝 update people, add ctcpip to TC by @ ctcpip in #5683
- remove minor version pinning from ci by @ jonchurch in #5722
- Fix link variable use in attribution section of CODE OF CONDUCT by @ IamLizu in #5762
- Replace Appveyor windows testing with GHA by @ jonchurch in #5599
- Add OSSF Scorecard badge by @ UlisesGascon in #5436
- update scorecard link by @ bjohansebas in #5814
- Nominate @ IamLizu to the triage team by @ UlisesGascon in #5836
- deps: [email protected] by @ blakeembrey in #5603
- docs: specify new instructions for
questionanddiscussby @ IamLizu in #5835 - 4.x: Upgrade
merge-descriptorsdependency by @ RobinTail in #5781 - [email protected] by @ blakeembrey in #5902
New Contributors
- @ marco-ippolito made their first contribution in #5565
- @ inigomarquinez made their first contribution in #5590
- @ mertcanaltin made their first contribution in #5627
- @ ctcpip made their first contribution in #5690
- @ bjohansebas made their first contribution in #5814
Full Changelog: 4.19.1...4.20.0
- IMPORTANT: The default
-
4.19.2 - 2024-03-25
What's Changed
Full Changelog: 4.19.1...4.19.2
-
4.19.1 - 2024-03-20
What's Changed
- Fix ci after location patch by @ wesleytodd in #5552
- fixed un-edited version in history.md for 4.19.0 by @ wesleytodd in #5556
Full Changelog: 4.19.0...4.19.1
-
4.19.0 - 2024-03-20
What's Changed
- fix typo in release date by @ UlisesGascon in #5527
- docs: nominating @ wesleytodd to be project captian by @ wesleytodd in #5511
- docs: loosen TC activity rules by @ wesleytodd in #5510
- Add note on how to update docs for new release by @ crandmck in #5541
- Prevent open redirect allow list bypass due to encodeurl
- Release 4.19.0 by @ wesleytodd in #5551
New Contributors
- @ crandmck made their first contribution in #5541
Full Changelog: 4.18.3...4.19.0
- 4.18.3 - 2024-02-29
- 4.18.2 - 2022-10-08
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: