opentok-node
opentok-node copied to clipboard
chore(deps): update dependency body-parser to v1.20.2
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| body-parser | dependencies | minor | ~1.12.0 -> ~1.20.2 |
| body-parser | dependencies | minor | ^1.12.4 -> ^1.20.2 |
This PR resolves the vulnerabilities described in Issue #271
Version 1.12.4
| Risk Change |
||||
|---|---|---|---|---|
| N/A | 0 | 3 | 2 | 0 |
Version 1.20.2
| Risk Change |
||||
|---|---|---|---|---|
| -100% |
0 (--) | 0 (-3 |
0 (-2 |
0 (--) |
Mend ensures you have the greatest risk reduction ("Recommended Fix"-highlighted in green) by removing as many vulnerabilities as possible. Click to see how we calculate risk reduction.
Release Notes
expressjs/body-parser (body-parser)
v1.20.2
===================
- Fix strict json error message on Node.js 19+
- deps: content-type@~1.0.5
- perf: skip value escaping when unnecessary
- deps: [email protected]
v1.20.1
===================
- deps: [email protected]
- perf: remove unnecessary object clone
v1.20.0
===================
- Fix error message for json parse whitespace in
strict - Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- Replace internal
evalusage withFunctionconstructor - Use instance methods on
processto check for listeners
- Replace internal
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
v1.19.2
===================
- deps: [email protected]
- deps: [email protected]
- Fix handling of
__proto__keys
- Fix handling of
- deps: [email protected]
- deps: [email protected]
v1.19.1
===================
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.18
v1.19.0
===================
- deps: [email protected]
- Add petabyte (
pb) support
- Add petabyte (
- deps: [email protected]
- Set constructor name when possible
- deps: [email protected]
- deps: statuses@'>= 1.5.0 < 2'
- deps: [email protected]
- Added encoding MIK
- deps: [email protected]
- Fix parsing array brackets after index
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.17
- deps: mime-types@~2.1.24
- perf: prevent internal
throwon invalid type
v1.18.3
===================
- Fix stack trace for strict json parse error
- deps: depd@~1.1.2
- perf: remove argument reassignment
- deps: http-errors@~1.6.3
- deps: depd@~1.1.2
- deps: [email protected]
- deps: statuses@'>= 1.3.1 < 2'
- deps: [email protected]
- Fix loading encoding with year appended
- Fix deprecation warnings on Node.js 10+
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.16
- deps: mime-types@~2.1.18
v1.18.2
===================
- deps: [email protected]
- perf: remove argument reassignment
v1.18.1
===================
- deps: content-type@~1.0.4
- perf: remove argument reassignment
- perf: skip parameter parsing when no parameters
- deps: [email protected]
- Fix ISO-8859-1 regression
- Update Windows-1255
- deps: [email protected]
- Fix parsing & compacting very deep objects
- deps: [email protected]
- deps: [email protected]
v1.18.0
===================
- Fix JSON strict violation error to match native parse error
- Include the
bodyproperty on verify errors - Include the
typeproperty on all generated errors - Use
http-errorsto set status code on errors - deps: [email protected]
- deps: [email protected]
- deps: depd@~1.1.1
- Remove unnecessary
Bufferloading
- Remove unnecessary
- deps: http-errors@~1.6.2
- deps: [email protected]
- deps: [email protected]
- Add support for React Native
- Add a warning if not loaded as utf-8
- Fix CESU-8 decoding in Node.js 8
- Improve speed of ISO-8859-1 encoding
- deps: [email protected]
- deps: [email protected]
- Use
http-errorsfor standard emitted errors - deps: [email protected]
- deps: [email protected]
- perf: skip buffer decoding on overage chunk
- Use
- perf: prevent internal
throwwhen missing charset
v1.17.2
===================
- deps: [email protected]
- Fix
DEBUG_MAX_ARRAY_LENGTH - deps: [email protected]
- Fix
- deps: type-is@~1.6.15
- deps: mime-types@~2.1.15
v1.17.1
===================
- deps: [email protected]
- Fix regression parsing keys starting with
[
- Fix regression parsing keys starting with
v1.17.0
===================
- deps: http-errors@~1.6.1
- Make
messageproperty enumerable forHttpErrors - deps: [email protected]
- Make
- deps: [email protected]
- Fix compacting nested arrays
v1.16.1
===================
- deps: [email protected]
- Fix deprecation messages in WebStorm and other editors
- Undeprecate
DEBUG_FDset to1or2
v1.16.0
===================
- deps: [email protected]
- Allow colors in workers
- Deprecated
DEBUG_FDenvironment variable - Fix error when running under React Native
- Use same color for same namespace
- deps: [email protected]
- deps: http-errors@~1.5.1
- deps: [email protected]
- deps: [email protected]
- deps: statuses@'>= 1.3.1 < 2'
- deps: [email protected]
- Added encoding MS-31J
- Added encoding MS-932
- Added encoding MS-936
- Added encoding MS-949
- Added encoding MS-950
- Fix GBK/GB18030 handling of Euro character
- deps: [email protected]
- Fix array parsing from skipping empty values
- deps: raw-body@~2.2.0
- deps: [email protected]
- deps: type-is@~1.6.14
- deps: mime-types@~2.1.13
v1.15.2
===================
- deps: [email protected]
- deps: content-type@~1.0.2
- perf: enable strict mode
- deps: http-errors@~1.5.0
- Use
setprototypeofmodule to replace__proto__setting - deps: statuses@'>= 1.3.0 < 2'
- perf: enable strict mode
- Use
- deps: [email protected]
- deps: raw-body@~2.1.7
- deps: [email protected]
- perf: remove double-cleanup on happy path
- deps: type-is@~1.6.13
- deps: mime-types@~2.1.11
v1.15.1
===================
- deps: [email protected]
- Drop partial bytes on all parsed units
- Fix parsing byte string that looks like hex
- deps: raw-body@~2.1.6
- deps: [email protected]
- deps: type-is@~1.6.12
- deps: mime-types@~2.1.10
v1.15.0
===================
- deps: http-errors@~1.4.0
- Add
HttpErrorexport, forerr instanceof createError.HttpError - deps: [email protected]
- deps: statuses@'>= 1.2.1 < 2'
- Add
- deps: [email protected]
- deps: type-is@~1.6.11
- deps: mime-types@~2.1.9
v1.14.2
===================
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: raw-body@~2.1.5
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.10
- deps: mime-types@~2.1.8
v1.14.1
===================
- Fix issue where invalid charset results in 400 when
verifyused - deps: [email protected]
- Fix CESU-8 decoding in Node.js 4.x
- deps: raw-body@~2.1.4
- Fix masking critical errors from
iconv-lite - deps: [email protected]
- Fix masking critical errors from
- deps: type-is@~1.6.9
- deps: mime-types@~2.1.7
v1.14.0
===================
- Fix JSON strict parse error to match syntax errors
- Provide static
requireanalysis inurlencodedparser - deps: depd@~1.1.0
- Support web browser loading
- deps: [email protected]
- deps: raw-body@~2.1.3
- Fix sync callback when attaching data listener causes sync read
- deps: type-is@~1.6.8
- Fix type error when given invalid type to match against
- deps: mime-types@~2.1.6
v1.13.3
===================
- deps: type-is@~1.6.6
- deps: mime-types@~2.1.4
v1.13.2
===================
- deps: [email protected]
- deps: [email protected]
- Fix dropping parameters like
hasOwnProperty - Fix user-visible incompatibilities from 3.1.0
- Fix various parsing edge cases
- Fix dropping parameters like
- deps: raw-body@~2.1.2
- Fix error stack traces to skip
makeError - deps: [email protected]
- Fix error stack traces to skip
- deps: type-is@~1.6.4
- deps: mime-types@~2.1.2
- perf: enable strict mode
- perf: remove argument reassignment
v1.13.1
===================
- deps: [email protected]
- Downgraded from 3.1.0 because of user-visible incompatibilities
v1.13.0
===================
- Add
statusCodeproperty onErrors, in addition tostatus - Change
typedefault toapplication/jsonfor JSON parser - Change
typedefault toapplication/x-www-form-urlencodedfor urlencoded parser - Provide static
requireanalysis - Use the
http-errorsmodule to generate errors - deps: [email protected]
- Slight optimizations
- deps: [email protected]
- The encoding UTF-16 without BOM now defaults to UTF-16LE when detection fails
- Leading BOM is now removed when decoding
- deps: on-finished@~2.3.0
- Add defined behavior for HTTP
CONNECTrequests - Add defined behavior for HTTP
Upgraderequests - deps: [email protected]
- Add defined behavior for HTTP
- deps: [email protected]
- Fix dropping parameters like
hasOwnProperty - Fix various parsing edge cases
- Parsed object now has
nullprototype
- Fix dropping parameters like
- deps: raw-body@~2.1.1
- Use
unpipemodule for unpiping requests - deps: [email protected]
- Use
- deps: type-is@~1.6.3
- deps: mime-types@~2.1.1
- perf: reduce try block size
- perf: remove bitwise operations
- perf: enable strict mode
- perf: remove argument reassignment
- perf: remove delete call
v1.12.4
===================
- deps: debug@~2.2.0
- deps: [email protected]
- Fix allowing parameters like
constructor
- Fix allowing parameters like
- deps: on-finished@~2.2.1
- deps: raw-body@~2.0.1
- Fix a false-positive when unpiping in Node.js 0.8
- deps: [email protected]
- deps: type-is@~1.6.2
- deps: mime-types@~2.0.11
v1.12.3
===================
- Slight efficiency improvement when not debugging
- deps: depd@~1.0.1
- deps: [email protected]
- Add encoding alias UNICODE-1-1-UTF-7
- deps: [email protected]
- Fix hanging callback if request aborts during read
- deps: [email protected]
v1.12.2
===================
- deps: [email protected]
- Fix error when parameter
hasOwnPropertyis present
- Fix error when parameter
v1.12.1
===================
- deps: debug@~2.1.3
- Fix high intensity foreground color for bold
- deps: [email protected]
- deps: type-is@~1.6.1
- deps: mime-types@~2.0.10
- [ ] If you want to rebase/retry this PR, check this box