opentok-node
opentok-node copied to clipboard
chore(deps): update dependency express to ~4.21.1 (main)
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| express (source) | dependencies | minor | ~4.19.0 -> ~4.21.1 |
By merging this PR, the issue #337 will be automatically resolved and closed:
| Severity | Vulnerability | Reachability | |
|---|---|---|---|
High |
7.5 | CVE-2024-45296 | |
High |
7.5 | CVE-2024-45590 | |
High |
7.5 | CVE-2024-52798 | |
Medium |
5.3 | CVE-2024-47764 | |
Medium |
5.0 | CVE-2024-43796 | |
Medium |
5.0 | CVE-2024-43799 | |
Medium |
5.0 | CVE-2024-43800 |
Release Notes
expressjs/express (express)
v4.21.1
What's Changed
- Backport a fix for CVE-2024-47764 to the 4.x branch by @joshbuker in https://github.com/expressjs/express/pull/6029
- Release: 4.21.1 by @UlisesGascon in https://github.com/expressjs/express/pull/6031
Full Changelog: https://github.com/expressjs/express/compare/4.21.0...4.21.1
v4.21.0
What's Changed
- Deprecate
"back"magic string in redirects by @blakeembrey in https://github.com/expressjs/express/pull/5935 - [email protected] by @wesleytodd in https://github.com/expressjs/express/pull/5954
- fix(deps): [email protected] by @wesleytodd in https://github.com/expressjs/express/pull/5951
- Upgraded dependency qs to 6.13.0 to match qs in body-parser by @agadzinski93 in https://github.com/expressjs/express/pull/5946
New Contributors
- @agadzinski93 made their first contribution in https://github.com/expressjs/express/pull/5946
Full Changelog: https://github.com/expressjs/express/compare/4.20.0...4.21.0
v4.20.0
==========
- deps: [email protected]
- Remove link renderization in html while redirecting
- deps: [email protected]
- Remove link renderization in html while redirecting
- deps: [email protected]
- add
depthoption to customize the depth level in the parser - IMPORTANT: The default
depthlevel for parsing URL-encoded data is now32(previously wasInfinity)
- add
- Remove link renderization in html while using
res.redirect - deps: [email protected]
- Adds support for named matching groups in the routes using a regex
- Adds backtracking protection to parameters without regexes defined
- deps: encodeurl@~2.0.0
- Removes encoding of
\,|, and^to align better with URL spec
- Removes encoding of
- Deprecate passing
options.maxAgeandoptions.expirestores.clearCookie- Will be ignored in v5, clearCookie will set a cookie with an expires in the past to instruct clients to delete the cookie
v4.19.2
==========
- Improved fix for open redirect allow list bypass
v4.19.1
==========
- Allow passing non-strings to res.location with new encoding handling checks
- [ ] If you want to rebase/retry this PR, check this box
High
Medium