Letters
Letters copied to clipboard
[Snyk] Upgrade express from 4.13.4 to 4.17.1
Snyk has created this PR to upgrade express from 4.13.4 to 4.17.1.
:sparkles: Snyk has automatically assigned this pull request, [set who gets assigned](https://app.snyk.io/org/tshemsedinov/project/501e1ec0-a667-4b07-ad64-59ffd30163fb/settings/integration?utm_source=github&utm_medium=upgrade-pr/settings/integration).
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is 15 versions ahead of your current version.
- The recommended version was released 2 years ago, on 2019-05-26.
The recommended version fixes:
| Severity | Issue | PriorityScore (*) | Exploit Maturity |
|---|---|---|---|
| Prototype Override Protection Bypass npm:qs:20170213 |
589/1000 Why? Has a fix available, CVSS 7.5 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) npm:negotiator:20160616 |
589/1000 Why? Has a fix available, CVSS 7.5 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) npm:fresh:20170908 |
589/1000 Why? Has a fix available, CVSS 7.5 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) npm:ms:20170412 |
589/1000 Why? Has a fix available, CVSS 7.5 |
No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) npm:mime:20170907 |
589/1000 Why? Has a fix available, CVSS 7.5 |
No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: express
-
4.17.1 - 2019-05-26
- Revert "Improve error message for
null/undefinedtores.status"
- Revert "Improve error message for
-
4.17.0 - 2019-05-17
- Add
express.rawto parse bodies intoBuffer - Add
express.textto parse bodies into string - Improve error message for non-strings to
res.sendFile - Improve error message for
null/undefinedtores.status - Support multiple hosts in
X-Forwarded-Host - deps: accepts@~1.3.7
- deps: [email protected]
- Add encoding MIK
- Add petabyte (
pb) support - Fix parsing array brackets after index
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.17
- deps: [email protected]
- deps: [email protected]
- Add
SameSite=Nonesupport
- Add
- deps: finalhandler@~1.1.2
- Set stricter
Content-Security-Policyheader - deps: parseurl@~1.3.3
- deps: statuses@~1.5.0
- Set stricter
- deps: parseurl@~1.3.3
- deps: proxy-addr@~2.0.5
- deps: [email protected]
- deps: [email protected]
- Fix parsing array brackets after index
- deps: range-parser@~1.2.1
- deps: [email protected]
- Set stricter CSP header in redirect & error responses
- deps: http-errors@~1.7.2
- deps: [email protected]
- deps: [email protected]
- deps: range-parser@~1.2.1
- deps: statuses@~1.5.0
- perf: remove redundant
path.normalizecall
- deps: [email protected]
- Set stricter CSP header in redirect response
- deps: parseurl@~1.3.3
- deps: [email protected]
- deps: [email protected]
- deps: statuses@~1.5.0
- Add
103 Early Hints
- Add
- deps: type-is@~1.6.18
- deps: mime-types@~2.1.24
- perf: prevent internal
throwon invalid type
- Add
-
4.16.4 - 2018-10-11
- Fix issue where
"Request aborted"may be logged inres.sendfile - Fix JSDoc for
Routerconstructor - deps: [email protected]
- Fix deprecation warnings on Node.js 10+
- Fix stack trace for strict json parse error
- deps: depd@~1.1.2
- deps: http-errors@~1.6.3
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: type-is@~1.6.16
- deps: proxy-addr@~2.0.4
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Fix issue where
-
4.16.3 - 2018-03-12
- deps: accepts@~1.3.5
- deps: mime-types@~2.1.18
- deps: depd@~1.1.2
- perf: remove argument reassignment
- deps: encodeurl@~1.0.2
- Fix encoding
%as last character
- Fix encoding
- deps: [email protected]
- Fix 404 output for bad / missing pathnames
- deps: encodeurl@~1.0.2
- deps: statuses@~1.4.0
- deps: proxy-addr@~2.0.3
- deps: [email protected]
- deps: [email protected]
- Fix incorrect end tag in default error & redirects
- deps: depd@~1.1.2
- deps: encodeurl@~1.0.2
- deps: statuses@~1.4.0
- deps: [email protected]
- Fix incorrect end tag in redirects
- deps: encodeurl@~1.0.2
- deps: [email protected]
- deps: statuses@~1.4.0
- deps: type-is@~1.6.16
- deps: mime-types@~2.1.18
- deps: accepts@~1.3.5
-
4.16.2 - 2017-10-10
- Fix
TypeErrorinres.sendwhen givenBufferandETagheader set - perf: skip parsing of entire
X-Forwarded-Protoheader
- Fix
-
4.16.1 - 2017-09-29
- deps: [email protected]
- deps: [email protected]
- Fix regression when
rootis incorrectly set to a file - deps: [email protected]
- Fix regression when
-
4.16.0 - 2017-09-28
- Add
"json escape"setting forres.jsonandres.jsonp - Add
express.jsonandexpress.urlencodedto parse bodies - Add
optionsargument tores.download - Improve error message when autoloading invalid view engine
- Improve error messages when non-function provided as middleware
- Skip
Bufferencoding when not generating ETag for small response - Use
safe-bufferfor improved Buffer API - deps: accepts@~1.3.4
- deps: mime-types@~2.1.16
- deps: content-type@~1.0.4
- perf: remove argument reassignment
- perf: skip parameter parsing when no parameters
- deps: etag@~1.8.1
- perf: replace regular expression with substring
- deps: [email protected]
- Use
res.headersSentwhen available
- Use
- deps: parseurl@~1.3.2
- perf: reduce overhead for full URLs
- perf: unroll the "fast-path"
RegExp
- deps: proxy-addr@~2.0.2
- Fix trimming leading / trailing OWS in
X-Forwarded-For - deps: forwarded@~0.1.2
- deps: [email protected]
- perf: reduce overhead when no
X-Forwarded-Forheader
- Fix trimming leading / trailing OWS in
- deps: [email protected]
- Fix parsing & compacting very deep objects
- deps: [email protected]
- Add 70 new types for file extensions
- Add
immutableoption - Fix missing
</html>in default error & redirects - Set charset as "UTF-8" for .js and .json
- Use instance methods on steam to check for listeners
- deps: [email protected]
- perf: improve path validation speed
- deps: [email protected]
- Add 70 new types for file extensions
- Add
immutableoption - Set charset as "UTF-8" for .js and .json
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: vary@~1.1.2
- perf: improve header token parsing speed
- perf: re-use options object when generating ETags
- perf: remove dead
.charsetset inres.jsonp
- Add
- 4.15.5 - 2017-09-25
- 4.15.4 - 2017-08-07
- 4.15.3 - 2017-05-17
- 4.15.2 - 2017-03-06
- 4.15.1 - 2017-03-06
- 4.15.0 - 2017-03-01
- 4.14.1 - 2017-01-28
- 4.14.0 - 2016-06-16
- 4.13.4 - 2016-01-22
Commit messages
Package name: express
- e1b45eb 4.17.1
- 0a48e18 Revert "Improve error message for null/undefined to res.status"
- eed05a1 build: [email protected]
- 10c7756 4.17.0
- 9dadca2 docs: remove Gratipay links
- b8e5056 tests: ignore unreachable line
- 94e48a1 build: update example dependencies
- efcb17d deps: [email protected]
- b9ecb9a build: support Node.js 12.x
- 5266f3a build: test against Node.js 13.x nightly
- e502dde build: [email protected]
- da6f701 deps: range-parser@~1.2.1
- 88f9733 deps: [email protected]
- 8267c4b deps: [email protected]
- bc07a41 deps: finalhandler@~1.1.2
- c754c8a build: support Node.js 11.x
- e917028 build: [email protected]
- 7b076bd build: [email protected]
- bb5211f tests: add express.text test suite
- 7f4e37f Add express.text to parse bodies into string
- 11192bd tests: add express.raw test suite
- 0bcdd88 Add express.raw to parse bodies into Buffer
- 60aacac deps: [email protected]
- 70a1947 deps: [email protected]
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
👩💻 Set who automatically gets assigned
🔕 Ignore this dependency or unsubscribe from future upgrade PRs