engineering-blog-samples
engineering-blog-samples copied to clipboard
Bump qs, @nestjs/platform-express, body-parser, express and formidable in /Nestjs/NestJS Session Auth
Bumps qs to 6.10.3 and updates ancestor dependencies qs, @nestjs/platform-express, body-parser, express and formidable. These dependencies need to be updated together.
Updates qs
from 6.9.3 to 6.10.3
Changelog
Sourced from qs's changelog.
6.10.3
- [Fix]
parse
: ignore__proto__
keys (#428)- [Robustness]
stringify
: avoid relying on a globalundefined
(#427)- [actions] reuse common workflows
- [Dev Deps] update
eslint
,@ljharb/eslint-config
,object-inspect
,tape
6.10.2
- [Fix]
stringify
: actually fix cyclic references (#426)- [Fix]
stringify
: avoid encoding arrayformat comma whenencodeValuesOnly = true
(#424)- [readme] remove travis badge; add github actions/codecov badges; update URLs
- [Docs] add note and links for coercing primitive values (#408)
- [actions] update codecov uploader
- [actions] update workflows
- [Tests] clean up stringify tests slightly
- [Dev Deps] update
eslint
,@ljharb/eslint-config
,aud
,object-inspect
,safe-publish-latest
,tape
6.10.1
- [Fix]
stringify
: avoid exception on repeated object values (#402)6.10.0
- [New]
stringify
: throw on cycles, instead of an infinite loop (#395, #394, #393)- [New]
parse
: addallowSparse
option for collapsing arrays with missing indices (#312)- [meta] fix README.md (#399)
- [meta] only run
npm run dist
in publish, not install- [Dev Deps] update
eslint
,@ljharb/eslint-config
,aud
,has-symbols
,tape
- [Tests] fix tests on node v0.6
- [Tests] use
ljharb/actions/node/install
instead ofljharb/actions/node/run
- [Tests] Revert "[meta] ignore eclint transitive audit warning"
6.9.7
- [Fix]
parse
: ignore__proto__
keys (#428)- [Fix]
stringify
: avoid encoding arrayformat comma whenencodeValuesOnly = true
(#424)- [Robustness]
stringify
: avoid relying on a globalundefined
(#427)- [readme] remove travis badge; add github actions/codecov badges; update URLs
- [Docs] add note and links for coercing primitive values (#408)
- [Tests] clean up stringify tests slightly
- [meta] fix README.md (#399)
- Revert "[meta] ignore eclint transitive audit warning"
- [actions] backport actions from main
- [Dev Deps] backport updates from main
6.9.6
- [Fix] restore
dist
dir; mistakenly removed in d4f6c326.9.5
- [Fix]
stringify
: do not encode parens for RFC1738- [Fix]
stringify
: fix arrayFormat comma with empty array/objects (#350)- [Refactor]
format
: removeutil.assign
call- [meta] add "Allow Edits" workflow; update rebase workflow
- [actions] switch Automatic Rebase workflow to
pull_request_target
event
... (truncated)
Commits
f92ddb5
v6.10.3d9e9529
[Dev Deps] updateeslint
8b4cc14
[Fix]parse
: ignore__proto__
keysad63d36
[actions] reuse common workflowsc028385
[Dev Deps] updateeslint
,@ljharb/eslint-config
,object-inspect
,tape
0a1d3e8
[Robustness]stringify
: avoid relying on a globalundefined
408ff95
v6.10.23cea04d
[Dev Deps] update@ljharb/eslint-config
28fba8f
[Dev Deps] updateeslint
,@ljharb/eslint-config
,tape
9aee773
[Fix]stringify
: actually fix cyclic references- Additional commits viewable in compare view
Updates @nestjs/platform-express
from 8.2.6 to 8.4.7
Release notes
Sourced from @nestjs/platform-express
's releases.
v8.4.7 (2022-06-14)
Enhancements
microservices
common
Dependencies
- #9731 chore(deps-dev): bump apollo-server-core from 3.8.1 to 3.8.2 (
@dependabot[bot]
)- #9762 chore(deps-dev): bump lint-staged from 13.0.0 to 13.0.1 (
@dependabot[bot]
)- #9764 chore(deps-dev): bump graphql-tools from 8.2.11 to 8.2.12 (
@dependabot[bot]
)- #9765 chore(deps-dev): bump point-of-view from 6.2.1 to 6.3.0 (
@dependabot[bot]
)- #9769 chore(deps-dev): bump mongoose from 6.3.5 to 6.3.8 (
@dependabot[bot]
)- #9729 chore(deps-dev): bump cache-manager from 4.0.0 to 4.0.1 (
@dependabot[bot]
)- #9730 chore(deps-dev): bump typescript from 4.7.2 to 4.7.3 (
@dependabot[bot]
)- #9732 chore(deps-dev): bump apollo-server-express from 3.8.1 to 3.8.2 (
@dependabot[bot]
)- #9735 chore(deps-dev): bump ts-morph from 15.0.0 to 15.1.0 (
@dependabot[bot]
)- #9740 chore(deps-dev): bump
@grpc/proto-loader
from 0.6.12 to 0.6.13 (@dependabot[bot]
)- #9756 chore(deps-dev): bump
@types/node
from 17.0.38 to 17.0.42 (@dependabot[bot]
)- #9757 chore(deps): bump fast-json-stringify from 3.2.0 to 4.1.0 (
@dependabot[bot]
)- #9711 chore(deps-dev): bump
@nestjs/apollo
from 10.0.13 to 10.0.14 (@dependabot[bot]
)- #9712 chore(deps-dev): bump lint-staged from 12.5.0 to 13.0.0 (
@dependabot[bot]
)- #9710 chore(deps-dev): bump cache-manager from 3.6.3 to 4.0.0 (
@dependabot[bot]
)- #9709 chore(deps-dev): bump
@commitlint/cli
from 17.0.1 to 17.0.2 (@dependabot[bot]
)- #9713 chore(deps-dev): bump core-js from 3.22.7 to 3.22.8 (
@dependabot[bot]
)- #9723 chore(deps-dev): bump
@nestjs/graphql
from 10.0.13 to 10.0.15 (@dependabot[bot]
)- #9722 chore(deps): bump protobufjs from 6.11.2 to 6.11.3 (
@dependabot[bot]
)- #9721 chore(deps): bump protobufjs from 6.11.2 to 6.11.3 in /sample/04-grpc (
@dependabot[bot]
)- #9724 chore(deps-dev): bump amqplib from 0.9.1 to 0.10.0 (
@dependabot[bot]
)- #9700 chore(deps-dev): bump kafkajs from 2.0.1 to 2.0.2 (
@dependabot[bot]
)- #9701 chore(deps-dev): bump
@types/node
from 17.0.36 to 17.0.38 (@dependabot[bot]
)- #9702 chore(deps-dev): bump point-of-view from 5.3.0 to 6.2.1 (
@dependabot[bot]
)- #9703 chore(deps-dev): bump lint-staged from 12.4.3 to 12.5.0 (
@dependabot[bot]
)Committers: 5
- Antonio T. alias Tony (
@Tony133
)- Daniel De Lucca (
@delucca
)- Matthew Painter (
@mjgp2
)- Sushant Zope (
@sushant9096
)- Volodymyr Tytarenko (
@bovatitar
)v8.4.5 (2022-05-13)
Bug fixes
core
- #9456 fix(core): scoped injection with symbol field name (
@MyAeroCode
)Enhancements
... (truncated)
Commits
f383352
chore(@nestjs
) publish v8.4.7 release11c32df
Merge pull request #9731 from nestjs/dependabot/npm_and_yarn/apollo-server-co...995b516
Merge pull request #9719 from delucca-workspaces/feat/export-base-rpc-context5523139
Merge pull request #9686 from sushant9096/master279f6fa
Merge pull request #9751 from delucca-workspaces/fix/server-transport-connect...52cf0b7
Merge pull request #9762 from nestjs/dependabot/npm_and_yarn/lint-staged-13.0.1bc3b431
Merge pull request #9764 from nestjs/dependabot/npm_and_yarn/graphql-tools-8....ba971a7
Merge pull request #9765 from nestjs/dependabot/npm_and_yarn/point-of-view-6.3.06e7cf52
Merge pull request #9769 from nestjs/dependabot/npm_and_yarn/mongoose-6.3.892fc598
chore(deps-dev): bump mongoose from 6.3.5 to 6.3.8- Additional commits viewable in compare view
Updates body-parser
from 1.19.1 to 1.20.0
Release notes
Sourced from body-parser's releases.
1.20.0
- Fix error message for json parse whitespace in
strict
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- Replace internal
eval
usage withFunction
constructor- Use instance methods on
process
to check for listeners- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
1.19.2
- deps: [email protected]
- deps: [email protected]
- Fix handling of
__proto__
keys- deps: [email protected]
- deps: [email protected]
Changelog
Sourced from body-parser's changelog.
1.20.0 / 2022-04-02
- Fix error message for json parse whitespace in
strict
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- Replace internal
eval
usage withFunction
constructor- Use instance methods on
process
to check for listeners- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
1.19.2 / 2022-02-15
- deps: [email protected]
- deps: [email protected]
- Fix handling of
__proto__
keys- deps: [email protected]
- deps: [email protected]
Commits
1f6f58e
1.20.07861a00
docs: update CI badge link601a076
docs: add security policy77bcc0e
deps: [email protected]eac5f22
build: [email protected]8611539
build: [email protected]2a2f471
Fix internal error when inflated body exceeds limit9db582d
Fix error message for json parse whitespace in strictbd702d2
lint: remove deprecated String.prototype.substr96df60f
deps: [email protected]- Additional commits viewable in compare view
Updates express
from 4.17.2 to 4.18.1
Release notes
Sourced from express's releases.
4.18.1
- Fix hanging on large stack of sync routes
4.18.0
- Add "root" option to
res.download
- Allow
options
withoutfilename
inres.download
- Deprecate string and non-integer arguments to
res.status
- Fix behavior of
null
/undefined
asmaxAge
inres.cookie
- Fix handling very large stacks of sync middleware
- Ignore
Object.prototype
values in settings throughapp.set
/app.get
- Invoke
default
with same arguments as types inres.format
- Support proper 205 responses using
res.send
- Use
http-errors
forres.format
error- deps: [email protected]
- Fix error message for json parse whitespace in
strict
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Add
priority
option- Fix
expires
option to reject invalid dates- deps: [email protected]
- Replace internal
eval
usage withFunction
constructor- Use instance methods on
process
to check for listeners- deps: [email protected]
- Remove set content headers that break response
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Prevent loss of async hooks context
- deps: [email protected]
- deps: [email protected]
- Fix emitted 416 error missing headers property
- Limit the headers removed for 304 response
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Remove code 306
- Rename
425 Unordered Collection
to standard425 Too Early
... (truncated)
Changelog
Sourced from express's changelog.
4.18.1 / 2022-04-29
- Fix hanging on large stack of sync routes
4.18.0 / 2022-04-25
- Add "root" option to
res.download
- Allow
options
withoutfilename
inres.download
- Deprecate string and non-integer arguments to
res.status
- Fix behavior of
null
/undefined
asmaxAge
inres.cookie
- Fix handling very large stacks of sync middleware
- Ignore
Object.prototype
values in settings throughapp.set
/app.get
- Invoke
default
with same arguments as types inres.format
- Support proper 205 responses using
res.send
- Use
http-errors
forres.format
error- deps: [email protected]
- Fix error message for json parse whitespace in
strict
- Fix internal error when inflated body exceeds limit
- Prevent loss of async hooks context
- Prevent hanging when request already read
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Add
priority
option- Fix
expires
option to reject invalid dates- deps: [email protected]
- Replace internal
eval
usage withFunction
constructor- Use instance methods on
process
to check for listeners- deps: [email protected]
- Remove set content headers that break response
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- Prevent loss of async hooks context
- deps: [email protected]
- deps: [email protected]
- Fix emitted 416 error missing headers property
- Limit the headers removed for 304 response
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
- deps: [email protected]
... (truncated)
Commits
d854c43
4.18.1b02a95c
build: [email protected]631ada0
Fix hanging on large stack of sync routes75e0c7a
bench: remove unused parametere2482b7
build: [email protected]2df96e3
build: [email protected]a38fae1
build: [email protected]547fdd4
4.18.00b330ef
bench: print latency and vary connections158a170
build: support Node.js 18.x- Additional commits viewable in compare view
Updates formidable
from 2.0.1 to 2.1.1
Commits
- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.