node-sdk
node-sdk copied to clipboard
[Snyk] Upgrade express from 4.21.0 to 4.21.2
Snyk has created this PR to upgrade express from 4.21.0 to 4.21.2.
:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
-
The recommended version is 2 versions ahead of your current version.
-
The recommended version was released 6 months ago.
Issues fixed by the recommended upgrade:
| Issue | Score | Exploit Maturity | |
|---|---|---|---|
| Cross-site Scripting (XSS) SNYK-JS-COOKIE-8163060 |
529 | No Known Exploit | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-PATHTOREGEXP-8482416 |
529 | Proof of Concept |
Release notes
Package name: express
-
4.21.2 - 2024-12-05
What's Changed
- Add funding field (v4) by @ bjohansebas in #6065
- deps: [email protected] by @ blakeembrey in #5956
- deps: bump [email protected] by @ jonchurch in #6209
- Release: 4.21.2 by @ UlisesGascon in #6094
Full Changelog: 4.21.1...4.21.2
-
4.21.1 - 2024-10-08
What's Changed
- Backport a fix for CVE-2024-47764 to the 4.x branch by @ joshbuker in #6029
- Release: 4.21.1 by @ UlisesGascon in #6031
Full Changelog: 4.21.0...4.21.1
-
4.21.0 - 2024-09-11
What's Changed
- Deprecate
"back"magic string in redirects by @ blakeembrey in #5935 - [email protected] by @ wesleytodd in #5954
- fix(deps): [email protected] by @ wesleytodd in #5951
- Upgraded dependency qs to 6.13.0 to match qs in body-parser by @ agadzinski93 in #5946
New Contributors
- @ agadzinski93 made their first contribution in #5946
Full Changelog: 4.20.0...4.21.0
- Deprecate
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- This PR was automatically created by Snyk using the credentials of a real user.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: