chore(deps): bump koa from 2.16.1 to 3.0.3
Bumps koa from 2.16.1 to 3.0.3.
Release notes
Sourced from koa's releases.
v3.0.3
What's Changed
- fix: normalize referer before redirect by
@fengmk2in koajs/koa#1908Full Changelog: https://github.com/koajs/koa/compare/v3.0.2...v3.0.3
v3.0.2
What's Changed
- fix: fixes response.attachment behaviour leads to Content-Type Sniffing by
@yowainwrightin koajs/koa#1904- chore: use NPM trusted publishing with semver tag triggers by
@Copilotin koajs/koa#1907New Contributors
@Copilotmade their first contribution in koajs/koa#1907Full Changelog: https://github.com/koajs/koa/compare/v3.0.1...v3.0.2
v3.0.1
What's Changed
- fix(security): only allow same origin referer on response back https://github.com/koajs/koa/commit/422c551c63d00f24e2bbbdf492f262a5935bb1f0
- chore: adds initial doc text refresh; migration guide [CHORE-1870] by
@yowainwrightin koajs/koa#1877- build(deps-dev): bump formidable from 3.5.2 to 3.5.4 by
@dependabot[bot] in koajs/koa#1878- chore: removes done callbacks in tests [CHORE-1870] by
@yowainwrightin koajs/koa#1875- build(deps-dev): bump supertest from 7.1.0 to 7.1.1 by
@dependabot[bot] in koajs/koa#1879- build(deps): bump debug from 4.4.0 to 4.4.1 by
@dependabot[bot] in koajs/koa#1880- feat: replace debug module with pure node:util::debuglog by
@3imed-jaberiin koajs/koa#1885- feat: replace cache-content-type with mime-types directly by
@3imed-jaberiin koajs/koa#1886- build(deps): bump statuses from 2.0.1 to 2.0.2 by
@dependabot[bot] in koajs/koa#1888- build(deps-dev): bump supertest from 7.1.1 to 7.1.4 by
@dependabot[bot] in koajs/koa#1895- build(deps-dev): bump form-data from 4.0.3 to 4.0.4 by
@dependabot[bot] in koajs/koa#1894Full Changelog: https://github.com/koajs/koa/compare/v3.0.0...v3.0.1
v3.0.0
This is a major release.
Breaking
- Minimum node v18
- Removes
.redirect('back'), adds.back(fallback_url)@fl0wkoajs/koa#1115- For
.redirect(), don't render redirect values in anchor ref https://github.com/koajs/koa/commit/ff25eb4a7f2392df46481fe86355161067687312req.originshould display the origin header if it exists, not the current hostname koajs/koa#1008.originnow aligns with theOriginheader as used in CORS..body=<json>should not overwrite type if type already json koajs/koa#1120- Remove special ENOENT support koajs/koa#1861 - this is a big change and will require any file servers to adapt to this change for handling 404s / files not found
- Removes generator deprecation messages. Generators are no longer supported. Koa no longer asserts if generators are used. Set content-length: 0 if body is explicitly set to null
@ognjenjevremovic#1528 Remove obsolete createAsyncCtxStorageMiddleware koajs/koa#1817ctx.thrownow requires a format ofctx.throw(status, error, properties). See: https://www.npmjs.com/package/http-errors
... (truncated)
Changelog
Sourced from koa's changelog.
[!IMPORTANT] Moving forwards we are using the GitHub releases page at https://github.com/koajs/koa/releases in combination with np for publishing releases and their changelogs.
3.0.0-alpha.3 / 2025-02-11
fixes
- Avoid redos on host and protocol getter
3.0.0-alpha.2 / 2024-11-04
breaking changes
- Update
http-errorstov2.0.0#1486
ctx.thrownow requires a format ofctx.throw(status, error, properties). See: https://www.npmjs.com/package/http-errors- Remove
res.redirect('back'), addback()method toctx#1115- Replace node querystring with
URLSearchParams#1828- Remove obsolete
createAsyncCtxStorageMiddleware#1817features
- Add support for web WHATWG #1830
updates
fixes
- Fix
exports.defaultsinpackage.json#1630- Fix leaky handles in tests #1838
- Fix body null checks #1814
- Fix reformatting redirect URLs #1805 #1804
- Fix passing
ctxin error handler #1758migrations
- Migrate from
jestto the native node test runner #18453.0.0-alpha.1 / 2023-04-12
fixes
- [
e98b8d1] - fix: can not get currentContext in error handler (#1758) (Gxkl <[email protected]>)3.0.0-alpha.0 / 2023-01-02
Breaking Changes
... (truncated)
Commits
ffd497a3.0.3769fd75fix: normalize referer before redirect (#1908)433b20c3.0.2307013bchore: use NPM trusted publishing with semver tag triggers (#1907)83128ebfix: fixes response.attachment behavior leads to Content-Type Sniffing (#1904)1ddb0483.0.1422c551Merge commit from fork6e51eb1build(deps-dev): bump form-data from 4.0.3 to 4.0.4 (#1894)d378e5cbuild(deps-dev): bump supertest from 7.1.1 to 7.1.4 (#1895)cb22d8dbuild(deps): bump statuses from 2.0.1 to 2.0.2 (#1888)- Additional commits viewable in compare view
Maintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for koa since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.
⚠️ No Changeset found
Latest commit: 69bf02a06514cfd6df281770bee9c4383dd739db
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
This PR includes no changesets
When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types
Click here to learn what changesets are, and how to add one.
Click here if you're a maintainer who wants to add a changeset to this PR