Skip to content

[Snyk] Upgrade express from 4.18.0 to 4.20.0 - #2

Open
1995preethi wants to merge 1 commit into
mainfrom
snyk-upgrade-8d1feb34dfffc8b8fef0f3b572a2f62e
Open

[Snyk] Upgrade express from 4.18.0 to 4.20.0#2
1995preethi wants to merge 1 commit into
mainfrom
snyk-upgrade-8d1feb34dfffc8b8fef0f3b572a2f62e

Conversation

@1995preethi

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to upgrade express from 4.18.0 to 4.20.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 7 versions ahead of your current version.

  • The recommended version was released on 21 days ago.

Issues fixed by the recommended upgrade:

IssueScoreExploit Maturity
high severityAsymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
391No Known Exploit
medium severityOpen Redirect
SNYK-JS-EXPRESS-6474509
391No Known Exploit
medium severityCross-site Scripting
SNYK-JS-EXPRESS-7926867
391No Known Exploit
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
391Proof of Concept
low severityCross-site Scripting
SNYK-JS-SERVESTATIC-7926865
391No Known Exploit
Release notes
Package name: express
  • 4.20.0 - 2024-09-10
  • 4.19.2 - 2024-03-25

    What's Changed

    Full Changelog: 4.19.1...4.19.2

  • 4.19.1 - 2024-03-20

    What's Changed

    Full Changelog: 4.19.0...4.19.1

  • 4.19.0 - 2024-03-20

    What's Changed

    New Contributors

    Full Changelog: 4.18.3...4.19.0

  • 4.18.3 - 2024-02-29

    Main Changes

    • Fix routing requests without method
    • deps: body-parser@1.20.2
      • Fix strict json error message on Node.js 19+
      • deps: content-type@~1.0.5
      • deps: raw-body@2.5.2

    Other Changes

    New Contributors

    Full Changelog: 4.18.2...4.18.3

  • 4.18.2 - 2022-10-08
    • Fix regression routing a large stack in a single route
    • deps: body-parser@1.20.1
      • deps: qs@6.11.0
      • perf: remove unnecessary object clone
    • deps: qs@6.11.0
  • 4.18.1 - 2022-04-29
    • Fix hanging on large stack of sync routes
  • 4.18.0 - 2022-04-25
    • Add "root" option to res.download
    • Allow options without filename in res.download
    • Deprecate string and non-integer arguments to res.status
    • Fix behavior of null/undefined as maxAge in res.cookie
    • Fix handling very large stacks of sync middleware
    • Ignore Object.prototype values in settings through app.set/app.get
    • Invoke default with same arguments as types in res.format
    • Support proper 205 responses using res.send
    • Use http-errors for res.format error
    • deps: body-parser@1.20.0
      • Fix error message for json parse whitespace in strict
      • Fix internal error when inflated body exceeds limit
      • Prevent loss of async hooks context
      • Prevent hanging when request already read
      • deps: depd@2.0.0
      • deps: http-errors@2.0.0
      • deps: on-finished@2.4.1
      • deps: qs@6.10.3
      • deps: raw-body@2.5.1
    • deps: cookie@0.5.0
      • Add priority option
      • Fix expires option to reject invalid dates
    • deps: depd@2.0.0
      • Replace internal eval usage with Function constructor
      • Use instance methods on process to check for listeners
    • deps: finalhandler@1.2.0
      • Remove set content headers that break response
      • deps: on-finished@2.4.1
      • deps: statuses@2.0.1
    • deps: on-finished@2.4.1
      • Prevent loss of async hooks context
    • deps: qs@6.10.3
    • deps: send@0.18.0
      • Fix emitted 416 error missing headers property
      • Limit the headers removed for 304 response
      • deps: depd@2.0.0
      • deps: destroy@1.2.0
      • deps: http-errors@2.0.0
      • deps: on-finished@2.4.1
      • deps: statuses@2.0.1
    • deps: serve-static@1.15.0
      • deps: send@0.18.0
    • deps: statuses@2.0.1
      • Remove code 306
      • Rename 425 Unordered Collection to standard 425 Too Early
from express GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade express from 4.18.0 to 4.20.0.
See this package in npm:
express
See this project in Snyk:
https://app.snyk.io/org/1995preethi/project/b0681701-5b0b-4607-b970-c667a7c1b4cf?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@1995preethi@snyk-bot