Skip to content

deps: qs@~6.16.0 - #761

Merged
Phillip9587 merged 1 commit into
expressjs:1.xfrom
krzysdz:1.x-update-qs.6.16
Sep 2, 2026
Merged

deps: qs@~6.16.0#761
Phillip9587 merged 1 commit into
expressjs:1.xfrom
krzysdz:1.x-update-qs.6.16

Conversation

@krzysdz

Copy link
Copy Markdown
Contributor

The 6.16.0 release of qs patches 2 vulnerabilities, neither of which affects body-parser:

@Phillip9587Phillip9587 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@Phillip9587

Copy link
Copy Markdown
Member

@krzysdz Can you please also create a PR for master?

@krzysdz

krzysdz commented Sep 1, 2026

Copy link
Copy Markdown
ContributorAuthor

The 2.x version uses ^6.15.2, so the version bump is not necessary, but I will do it.

EDIT:#762

This was referenced Sep 1, 2026
@Phillip9587
Phillip9587 merged commit 355eb04 into expressjs:1.xSep 2, 2026
35 checks passed
@Phillip9587

Copy link
Copy Markdown
Member

Hey @UlisesGascon we would need your help to get this security 1.x release out.

@krzysdz
krzysdz deleted the 1.x-update-qs.6.16 branch September 2, 2026 12:40
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@krzysdz@Phillip9587