Repository navigation
chore(deps): update dependency express to v5.3.0 - #281
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.2.1→5.3.0Release Notes
expressjs/express (express)
v5.3.0Compare Source
=====
🐞 Bug fixes
Fixed HTTP header conflict between Content-Length and Transfer-Encoding in res.send - by @YuryShkoda in #4893
Fixed the behavior of
res.send()to prevent conflicts betweenContent-LengthandTransfer-EncodingHTTP headers in responses. TheContent-Lengthheader inres.send()is now only added when aTransfer-Encodingheader is not present, complying with the HTTP specification that states both headers should not coexist in the same response. ETag generation is unaffected by the presence of aTransfer-Encodingheader - by @cuishuang in #7459Upgrade
qsto^6.16.0, which fixes CVE-2026-2391 (GHSA-w7fw-mjwx-w883), CVE-2026-82417 (GHSA-4mjr-xmp4-gh2g) and CVE-2026-82562 (GHSA-x5fp-wj9c-mxmx):arrayLimitbypasses in comma parsing and a denial of service via an attacker-controlledisBuffer- by @davetashner in #7057 and #7478, and @cyphercodes in #7305Upgrade
proxy-addrto^2.0.8, which fixes CVE-2026-90711 - by @lazerg in #7474🚀 Improvements
Allow conditional revalidation for QUERY requests.
req.freshpreviously only validated freshness for GET and HEAD requests, so QUERY responses never returned 304 despite a matching validator. Since QUERY is a safe, idempotent, and cacheable method that supports conditional requests, it is now included in the freshness check - by @Cherry in #7366Improve HTML structure in
res.redirect()responses when HTML format is accepted by adding<!DOCTYPE html>,<title>, and<body>tags for better browser compatibility - by @Bernice55231 in #5167When calling
app.renderwith options set to null, the locals object is handled correctly, preventing unexpected errors and making the method behave the same as when options is omitted or an empty object is passed - by AkaHarshit in #6903Upgrade
content-typeto^2.0.0, bringing a faster parser (~1.5x quickerContent-Typeparsing/formatting inres.send()) along with a behavior change:res.send()now keeps any existing parameters when adding the charset and no longer throws on aContent-Typethat fails to parse.type-isis upgraded to^2.1.0as part of the same change - by @blakeembrey in #7234The default error handler now logs the full error object instead of only its stack trace, so nested details such as
Error.causeand library-specific properties (e.g. Sequelize'sparent/original) are no longer swallowed - by @Nitin-Mohapatra in #6464Upgrade
content-dispositionto^2.0.1, which changes theContent-Dispositionheader emitted byres.download(),res.attachment(), andres.sendFile(): file names that are valid HTTP tokens are no longer wrapped in quotes. This is equivalent per RFC 6266, but applications asserting on the exact header bytes should update their expectations - by @blakeembrey in #7233Upgrade
body-parserto^2.3.0, which fixes CVE-2026-12590 (GHSA-v422-hmwv-36x6): an invalidlimitoption value caused request body size enforcement to be silently disabled (fail-open), allowing a denial of service via arbitrarily large payloads. Invalidlimitvalues now throw at parser initialization instead of being ignored - by @Mayvis in #7390⚡ Performance
res.send()when sending string responses without an explicit Content-Type header - by @bjohansebas in #6991Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.