tamirdahan / NodeJSWebApp

0 stars 0 forks source link

Update dependency express to v4.20.0 - autoclosed #12

Closed mend-for-github-com[bot] closed 1 week ago

mend-for-github-com[bot] commented 2 months ago

This PR contains the following updates:

Package Type Update Change
express (source) dependencies minor 4.19.2 -> 4.20.0

By merging this PR, the issue #11 will be automatically resolved and closed:

Severity CVSS Score CVE
Medium Medium 5.0 CVE-2024-43796

Release Notes

expressjs/express (express) ### [`v4.20.0`](https://togithub.com/expressjs/express/blob/HEAD/History.md#4200--2024-09-10) [Compare Source](https://togithub.com/expressjs/express/compare/4.19.2...4.20.0) \========== - deps: serve-static@0.16.0 - Remove link renderization in html while redirecting - deps: send@0.19.0 - Remove link renderization in html while redirecting - deps: body-parser@0.6.0 - add `depth` option to customize the depth level in the parser - IMPORTANT: The default `depth` level for parsing URL-encoded data is now `32` (previously was `Infinity`) - Remove link renderization in html while using `res.redirect` - deps: path-to-regexp@0.1.10 - Adds support for named matching groups in the routes using a regex - Adds backtracking protection to parameters without regexes defined - deps: encodeurl@~2.0.0 - Removes encoding of `\`, `|`, and `^` to align better with URL spec - Deprecate passing `options.maxAge` and `options.expires` to `res.clearCookie` - Will be ignored in v5, clearCookie will set a cookie with an expires in the past to instruct clients to delete the cookie