Skip to content

chore: update dependency express to v5 - #10738

Draft
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/express-5.x
Draft

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/express-5.x

Conversation

@renovate

@renovate renovate Bot commented Nov 14, 2024 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
express (source) ^4.22.3 → ^5.3.0 age adoption passing confidence
@types/express (source) ^4.17.25 → ^5.0.6 age adoption passing confidence

Release Notes

expressjs/express (express)

v5.3.0

Compare Source

=====

🐞 Bug fixes

  • Fixed HTTP header conflict between Content-Length and Transfer-Encoding in res.send - by @​YuryShkoda in #​4893

    Fixed the behavior of res.send() to prevent conflicts between Content-Length and Transfer-Encoding HTTP headers in responses. The Content-Length header in res.send() is now only added when a Transfer-Encoding header is not present, complying with the HTTP specification that states both headers should not coexist in the same response. ETag generation is unaffected by the presence of a Transfer-Encoding header - by @​cuishuang in #​7459

🚀 Improvements

  • Allow conditional revalidation for QUERY requests. req.fresh previously only validated freshness for GET and HEAD requests, so QUERY responses never returned 304 despite a matching validator. Since QUERY is a safe, idempotent, and cacheable method that supports conditional requests, it is now included in the freshness check - by @​Cherry in #​7366

    // QUERY /reports with If-None-Match: "12345"
    app.query('/reports', (req, res) => {
      res.set('ETag', '"12345"');
      res.send(results); // now responds 304 Not Modified
    });
  • Improve HTML structure in res.redirect() responses when HTML format is accepted by adding <!DOCTYPE html>, <title>, and <body> tags for better browser compatibility - by @​Bernice55231 in #​5167

  • When calling app.render with options set to null, the locals object is handled correctly, preventing unexpected errors and making the method behave the same as when options is omitted or an empty object is passed - by AkaHarshit in #​6903

    app.render('index', null, callback); // now works as expected
  • Upgrade content-type to ^2.0.0, bringing a faster parser (~1.5x quicker Content-Type parsing/formatting in res.send()) along with a behavior change: res.send() now keeps any existing parameters when adding the charset and no longer throws on a Content-Type that fails to parse. type-is is upgraded to ^2.1.0 as part of the same change - by @​blakeembrey in #​7234

    res.set('Content-Type', 'text/plain; foo=bar').send('hey');
    // -> Content-Type: text/plain; foo=bar; charset=utf-8
  • The default error handler now logs the full error object instead of only its stack trace, so nested details such as Error.cause and library-specific properties (e.g. Sequelize's parent/original) are no longer swallowed - by @​Nitin-Mohapatra in #​6464

  • Upgrade content-disposition to ^2.0.1, which changes the Content-Disposition header emitted by res.download(), res.attachment(), and res.sendFile(): file names that are valid HTTP tokens are no longer wrapped in quotes. This is equivalent per RFC 6266, but applications asserting on the exact header bytes should update their expectations - by @​blakeembrey in #​7233

    res.attachment('user.html');
    // before -> Content-Disposition: attachment; filename="user.html"
    // after  -> Content-Disposition: attachment; filename=user.html
  • Upgrade body-parser to ^2.3.0, which fixes CVE-2026-12590 (GHSA-v422-hmwv-36x6): an invalid limit option value caused request body size enforcement to be silently disabled (fail-open), allowing a denial of service via arbitrarily large payloads. Invalid limit values now throw at parser initialization instead of being ignored - by @​Mayvis in #​7390

⚡ Performance

  • Avoid duplicate Content-Type header processing in res.send() when sending string responses without an explicit Content-Type header - by @​bjohansebas in #​6991

v5.2.1

Compare Source

=======================

  • Revert security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
    • The prior release (5.2.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.

v5.2.0

Compare Source

========================

  • Security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
  • deps: body-parser@^2.2.1
  • A deprecation warning was added when using res.redirect with undefined arguments, Express now emits a warning to help detect calls that pass undefined as the status or URL and make them easier to fix.

v5.1.0

Compare Source

========================

  • Add support for Uint8Array in res.send()
  • Add support for ETag option in res.sendFile()
  • Add support for multiple links with the same rel in res.links()
  • Add funding field to package.json
  • perf: use loop for acceptParams
  • refactor: prefix built-in node module imports
  • deps: remove setprototypeof
  • deps: remove safe-buffer
  • deps: remove utils-merge
  • deps: remove methods
  • deps: remove depd
  • deps: debug@^4.4.0
  • deps: body-parser@^2.2.0
  • deps: router@^2.2.0
  • deps: content-type@^1.0.5
  • deps: finalhandler@^2.1.0
  • deps: qs@^6.14.0
  • deps: server-static@2.2.0
  • deps: type-is@2.0.1

v5.0.1

Compare Source

==========

v5.0.0

Compare Source

=========================

  • remove:
    • path-is-absolute dependency - use path.isAbsolute instead
  • breaking:
    • res.status() accepts only integers, and input must be greater than 99 and less than 1000
      • will throw a RangeError: Invalid status code: ${code}. Status code must be greater than 99 and less than 1000. for inputs outside this range
      • will throw a TypeError: Invalid status code: ${code}. Status code must be an integer. for non integer inputs
    • deps: send@​1.0.0
    • res.redirect('back') and res.location('back') is no longer a supported magic string, explicitly use req.get('Referrer') || '/'.
  • change:
    • res.clearCookie will ignore user provided maxAge and expires options
  • deps: cookie-signature@^1.2.1
  • deps: debug@​4.3.6
  • deps: merge-descriptors@^2.0.0
  • deps: serve-static@^2.1.0
  • deps: qs@​6.13.0
  • deps: accepts@^2.0.0
  • deps: mime-types@^3.0.0
    • application/javascript => text/javascript
  • deps: type-is@^2.0.0
  • deps: content-disposition@^1.0.0
  • deps: finalhandler@^2.0.0
  • deps: fresh@^2.0.0
  • deps: body-parser@^2.0.1
  • deps: send@^1.1.0

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Nov 14, 2024
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 62fe213 to 4464b83 Compare November 18, 2024 19:10
@renovate renovate Bot changed the title chore: update dependency @types/express to v5 chore: update dependency @types/express to v5 - autoclosed Dec 8, 2024
@renovate renovate Bot closed this Dec 8, 2024
@renovate
renovate Bot deleted the renovate/express-5.x branch December 8, 2024 18:32
@renovate renovate Bot changed the title chore: update dependency @types/express to v5 - autoclosed chore: update dependency @types/express to v5 Dec 12, 2024
@renovate renovate Bot reopened this Dec 12, 2024
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 3 times, most recently from 4b97451 to 43416cc Compare December 12, 2024 14:27
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 2 times, most recently from 429588e to 0ecd034 Compare January 4, 2025 01:55
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 0ecd034 to cfb8a30 Compare January 15, 2025 15:43
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 3 times, most recently from 9ec4d39 to d6925a3 Compare February 3, 2025 18:11
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 2 times, most recently from 297fa86 to a0e9d53 Compare February 13, 2025 15:00
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 4 times, most recently from 03693df to bf08618 Compare March 19, 2025 23:16
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from bf08618 to 301bcb4 Compare March 31, 2025 16:11
@renovate renovate Bot changed the title chore: update dependency @types/express to v5 chore: update dependency express to v5 Mar 31, 2025
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 301bcb4 to 0dd4ae7 Compare April 10, 2025 01:06
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 0dd4ae7 to 293d389 Compare April 17, 2025 17:17
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 3 times, most recently from d88852e to 1f969e2 Compare May 17, 2025 03:39
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 1f969e2 to d9060d5 Compare May 20, 2025 20:38
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 4 times, most recently from dea4a5d to dd2f846 Compare June 17, 2025 14:18
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from dd2f846 to 7c83852 Compare June 19, 2025 02:59
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 2 times, most recently from 84c758d to bd488a1 Compare July 2, 2025 20:18
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 3 times, most recently from d1baee8 to aae3a5b Compare July 18, 2025 17:21
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 5 times, most recently from 7d72ca5 to bbc7b24 Compare August 15, 2025 17:19
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from bbc7b24 to 239e4f2 Compare August 19, 2025 14:03
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 239e4f2 to 6b69bc6 Compare August 31, 2025 10:35
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 6b69bc6 to b98f04d Compare September 10, 2025 16:00
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 3 times, most recently from 4d6c34e to 922cb9d Compare September 25, 2025 18:22
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 922cb9d to a713c16 Compare October 7, 2025 23:49
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 2 times, most recently from 319113e to 5ce0a3f Compare October 21, 2025 18:40
@renovate
renovate Bot force-pushed the renovate/express-5.x branch 4 times, most recently from e5d6a34 to 8c35db8 Compare October 28, 2025 13:33
@renovate
renovate Bot force-pushed the renovate/express-5.x branch from 8c35db8 to 86ca686 Compare November 10, 2025 19:43
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants