Skip to content

chore(deps-dev): bump compression from 1.7.4 to 1.8.2 in /frontend - #2852

Merged
osmontero merged 1 commit into
v11from
dependabot/npm_and_yarn/frontend/compression-1.8.2
Oct 8, 2026
Merged

osmontero merged 1 commit into
v11from
dependabot/npm_and_yarn/frontend/compression-1.8.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps compression from 1.7.4 to 1.8.2.

Release notes

Sourced from compression's releases.

v1.8.2

Important

What's Changed

New Contributors

Full Changelog: expressjs/compression@v1.8.1...v1.8.2

v1.8.1

What's Changed

... (truncated)

Changelog

Sourced from compression's changelog.

1.8.2

1.8.1

1.8.0

  • Use res.headersSent when available
  • Replace _implicitHeader with writeHead property
  • add brotli support for versions of node that support it
  • Add the enforceEncoding option for requests without Accept-Encoding header

1.7.5

  • deps: Replace accepts with negotiator@~0.6.4
    • Add preference option
  • deps: bytes@3.1.2
    • Add petabyte (pb) support
    • Fix "thousandsSeparator" incorrecting formatting fractional part
    • Fix return value for un-parsable strings
  • deps: compressible@~2.0.18
    • Mark font/ttf as compressible
    • Remove compressible from multipart/mixed
    • deps: mime-db@'>= 1.43.0 < 2'
  • deps: safe-buffer@5.2.1
Commits
  • 0f97074 1.8.2 (#287)
  • 151f63e fix: destroy compression stream on response close
  • 0a76495 fix: match Cache-Control no-transform directive case-insensitively (#286)
  • c17b6e5 docs: update outdated Brotli note and fix npm install docs URL (#276)
  • 112911a chore(ci): npm-publish via reusable workflows (#269)
  • 1bf5eb0 build(deps): bump actions/upload-artifact from 5.0.0 to 6.0.0 (#267)
  • d8fe64d build(deps): bump actions/setup-node from 6.0.0 to 6.1.0 (#266)
  • b218ff5 build(deps): bump github/codeql-action from 4.31.5 to 4.31.9 (#265)
  • 8a1cf8e build(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (#268)
  • 4a19855 build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 (#257)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for compression since your current version.


@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 7, 2026
@dependabot
dependabot Bot requested a review from a team October 7, 2026 14:49
@dependabot dependabot Bot added javascript Pull requests that update javascript code dependencies Pull requests that update a dependency file labels Oct 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/compression-1.8.2 branch from 36cb6a7 to 70a210d Compare October 8, 2026 16:34
Bumps [compression](https://github.com/expressjs/compression) from 1.7.4 to 1.8.2.
- [Release notes](https://github.com/expressjs/compression/releases)
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md)
- [Commits](expressjs/compression@1.7.4...v1.8.2)

---
updated-dependencies:
- dependency-name: compression
  dependency-version: 1.8.2
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/compression-1.8.2 branch from 70a210d to 7730fd7 Compare October 8, 2026 16:39
@osmontero
osmontero merged commit 15cde71 into v11 Oct 8, 2026
2 of 5 checks passed
@osmontero
osmontero deleted the dependabot/npm_and_yarn/frontend/compression-1.8.2 branch October 8, 2026 16:39
osmontero added a commit that referenced this pull request Oct 8, 2026
…build

The six frontend dependabot bumps (#2848, #2849, #2850, #2851, #2852, #2853)
re-resolved package-lock.json from lockfileVersion 1 to 3, dragging in
incompatible transitive deps (@types/node 8→18, echarts 4.9→3.8.5, moment
2.29→2.31) that the Angular 7 / TS 3.2 / Node 14 stack cannot compile.

Reverts frontend/package.json + package-lock.json to the last known-good
state (800dede). The backend/Go dependabot bumps (snakeyaml 2.0, gRPC
1.83.2, OTel 1.45.0) are fine — they don't affect the frontend build.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant