Update dependency express to v4.21.1 - #17
Open
mend-for-github-com[bot] wants to merge 1 commit into
Open
Conversation
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
from
September 29, 2024 12:05
2092561 to
b58b927
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
from
December 6, 2024 20:30
b58b927 to
3f48cd5
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
from
January 27, 2025 04:13
3f48cd5 to
9f5ca58
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
2 times, most recently
from
February 13, 2025 07:42
5f8c8f4 to
9cc1014
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
from
February 23, 2025 08:02
9cc1014 to
f570462
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
2 times, most recently
from
March 9, 2025 18:27
17cdb38 to
792447f
Compare
mend-for-github-com
Bot
deleted the
whitesource-remediate/express-4.x-lockfile
branch
March 20, 2025 16:55
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
from
March 21, 2025 04:54
6e70cb0 to
792447f
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
2 times, most recently
from
October 1, 2025 09:32
e8c7f9f to
e25eba8
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
from
April 9, 2026 01:15
e25eba8 to
f399996
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
from
April 18, 2026 07:16
f399996 to
c132454
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
2 times, most recently
from
May 29, 2026 08:26
d1ded73 to
a40bfc0
Compare
mend-for-github-com
Bot
force-pushed
the
whitesource-remediate/express-4.x-lockfile
branch
from
June 9, 2026 09:18
a40bfc0 to
45e8981
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.17.1→4.21.1By merging this PR, the below vulnerabilities will be automatically resolved:
Release Notes
expressjs/express (express)
v4.21.1Compare Source
What's Changed
Full Changelog: expressjs/express@4.21.0...4.21.1
v4.21.0Compare Source
What's Changed
"back"magic string in redirects by @blakeembrey in #5935New Contributors
Full Changelog: expressjs/express@4.20.0...4.21.0
v4.20.0Compare Source
==========
depthoption to customize the depth level in the parserdepthlevel for parsing URL-encoded data is now32(previously wasInfinity)res.redirect\,|, and^to align better with URL specoptions.maxAgeandoptions.expirestores.clearCookiev4.19.2Compare Source
==========
v4.19.1Compare Source
==========
v4.19.0Compare Source
==========
v4.18.3Compare Source
==========
partitionedoptionv4.18.2Compare Source
===================
v4.18.1Compare Source
===================
v4.18.0Compare Source
===================
res.downloadoptionswithoutfilenameinres.downloadres.statusnull/undefinedasmaxAgeinres.cookieObject.prototypevalues in settings throughapp.set/app.getdefaultwith same arguments as types inres.formatres.sendhttp-errorsforres.formaterrorstrictpriorityoptionexpiresoption to reject invalid datesevalusage withFunctionconstructorprocessto check for listeners425 Unordered Collectionto standard425 Too Earlyv4.17.3Compare Source
===================
__proto__keysv4.17.2Compare Source
===================
undefinedinres.jsonpundefinedwhen"json escape"is enabledRegExpsres.jsonp(obj, status)deprecation messageres.isJSDocmaxAgeoption to reject invalid valuesreq.socketover deprecatedreq.connection