Skip to content

chore(deps): bump the minor-and-patch group across 1 directory with 34 updates - #246

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-500c0aafb6
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/minor-and-patch-500c0aafb6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 34 updates in the / directory:

Package From To
@cap-js-community/odata-v2-adapter 1.16.0 1.16.1
@cap-js/hana 3.0.1 3.1.1
@cap-js/postgres 3.0.1 3.1.1
@cap-js/sqlite 3.0.2 3.1.1
@inquirer/prompts 8.5.2 8.7.2
@json2csv/node 7.0.6 7.0.8
@modelcontextprotocol/sdk 1.30.0 1.30.1
@sap-cloud-sdk/resilience 4.7.0 4.9.1
@sap/cds 10.0.3 10.1.1
@sap/textbundle 6.2.0 6.3.0
@sap/xsenv 6.2.1 6.2.2
csv-parse 7.0.1 7.0.3
hdb 2.29.5 2.30.1
inquirer 14.0.2 14.2.2
js-yaml 5.4.1 5.4.2
jszip 3.10.1 3.10.2
multer 2.2.0 2.4.0
open 11.0.0 11.0.4
terminal-kit 3.1.3 3.1.4
uuid 14.0.1 14.0.2
ws 8.21.0 8.22.0
yargs 18.0.0 18.2.0
@sap/eslint-plugin-cds 4.2.4 4.2.5
@types/node 26.1.1 26.6.3
@wdio/cli 9.31.5 9.32.0
@wdio/globals 9.29.1 9.31.3
@wdio/local-runner 9.31.5 9.32.0
@wdio/mocha-framework 9.31.5 9.32.0
@wdio/spec-reporter 9.29.1 9.32.0
eslint 10.7.0 10.11.0
sinon 22.0.0 22.1.0
supertest 7.2.2 7.3.0
wdio-ui5-service 3.0.11 3.0.12
webdriverio 9.31.5 9.32.0

Updates @cap-js-community/odata-v2-adapter from 1.16.0 to 1.16.1

Release notes

Sourced from @​cap-js-community/odata-v2-adapter's releases.

v1.16.1

Fixed:

  • Migrate jest to vitest
  • Dependencies
Changelog

Sourced from @​cap-js-community/odata-v2-adapter's changelog.

Version 1.16.1 - 2026-08-04

Fixed

  • Migrate jest to vitest
  • Dependencies
Commits

Updates @cap-js/hana from 3.0.1 to 3.1.1

Release notes

Sourced from @​cap-js/hana's releases.

db-service: v3.1.1

3.1.1 (2026-09-15)

Fixed

  • cqn4sql: correctly expand not exists alongside a null-check branch (#1736) (bfb0a01)

Performance Improvements

  • do not use ranked search for static values (#1727) (33fb36b)
  • if explicit order by is specified, do not add ranked search as a secondary clause (33fb36b)

hana: v3.1.1

3.1.1 (2026-09-15)

Fixed

Performance Improvements

  • do not use ranked search for static values (#1727) (33fb36b)
  • if explicit order by is specified, do not add ranked search as a secondary clause (33fb36b)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​cap-js/db-service bumped from ^3.1.0 to ^3.1.1

postgres: v3.1.1

3.1.1 (2026-09-15)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​cap-js/db-service bumped from ^3.1.0 to ^3.1.1

sqlite: v3.1.1

3.1.1 (2026-09-15)

Dependencies

... (truncated)

Commits
  • 7241d2d chore: release main (#1728)
  • bfb0a01 fix(cqn4sql): correctly expand not exists \<assoc> alongside a null-check br...
  • 960ac9b fix: resolve service projections for upsert (#1735)
  • 33fb36b perf: do not use ranked search for static values (#1727)
  • dba03e9 chore: release main (#1703)
  • bc93160 feat: rank $search results by relevance (#1725)
  • 633db11 test(cqn4sql): refactor calculated elements test suite (#1643)
  • cf6af99 fix(pool): recover lost connection after stale acquire timeout (#1724)
  • c9228a6 chore(deps-dev): bump @​sap/hana-client from 2.29.25 to 2.29.27 in the depende...
  • 1443f85 chore(deps): bump qs from 6.15.3 to 6.16.0 (#1722)
  • Additional commits viewable in compare view

Updates @cap-js/postgres from 3.0.1 to 3.1.1

Release notes

Sourced from @​cap-js/postgres's releases.

db-service: v3.1.1

3.1.1 (2026-09-15)

Fixed

  • cqn4sql: correctly expand not exists alongside a null-check branch (#1736) (bfb0a01)

Performance Improvements

  • do not use ranked search for static values (#1727) (33fb36b)
  • if explicit order by is specified, do not add ranked search as a secondary clause (33fb36b)

hana: v3.1.1

3.1.1 (2026-09-15)

Fixed

Performance Improvements

  • do not use ranked search for static values (#1727) (33fb36b)
  • if explicit order by is specified, do not add ranked search as a secondary clause (33fb36b)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​cap-js/db-service bumped from ^3.1.0 to ^3.1.1

postgres: v3.1.1

3.1.1 (2026-09-15)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​cap-js/db-service bumped from ^3.1.0 to ^3.1.1

sqlite: v3.1.1

3.1.1 (2026-09-15)

Dependencies

... (truncated)

Commits
  • 7241d2d chore: release main (#1728)
  • bfb0a01 fix(cqn4sql): correctly expand not exists \<assoc> alongside a null-check br...
  • 960ac9b fix: resolve service projections for upsert (#1735)
  • 33fb36b perf: do not use ranked search for static values (#1727)
  • dba03e9 chore: release main (#1703)
  • bc93160 feat: rank $search results by relevance (#1725)
  • 633db11 test(cqn4sql): refactor calculated elements test suite (#1643)
  • cf6af99 fix(pool): recover lost connection after stale acquire timeout (#1724)
  • c9228a6 chore(deps-dev): bump @​sap/hana-client from 2.29.25 to 2.29.27 in the depende...
  • 1443f85 chore(deps): bump qs from 6.15.3 to 6.16.0 (#1722)
  • Additional commits viewable in compare view

Updates @cap-js/sqlite from 3.0.2 to 3.1.1

Release notes

Sourced from @​cap-js/sqlite's releases.

db-service: v3.1.1

3.1.1 (2026-09-15)

Fixed

  • cqn4sql: correctly expand not exists alongside a null-check branch (#1736) (bfb0a01)

Performance Improvements

  • do not use ranked search for static values (#1727) (33fb36b)
  • if explicit order by is specified, do not add ranked search as a secondary clause (33fb36b)

hana: v3.1.1

3.1.1 (2026-09-15)

Fixed

Performance Improvements

  • do not use ranked search for static values (#1727) (33fb36b)
  • if explicit order by is specified, do not add ranked search as a secondary clause (33fb36b)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​cap-js/db-service bumped from ^3.1.0 to ^3.1.1

postgres: v3.1.1

3.1.1 (2026-09-15)

Dependencies

  • The following workspace dependencies were updated
    • dependencies
      • @​cap-js/db-service bumped from ^3.1.0 to ^3.1.1

sqlite: v3.1.1

3.1.1 (2026-09-15)

Dependencies

... (truncated)

Commits
  • 7241d2d chore: release main (#1728)
  • bfb0a01 fix(cqn4sql): correctly expand not exists \<assoc> alongside a null-check br...
  • 960ac9b fix: resolve service projections for upsert (#1735)
  • 33fb36b perf: do not use ranked search for static values (#1727)
  • dba03e9 chore: release main (#1703)
  • bc93160 feat: rank $search results by relevance (#1725)
  • 633db11 test(cqn4sql): refactor calculated elements test suite (#1643)
  • cf6af99 fix(pool): recover lost connection after stale acquire timeout (#1724)
  • c9228a6 chore(deps-dev): bump @​sap/hana-client from 2.29.25 to 2.29.27 in the depende...
  • 1443f85 chore(deps): bump qs from 6.15.3 to 6.16.0 (#1722)
  • Additional commits viewable in compare view

Updates @inquirer/prompts from 8.5.2 to 8.7.2

Release notes

Sourced from @​inquirer/prompts's releases.

@​inquirer/prompts@​8.7.2

What's new

  • Fixed a race where keystrokes batched in the same tick as the key that settled a prompt could still reach keypress handlers after the prompt was done, cancelled, or aborted (@inquirer/core, #2255, closes #1816).
  • confirm() now trims surrounding whitespace from answers before matching yes/no keywords (@inquirer/confirm, #2254).

Included

  • @inquirer/checkbox@^5.2.5
  • @inquirer/confirm@^6.3.2
  • @inquirer/editor@^5.3.3
  • @inquirer/expand@^5.1.5
  • @inquirer/input@^5.1.6
  • @inquirer/number@^4.2.3
  • @inquirer/password@^5.2.2
  • @inquirer/rawlist@^5.3.5
  • @inquirer/search@^4.3.3
  • @inquirer/select@^5.2.5

@​inquirer/prompts@​8.7.1

What's new

  • All bundled prompts now pin @inquirer/type to an exact version in their published manifests. Since these type definitions leak into consumers' tsc runs, a semver range on the types-only dependency could break downstream TypeScript builds without any change to Inquirer.js itself (#2247, fixes #2244).

Included

  • @inquirer/checkbox@^5.2.4
  • @inquirer/confirm@^6.3.1
  • @inquirer/editor@^5.3.2
  • @inquirer/expand@^5.1.4
  • @inquirer/input@^5.1.5
  • @inquirer/number@^4.2.2
  • @inquirer/password@^5.2.1
  • @inquirer/rawlist@^5.3.4
  • @inquirer/search@^4.3.2
  • @inquirer/select@^5.2.4

@​inquirer/prompts@​8.7.0

What's new

  • password gains the toggleMask option (ctrl+t to reveal the typed value).
  • confirm now matches localized yes/no answers per-locale.
  • Prettified prompt and theme types for better IDE display.
  • Added inquirer-grouped-checkbox to the community prompts list (#2236).

Included

... (truncated)

Commits
  • cbdb34b chore: Publish new release
  • 8340d2d fix(@​inquirer/core): clear hook effects before settling prompts
  • 2475e07 test(@​inquirer/core): cover hook cleanup error semantics
  • 15cd8d3 fix(confirm): ignore surrounding whitespace in answers
  • 9cb0da6 chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9
  • 1c750bc chore(deps-dev): Bump the build group with 3 updates (#2251)
  • 81f1525 chore(deps-dev): Bump @​types/node in the types group (#2252)
  • 7c27f26 chore(deps-dev): Bump oxfmt in the formatting group (#2249)
  • 6119088 chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (#2250)
  • 0d167c0 chore(deps-dev): Bump the linting group with 4 updates (#2248)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​inquirer/prompts since your current version.


Updates @json2csv/node from 7.0.6 to 7.0.8

Changelog

Sourced from @​json2csv/node's changelog.

7.0.8 (2026-08-04)

Bug Fixes

  • --config file values silently overridden by CLI option defaults (3785565)
  • --pretty tears quoted values apart on embedded delimiter/newline (5705272)
  • flatten treats empty objects and empty arrays inconsistently (7231780)
  • includeEmptyRows:true silently drops single-field empty rows (6e28964)
  • null array elements crash field-inference with raw TypeError (f1bf37f)
  • quote/separator regex injection and decimals:0 in formatters (14c9f8d)
  • TablePrinter splits astral characters (emoji) across wrapped lines (2863e5f)
  • unencoded file paths break dynamic import() in CLI (2d7289c)
  • WHATWG AsyncParser mutates caller's asyncOpts on array/object input (3476a15)
  • WHATWG TransformStream events silently no-op outside a browser (2b24b5d)

Performance Improvements

  • avoid array allocation in quote-only formatter (e5066f8)
  • batch stream output per input chunk (3afffb5)
  • cache parsed field paths (2e945d6)
  • cache parsed property paths in transforms getProp (4127458)
  • discover unwind paths once (c2fdaee)
  • flatten arrays without spread (256c36b)
  • lazily consume array inputs in AsyncParser (417012f)
  • precompile TablePrinter's cell-wrapping regex per column (e8e97e1)
  • use a Set for field inference (6f295e6)

7.0.7 (2025-01-26)

Bug Fixes

  • fix incorrect docs about transformers actions (150cef3)
  • infinite loop in flatten (e81cd60)
Commits
  • 6b90db8 chore: bump version number and update changelog
  • 06d5ab1 docs: fix outdated and incorrect documentation
  • 2f29c59 chore: update dependencies
  • 2863e5f fix: TablePrinter splits astral characters (emoji) across wrapped lines
  • e8e97e1 perf: precompile TablePrinter's cell-wrapping regex per column
  • 471098c chore: mark WHATWG TransformStream's readable field as declare
  • 34c9959 chore: remove dead getProp export from plainjs/utils.ts
  • 7231780 fix: flatten treats empty objects and empty arrays inconsistently
  • 5705272 fix: --pretty tears quoted values apart on embedded delimiter/newline
  • 4127458 perf: cache parsed property paths in transforms getProp
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​json2csv/node since your current version.


Updates @modelcontextprotocol/sdk from 1.30.0 to 1.30.1

Release notes

Sourced from @​modelcontextprotocol/sdk's releases.

1.30.1

What's Changed

New Contributors

Full Changelog: modelcontextprotocol/typescript-sdk@1.30.0...1.30.1

Commits
  • 289ac2c chore: bump version to 1.30.1 (#2848)
  • 12b4256 fix(auth): preserve resource URI without trailing slash (#1968) (#1972)
  • a9f6eb7 [v1.x] fix(server): read HTTP request bodies with a size limit and bound JSON...
  • See full diff in compare view

Updates @sap-cloud-sdk/resilience from 4.7.0 to 4.9.1

Release notes

Sourced from @​sap-cloud-sdk/resilience's releases.

v4.9.1

Fixed Issues

  • [connectivity, generator, generator-common, http-client, odata-common, odata-v2, odata-v4, openapi, openapi-generator, resilience, temporal-de-serializers] Export ./internal.js named export in package.json for compatibility. Please migrate to the new named export ./internal, the old export is deprecated and will be removed in the next major release. (e8f8134)

v4.9.0

Compatibility Notes

  • [generator-common] Generated files now include a blank line between the copyright header and the file content. (118131d)
  • [openapi-generator] Fields with contentMediaType: application/json and a contentSchema will now be typed as the contentSchema type instead of string. Re-generate your client to pick up the new types. (404dc92)

New Features

  • [openapi-generator] Support contentSchema in OpenAPI 3.1 schemas: fields with contentMediaType: application/json and a contentSchema are now typed as the contentSchema type instead of string. Serialization to a JSON string is supported for multipart bodies via FormDataBuilder; non-multipart bodies are not yet handled. (404dc92)
  • [openapi-generator] OpenAPI generator now supports OAS 3.1 input. This feature is experiemental. Use with caution. (5f6fe80)

Fixed Issues

  • [connectivity] Extend OnPremise HTTP agent cache key to scope it more strongly. The cache key now includes the subaccount identity ensuring keep-alive sockets are not reused across tenants in multi-tenant technical user flows. If no stable identity context can be derived from the request, a fresh agent without keep-alive is created for each request. This matches the behavior of the previous implementation in SAP Cloud SDK v4.6.0 and lower, which did not cache agents in any case. (9f55261)
  • [generator-common] readCompilerOptions now uses the TypeScript compiler API for tsconfig parsing, fixing support for JSONC (comments, trailing commas), package-name extends (e.g. @tsconfig/node18), and circular extends chains. (88c304e)
  • [http-client] Restore proxy authorization headers for same-origin redirects when using proxy configuration. (05e9299)

v4.8.0

Compatibility Notes

  • [generator, openapi-generator] Transpilation now includes inherited compiler options. (82a6d2d)
  • [generator, generator-common, openapi-generator] The project has been updated to typescript version 6. Some options are deprecated in TypeScript 6, reference the breaking changes page for more details. (b7cfc1b)

New Features

  • [connectivity, http-client] A new agentOptions property on Destination allows configuring the underlying HTTP(S) agent (e.g. keepAlive, timeout) without constructing an agent manually. (32aab37)

Fixed Issues

  • [connectivity] HTTP(S) agents are now cached per destination instead of per protocol and options, preventing unintended agent reuse across different destinations. (34da40e)
  • [connectivity] Refactor HTTP agent cache for better runtime compatibility. (a42a3a2)
  • [connectivity, util] Fix DestinationOrFetchOptions and HttpDestinationOrFetchOptions so the service key surfaces at the type level. (24fe0c5)
  • [generator, openapi-generator] Transpilation now resolves extends inheritance in tsconfig files, merging base config options with child options taking precedence. (82a6d2d)
  • [openapi] Wrap Buffer responses in Blob when executing OpenAPI requests that return binary data. (e568017)

Improvements

  • [generator-common] Extend script target mapper to handle ES2023, ES2024, and ES2025 targets. Extend module kind mapper to handle UMD, System, ES2022, Node18, Node20, and Preserve module kinds. Extend module resolution mapping to handle Bundler. (9df742e)
Changelog

Sourced from @​sap-cloud-sdk/resilience's changelog.

4.9.1

Patch Changes

  • e8f8134: [fix] Export ./internal.js named export in package.json for compatibility. Please migrate to the new named export ./internal, the old export is deprecated and will be removed in the next major release.
  • @​sap-cloud-sdk/util@​4.9.1

4.9.0

Patch Changes

  • @​sap-cloud-sdk/util@​4.9.0

4.8.0

Patch Changes

  • @​sap-cloud-sdk/util@​4.8.0
Commits

Updates @sap/cds from 10.0.3 to 10.1.1

Updates @sap/textbundle from 6.2.0 to 6.3.0

Updates @sap/xsenv from 6.2.1 to 6.2.2

Updates csv-parse from 7.0.1 to 7.0.3

Changelog

Sourced from csv-parse's changelog.

7.0.3 (2026-09-25)

Bug Fixes

  • csv-parse: preserve typed column keys (#500) (745f045)
  • csv-parse: type the delimiter_auto score callback arguments (#499) (4aa04da)

7.0.2 (2026-08-02)

Bug Fixes

  • csv-parse: prototype replacement reachable via columns (#497)

Performance Improvements

  • csv-parse: avoid unnecessary allocation in ResizeableBuffer.toString (#495)
Commits
  • 594c646 chore(release): publish
  • 16d9900 refactor(csv-parse): isolate error and normalize_options in types
  • 4aa04da fix(csv-parse): type the delimiter_auto score callback arguments (#499)
  • 8d4173d build: latest dev dependencies
  • c8caa1c build: generate latest dist
  • 6c45c9b build: remove npx usage in package scripts
  • 6f39f27 test: remove lint errors
  • 94ae7b9 test: rename mocha setup rule
  • 42a6b09 test: remove ts-node usage
  • 745f045 fix(csv-parse): preserve typed column keys (#500)
  • Additional commits viewable in compare view

Updates hdb from 2.29.5 to 2.30.1

Release notes

Sourced from hdb's releases.

v2.30.1

Changelog v2.30.1

Features

  • Added client.isValid() method to check whether the current session is still connected ([f7d2b65])

Fixes

  • setClientInfo with an empty string as the value now succeeds instead of throwing ([5247eab])
  • Fixed security vulnerability GHSA-2883-xcg3-v3hh by upgrading js-yaml ([7ef15c4])
  • Fixed security vulnerabilities GHSA-5p4m-2wfm-xmqj (js-yaml) and GHSA-rgw5-rvv9-x895 (brace-expansion) ([4d84ab1])

Internal / Refactoring

  • Modernised filesystem LOB examples and removed fstream dependency ([5465427])
  • Fixed "avaliable" typo in Writer.js comments ([968e537])
  • Removed obsolete test/mocha.opts ([f3fd7fa])

v2.29.6

Changelog v2.29.6

Fixes

  • Keep extra space for potential client info updates ([a691e82])

Infrastructure

Commits

Updates inquirer from 14.0.2 to 14.2.2

Release notes

Sourced from inquirer's releases.

inquirer@14.2.2

The umbrella package, bundling @inquirer/prompts and @inquirer/core.

What's new

  • Fixed a race where keystrokes batched in the same tick as the key that settled a prompt could still reach keypress handlers after the prompt was done, cancelled, or aborted (@inquirer/core, #2255, closes #1816).
  • confirm() now trims surrounding whitespace from answers before matching yes/no keywords (@inquirer/confirm, #2254).

Included

  • @inquirer/core@^12.0.3
  • @inquirer/prompts@^8.7.2

inquirer@14.2.1

The umbrella package, bundling @inquirer/prompts and @inquirer/core.

What's new

  • Published manifests now pin @inquirer/type to an exact version. Since these type definitions leak into consumers' tsc runs, a semver range on the types-only dependency could break downstream TypeScript builds without any change to Inquirer.js itself (#2247, fixes #2244).

Included

  • @inquirer/core@^12.0.2
  • @inquirer/prompts@^8.7.1
  • @inquirer/type@4.1.1 (pinned exactly)
  • @inquirer/ansi@^2.0.8

inquirer@14.2.0

The umbrella package, bundling @inquirer/prompts and @inquirer/core.

What's new

  • Updated to @inquirer/prompts@^8.7.0 and @inquirer/core@^12.0.1.
  • Includes the new toggleMask option for password (ctrl+t to reveal), localized yes/no parsing for confirm, and prettified prompt/theme types for better IDE display.

Included

  • @inquirer/core@^12.0.1
  • @inquirer/prompts@^8.7.0
  • @inquirer/type@^4.1.0
  • @inquirer/ansi@^2.0.7

inquirer@14.1.0

The umbrella package, bundling @inquirer/prompts and @inquirer/core.

What's new

... (truncated)

Commits
  • cbdb34b chore: Publish new release
  • 8340d2d fix(@​inquirer/core): clear hook effects before settling prompts
  • 2475e07 test(@​inquirer/core): cover hook cleanup error semantics
  • 15cd8d3 fix(confirm): ignore surrounding whitespace in answers
  • 9cb0da6 chore(deps): Bump github/codeql-action/analyze from 4.37.7 to 4.37.9
  • 1c750bc chore(deps-dev): Bump the build group with 3 updates (#2251)
  • 81f1525 chore(deps-dev): Bump @​types/node in the types group (#2252)
  • 7c27f26 chore(deps-dev): Bump oxfmt in the formatting group (#2249)
  • 6119088 chore(deps): Bump github/codeql-action/init from 4.37.7 to 4.37.9 (#2250)
  • 0d167c0 chore(deps-dev): Bump the linting group with 4 updates (#2248)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for inquirer since your current version.


Updates js-yaml from 5.4.1 to 5.4.2

Changelog

Sourced from js-yaml's changelog.

[5.4.2] - 2026-09-13

Fixed

  • forceQuotes no longer quotes non-string scalars, #798.
Commits

Updates jszip from 3.10.1 to 3.10.2

Changelog

Sourced from jszip's changelog.

v3.10.2 2026-09-09

  • Fix cross-realm binary type detection in getTypeOf. Fixes #759 (see #578)
  • Add missing types for JSZip.defaults. Fixes #690 (see #927)
  • Fix Blob support in Node.js 18 and up. Fixes #941 (see #955)
Commits
Maintainer changes

This version was pushed to npm by jkoops, a new releaser for jszip since your current version.


Updates multer from 2.2.0 to 2.4.0

Release notes

Sourced from multer's releases.

v2.4.0

Highlights

multer finally supports Google Cloud Functions and Firebase 🎉

These platforms read the request body before your code runs, so multer's classic req.pipe(busboy) received nothing: empty req.body, empty req.files, and nearly a decade of duplicated issues.

The new streamHandler option closes that gap: you decide how the body reaches the parser, so the pre-read rawBody just works (see image).

const multer = require('multer')
const upload = multer({
storage: multer.memoryStorage(),
streamHandler: (req, busboy) => {
// Cloud Functions / Firebase expose the pre-read body here
if (req.rawBody) busboy.end(req.rawBody)
else req.pipe(busboy)
}
})
app.post('/upload', upload.single('file'), (req, res) => {
res.json({ name: req.file.originalname, size: req.file.size })
})

This landed thanks to community PRs going back to 2017; their authors are credited as co-authors in the release.

Important: Security

What's Changed

…4 updates

Bumps the minor-and-patch group with 34 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [@cap-js-community/odata-v2-adapter](https://github.com/cap-js-community/odata-v2-adapter) | `1.16.0` | `1.16.1` |
| [@cap-js/hana](https://github.com/cap-js/cds-dbs) | `3.0.1` | `3.1.1` |
| [@cap-js/postgres](https://github.com/cap-js/cds-dbs) | `3.0.1` | `3.1.1` |
| [@cap-js/sqlite](https://github.com/cap-js/cds-dbs) | `3.0.2` | `3.1.1` |
| [@inquirer/prompts](https://github.com/SBoudrias/Inquirer.js) | `8.5.2` | `8.7.2` |
| [@json2csv/node](https://github.com/juanjoDiaz/json2csv) | `7.0.6` | `7.0.8` |
| [@modelcontextprotocol/sdk](https://github.com/modelcontextprotocol/typescript-sdk) | `1.30.0` | `1.30.1` |
| [@sap-cloud-sdk/resilience](https://github.com/SAP/cloud-sdk-js/tree/HEAD/packages/resilience) | `4.7.0` | `4.9.1` |
| [@sap/cds](https://cap.cloud.sap/) | `10.0.3` | `10.1.1` |
| @sap/textbundle | `6.2.0` | `6.3.0` |
| @sap/xsenv | `6.2.1` | `6.2.2` |
| [csv-parse](https://github.com/adaltas/node-csv/tree/HEAD/packages/csv-parse) | `7.0.1` | `7.0.3` |
| [hdb](https://github.com/SAP/node-hdb) | `2.29.5` | `2.30.1` |
| [inquirer](https://github.com/SBoudrias/Inquirer.js) | `14.0.2` | `14.2.2` |
| [js-yaml](https://github.com/nodeca/js-yaml) | `5.4.1` | `5.4.2` |
| [jszip](https://github.com/Stuk/jszip) | `3.10.1` | `3.10.2` |
| [multer](https://github.com/expressjs/multer) | `2.2.0` | `2.4.0` |
| [open](https://github.com/sindresorhus/open) | `11.0.0` | `11.0.4` |
| [terminal-kit](https://github.com/cronvel/terminal-kit) | `3.1.3` | `3.1.4` |
| [uuid](https://github.com/uuidjs/uuid) | `14.0.1` | `14.0.2` |
| [ws](https://github.com/websockets/ws) | `8.21.0` | `8.22.0` |
| [yargs](https://github.com/yargs/yargs) | `18.0.0` | `18.2.0` |
| [@sap/eslint-plugin-cds](https://cap.cloud.sap/) | `4.2.4` | `4.2.5` |
| [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node) | `26.1.1` | `26.6.3` |
| [@wdio/cli](https://github.com/webdriverio/webdriverio/tree/HEAD/packages/wdio-cli) | `9.31.5` | `9.32.0` |
| [@wdio/globals](https://github.com/webdriverio/webdriverio/tree/HEAD/packages/wdio-globals) | `9.29.1` | `9.31.3` |
| [@wdio/local-runner](https://github.com/webdriverio/webdriverio/tree/HEAD/packages/wdio-local-runner) | `9.31.5` | `9.32.0` |
| [@wdio/mocha-framework](https://github.com/webdriverio/webdriverio/tree/HEAD/packages/wdio-mocha-framework) | `9.31.5` | `9.32.0` |
| [@wdio/spec-reporter](https://github.com/webdriverio/webdriverio/tree/HEAD/packages/wdio-spec-reporter) | `9.29.1` | `9.32.0` |
| [eslint](https://github.com/eslint/eslint) | `10.7.0` | `10.11.0` |
| [sinon](https://github.com/sinonjs/sinon) | `22.0.0` | `22.1.0` |
| [supertest](https://github.com/ladjs/supertest) | `7.2.2` | `7.3.0` |
| [wdio-ui5-service](https://github.com/ui5-community/wdi5) | `3.0.11` | `3.0.12` |
| [webdriverio](https://github.com/webdriverio/webdriverio/tree/HEAD/packages/webdriverio) | `9.31.5` | `9.32.0` |



Updates `@cap-js-community/odata-v2-adapter` from 1.16.0 to 1.16.1
- [Release notes](https://github.com/cap-js-community/odata-v2-adapter/releases)
- [Changelog](https://github.com/cap-js-community/odata-v2-adapter/blob/main/CHANGELOG.md)
- [Commits](cap-js-community/odata-v2-adapter@v1.16.0...v1.16.1)

Updates `@cap-js/hana` from 3.0.1 to 3.1.1
- [Release notes](https://github.com/cap-js/cds-dbs/releases)
- [Commits](cap-js/cds-dbs@hana-v3.0.1...hana-v3.1.1)

Updates `@cap-js/postgres` from 3.0.1 to 3.1.1
- [Release notes](https://github.com/cap-js/cds-dbs/releases)
- [Commits](cap-js/cds-dbs@hana-v3.0.1...hana-v3.1.1)

Updates `@cap-js/sqlite` from 3.0.2 to 3.1.1
- [Release notes](https://github.com/cap-js/cds-dbs/releases)
- [Commits](cap-js/cds-dbs@hana-v3.0.2...hana-v3.1.1)

Updates `@inquirer/prompts` from 8.5.2 to 8.7.2
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/@inquirer/prompts@8.5.2...@inquirer/prompts@8.7.2)

Updates `@json2csv/node` from 7.0.6 to 7.0.8
- [Release notes](https://github.com/juanjoDiaz/json2csv/releases)
- [Changelog](https://github.com/juanjoDiaz/json2csv/blob/main/CHANGELOG.md)
- [Commits](juanjoDiaz/json2csv@v7.0.6...v7.0.8)

Updates `@modelcontextprotocol/sdk` from 1.30.0 to 1.30.1
- [Release notes](https://github.com/modelcontextprotocol/typescript-sdk/releases)
- [Commits](modelcontextprotocol/typescript-sdk@1.30.0...1.30.1)

Updates `@sap-cloud-sdk/resilience` from 4.7.0 to 4.9.1
- [Release notes](https://github.com/SAP/cloud-sdk-js/releases)
- [Changelog](https://github.com/SAP/cloud-sdk-js/blob/main/packages/resilience/CHANGELOG.md)
- [Commits](https://github.com/SAP/cloud-sdk-js/commits/v4.9.1/packages/resilience)

Updates `@sap/cds` from 10.0.3 to 10.1.1

Updates `@sap/textbundle` from 6.2.0 to 6.3.0

Updates `@sap/xsenv` from 6.2.1 to 6.2.2

Updates `csv-parse` from 7.0.1 to 7.0.3
- [Changelog](https://github.com/adaltas/node-csv/blob/master/packages/csv-parse/CHANGELOG.md)
- [Commits](https://github.com/adaltas/node-csv/commits/csv-parse@7.0.3/packages/csv-parse)

Updates `hdb` from 2.29.5 to 2.30.1
- [Release notes](https://github.com/SAP/node-hdb/releases)
- [Commits](SAP/node-hdb@v2.29.5...v2.30.1)

Updates `inquirer` from 14.0.2 to 14.2.2
- [Release notes](https://github.com/SBoudrias/Inquirer.js/releases)
- [Commits](https://github.com/SBoudrias/Inquirer.js/compare/inquirer@14.0.2...inquirer@14.2.2)

Updates `js-yaml` from 5.4.1 to 5.4.2
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md)
- [Commits](nodeca/js-yaml@5.4.1...5.4.2)

Updates `jszip` from 3.10.1 to 3.10.2
- [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md)
- [Commits](Stuk/jszip@v3.10.1...v3.10.2)

Updates `multer` from 2.2.0 to 2.4.0
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](expressjs/multer@v2.2.0...v2.4.0)

Updates `open` from 11.0.0 to 11.0.4
- [Release notes](https://github.com/sindresorhus/open/releases)
- [Commits](sindresorhus/open@v11.0.0...v11.0.4)

Updates `terminal-kit` from 3.1.3 to 3.1.4
- [Changelog](https://github.com/cronvel/terminal-kit/blob/master/CHANGELOG)
- [Commits](cronvel/terminal-kit@v3.1.3...v3.1.4)

Updates `uuid` from 14.0.1 to 14.0.2
- [Release notes](https://github.com/uuidjs/uuid/releases)
- [Changelog](https://github.com/uuidjs/uuid/blob/main/CHANGELOG.md)
- [Commits](uuidjs/uuid@v14.0.1...v14.0.2)

Updates `ws` from 8.21.0 to 8.22.0
- [Release notes](https://github.com/websockets/ws/releases)
- [Commits](websockets/ws@8.21.0...8.22.0)

Updates `yargs` from 18.0.0 to 18.2.0
- [Release notes](https://github.com/yargs/yargs/releases)
- [Changelog](https://github.com/yargs/yargs/blob/main/CHANGELOG.md)
- [Commits](yargs/yargs@v18.0.0...v18.2.0)

Updates `@sap/eslint-plugin-cds` from 4.2.4 to 4.2.5

Updates `@types/node` from 26.1.1 to 26.6.3
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `@wdio/cli` from 9.31.5 to 9.32.0
- [Release notes](https://github.com/webdriverio/webdriverio/releases)
- [Changelog](https://github.com/webdriverio/webdriverio/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webdriverio/webdriverio/commits/v9.32.0/packages/wdio-cli)

Updates `@wdio/globals` from 9.29.1 to 9.31.3
- [Release notes](https://github.com/webdriverio/webdriverio/releases)
- [Changelog](https://github.com/webdriverio/webdriverio/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webdriverio/webdriverio/commits/v9.31.3/packages/wdio-globals)

Updates `@wdio/local-runner` from 9.31.5 to 9.32.0
- [Release notes](https://github.com/webdriverio/webdriverio/releases)
- [Changelog](https://github.com/webdriverio/webdriverio/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webdriverio/webdriverio/commits/v9.32.0/packages/wdio-local-runner)

Updates `@wdio/mocha-framework` from 9.31.5 to 9.32.0
- [Release notes](https://github.com/webdriverio/webdriverio/releases)
- [Changelog](https://github.com/webdriverio/webdriverio/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webdriverio/webdriverio/commits/v9.32.0/packages/wdio-mocha-framework)

Updates `@wdio/spec-reporter` from 9.29.1 to 9.32.0
- [Release notes](https://github.com/webdriverio/webdriverio/releases)
- [Changelog](https://github.com/webdriverio/webdriverio/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webdriverio/webdriverio/commits/v9.32.0/packages/wdio-spec-reporter)

Updates `eslint` from 10.7.0 to 10.11.0
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v10.7.0...v10.11.0)

Updates `sinon` from 22.0.0 to 22.1.0
- [Release notes](https://github.com/sinonjs/sinon/releases)
- [Changelog](https://github.com/sinonjs/sinon/blob/main/CHANGES.md)
- [Commits](sinonjs/sinon@v22.0.0...v22.1.0)

Updates `supertest` from 7.2.2 to 7.3.0
- [Release notes](https://github.com/ladjs/supertest/releases)
- [Commits](forwardemail/supertest@v7.2.2...v7.3.0)

Updates `wdio-ui5-service` from 3.0.11 to 3.0.12
- [Release notes](https://github.com/ui5-community/wdi5/releases)
- [Changelog](https://github.com/ui5-community/wdi5/blob/main/CHANGELOG.md)
- [Commits](ui5-community/wdi5@v3.0.11...v3.0.12)

Updates `webdriverio` from 9.31.5 to 9.32.0
- [Release notes](https://github.com/webdriverio/webdriverio/releases)
- [Changelog](https://github.com/webdriverio/webdriverio/blob/main/CHANGELOG.md)
- [Commits](https://github.com/webdriverio/webdriverio/commits/v9.32.0/packages/webdriverio)

---
updated-dependencies:
- dependency-name: "@cap-js-community/odata-v2-adapter"
  dependency-version: 1.16.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@cap-js/hana"
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@cap-js/postgres"
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@cap-js/sqlite"
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@inquirer/prompts"
  dependency-version: 8.7.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@json2csv/node"
  dependency-version: 7.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@modelcontextprotocol/sdk"
  dependency-version: 1.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@sap-cloud-sdk/resilience"
  dependency-version: 4.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@sap/cds"
  dependency-version: 10.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@sap/textbundle"
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@sap/xsenv"
  dependency-version: 6.2.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: csv-parse
  dependency-version: 7.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: hdb
  dependency-version: 2.30.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: inquirer
  dependency-version: 14.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: js-yaml
  dependency-version: 5.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: jszip
  dependency-version: 3.10.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: multer
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: open
  dependency-version: 11.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: terminal-kit
  dependency-version: 3.1.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: uuid
  dependency-version: 14.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ws
  dependency-version: 8.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: yargs
  dependency-version: 18.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@sap/eslint-plugin-cds"
  dependency-version: 4.2.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.6.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@wdio/cli"
  dependency-version: 9.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@wdio/globals"
  dependency-version: 9.31.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@wdio/local-runner"
  dependency-version: 9.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@wdio/mocha-framework"
  dependency-version: 9.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@wdio/spec-reporter"
  dependency-version: 9.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: eslint
  dependency-version: 10.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: sinon
  dependency-version: 22.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: supertest
  dependency-version: 7.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: wdio-ui5-service
  dependency-version: 3.0.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: webdriverio
  dependency-version: 9.32.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@dependabot
dependabot Bot requested a review from jung-thomas as a code owner September 30, 2026 03:27
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants