Repository navigation
chore(deps): update dependency express to v5 - #208
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
April 2, 2025 23:43
c50a08a to
490500b
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
May 1, 2025 07:18
490500b to
c7cf350
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
2 times, most recently
from
August 13, 2025 11:38
0605823 to
c46269e
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
September 25, 2025 20:30
c46269e to
d09822e
Compare
dhmlau
force-pushed
the
renovate/express-5.x
branch
from
October 15, 2025 14:39
d09822e to
f48286a
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
October 21, 2025 09:36
f48286a to
f74995c
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
2 times, most recently
from
November 11, 2025 18:17
3b39d26 to
70254a4
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
November 18, 2025 19:55
70254a4 to
adc0e6f
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
4 times, most recently
from
December 6, 2025 00:59
d4164b8 to
91f88a1
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
December 31, 2025 16:49
91f88a1 to
feb43f2
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
January 8, 2026 17:43
feb43f2 to
c62f770
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
2 times, most recently
from
January 23, 2026 16:45
91a79d0 to
3f99261
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
February 1, 2026 14:54
3f99261 to
2cab049
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
February 12, 2026 10:10
2cab049 to
93d9d0a
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
February 24, 2026 14:58
93d9d0a to
c1aaa5b
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
March 5, 2026 14:51
c1aaa5b to
d2a5e68
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
March 13, 2026 12:09
d2a5e68 to
ea76e3e
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
April 1, 2026 04:50
ea76e3e to
636e2ca
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
April 8, 2026 14:51
636e2ca to
bdcbd99
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
2 times, most recently
from
May 1, 2026 12:25
bdfc109 to
a6b1b14
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
2 times, most recently
from
May 14, 2026 20:00
a52b7f5 to
3304d4a
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
June 1, 2026 19:13
3304d4a to
dd214eb
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
2 times, most recently
from
June 15, 2026 01:26
8bdeb59 to
e0937ce
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
July 6, 2026 00:57
e0937ce to
ae4da96
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
July 16, 2026 17:10
ae4da96 to
26ec0e8
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
August 1, 2026 04:20
26ec0e8 to
df3e766
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
August 12, 2026 01:36
df3e766 to
cc60835
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
2 times, most recently
from
September 1, 2026 12:47
3b96648 to
d528ab3
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
September 6, 2026 00:13
d528ab3 to
74738f9
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
3 times, most recently
from
September 18, 2026 19:11
eddeeba to
7c1b70e
Compare
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
September 25, 2026 03:38
7c1b70e to
44418b5
Compare
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
renovate
Bot
force-pushed
the
renovate/express-5.x
branch
from
October 9, 2026 13:44
44418b5 to
c373ea2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^4.12.0→^5.0.0Release Notes
expressjs/express (express)
v5.3.0Compare Source
=====
🐞 Bug fixes
Fixed HTTP header conflict between Content-Length and Transfer-Encoding in res.send - by @YuryShkoda in #4893
Fixed the behavior of
res.send()to prevent conflicts betweenContent-LengthandTransfer-EncodingHTTP headers in responses. TheContent-Lengthheader inres.send()is now only added when aTransfer-Encodingheader is not present, complying with the HTTP specification that states both headers should not coexist in the same response. ETag generation is unaffected by the presence of aTransfer-Encodingheader - by @cuishuang in #7459Upgrade
qsto^6.16.0, which fixes CVE-2026-2391 (GHSA-w7fw-mjwx-w883), CVE-2026-82417 (GHSA-4mjr-xmp4-gh2g) and CVE-2026-82562 (GHSA-x5fp-wj9c-mxmx):arrayLimitbypasses in comma parsing and a denial of service via an attacker-controlledisBuffer- by @davetashner in #7057 and #7478, and @cyphercodes in #7305Upgrade
proxy-addrto^2.0.8, which fixes CVE-2026-90711 - by @lazerg in #7474🚀 Improvements
Allow conditional revalidation for QUERY requests.
req.freshpreviously only validated freshness for GET and HEAD requests, so QUERY responses never returned 304 despite a matching validator. Since QUERY is a safe, idempotent, and cacheable method that supports conditional requests, it is now included in the freshness check - by @Cherry in #7366Improve HTML structure in
res.redirect()responses when HTML format is accepted by adding<!DOCTYPE html>,<title>, and<body>tags for better browser compatibility - by @Bernice55231 in #5167When calling
app.renderwith options set to null, the locals object is handled correctly, preventing unexpected errors and making the method behave the same as when options is omitted or an empty object is passed - by AkaHarshit in #6903Upgrade
content-typeto^2.0.0, bringing a faster parser (~1.5x quickerContent-Typeparsing/formatting inres.send()) along with a behavior change:res.send()now keeps any existing parameters when adding the charset and no longer throws on aContent-Typethat fails to parse.type-isis upgraded to^2.1.0as part of the same change - by @blakeembrey in #7234The default error handler now logs the full error object instead of only its stack trace, so nested details such as
Error.causeand library-specific properties (e.g. Sequelize'sparent/original) are no longer swallowed - by @Nitin-Mohapatra in #6464Upgrade
content-dispositionto^2.0.1, which changes theContent-Dispositionheader emitted byres.download(),res.attachment(), andres.sendFile(): file names that are valid HTTP tokens are no longer wrapped in quotes. This is equivalent per RFC 6266, but applications asserting on the exact header bytes should update their expectations - by @blakeembrey in #7233Upgrade
body-parserto^2.3.0, which fixes CVE-2026-12590 (GHSA-v422-hmwv-36x6): an invalidlimitoption value caused request body size enforcement to be silently disabled (fail-open), allowing a denial of service via arbitrarily large payloads. Invalidlimitvalues now throw at parser initialization instead of being ignored - by @Mayvis in #7390⚡ Performance
res.send()when sending string responses without an explicit Content-Type header - by @bjohansebas in #6991v5.2.1Compare Source
=======================
v5.2.0Compare Source
========================
body-parser@^2.2.1res.redirectwith undefined arguments, Express now emits a warning to help detect calls that pass undefined as the status or URL and make them easier to fix.v5.1.0Compare Source
========================
Uint8Arrayinres.send()res.sendFile()res.links()setprototypeofsafe-bufferutils-mergemethodsdepddebug@^4.4.0body-parser@^2.2.0router@^2.2.0content-type@^1.0.5finalhandler@^2.1.0qs@^6.14.0server-static@2.2.0type-is@2.0.1v5.0.1Compare Source
==========
cookiesemver lock to address CVE-2024-47764v5.0.0Compare Source
=========================
path-is-absolutedependency - usepath.isAbsoluteinsteadres.status()accepts only integers, and input must be greater than 99 and less than 1000RangeError: Invalid status code: ${code}. Status code must be greater than 99 and less than 1000.for inputs outside this rangeTypeError: Invalid status code: ${code}. Status code must be an integer.for non integer inputsres.redirect('back')andres.location('back')is no longer a supported magic string, explicitly usereq.get('Referrer') || '/'.res.clearCookiewill ignore user providedmaxAgeandexpiresoptionsapplication/javascript=>text/javascriptConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.