Bumps qs and express. These dependencies needed to be updated together.
Updates qs from 6.11.0 to 6.14.2
Changelog
Sourced from qs's changelog.
6.14.2
- [Fix]
parse: mark overflow objects for indexed notation exceeding arrayLimit (#546)
- [Fix]
arrayLimit means max count, not max index, in combine/merge/parseArrayValue
- [Fix]
parse: throw on arrayLimit exceeded with indexed notation when throwOnLimitExceeded is true (#529)
- [Fix]
parse: enforce arrayLimit on comma-parsed values
- [Fix]
parse: fix error message to reflect arrayLimit as max index; remove extraneous comments (#545)
- [Robustness] avoid
.push, use void
- [readme] document that
addQueryPrefix does not add ? to empty output (#418)
- [readme] clarify
parseArrays and arrayLimit documentation (#543)
- [readme] replace runkit CI badge with shields.io check-runs badge
- [meta] fix changelog typo (
arrayLength → arrayLimit)
- [actions] fix rebase workflow permissions
6.14.1
- [Fix] ensure
arrayLimit applies to [] notation as well
- [Fix]
parse: when a custom decoder returns null for a key, ignore that key
- [Refactor]
parse: extract key segment splitting helper
- [meta] add threat model
- [actions] add workflow permissions
- [Tests]
stringify: increase coverage
- [Dev Deps] update
eslint, @ljharb/eslint-config, npmignore, es-value-fixtures, for-each, object-inspect
6.14.0
- [New]
parse: add throwOnParameterLimitExceeded option (#517)
- [Refactor]
parse: use utils.combine more
- [patch]
parse: add explicit throwOnLimitExceeded default
- [actions] use shared action; re-add finishers
- [meta] Fix changelog formatting bug
- [Deps] update
side-channel
- [Dev Deps] update
es-value-fixtures, has-bigints, has-proto, has-symbols
- [Tests] increase coverage
6.13.1
- [Fix]
stringify: avoid a crash when a filter key is null
- [Fix]
utils.merge: functions should not be stringified into keys
- [Fix]
parse: avoid a crash with interpretNumericEntities: true, comma: true, and iso charset
- [Fix]
stringify: ensure a non-string filter does not crash
- [Refactor] use
__proto__ syntax instead of Object.create for null objects
- [Refactor] misc cleanup
- [Tests]
utils.merge: add some coverage
- [Tests] fix a test case
- [actions] split out node 10-20, and 20+
- [Dev Deps] update
es-value-fixtures, mock-property, object-inspect, tape
6.13.0
- [New]
parse: add strictDepth option (#511)
- [Tests] use
npm audit instead of aud
6.12.3
- [Fix]
parse: properly account for strictNullHandling when allowEmptyArrays
... (truncated)
Commits
bdcf0c7 v6.14.2
294db90 [readme] document that addQueryPrefix does not add ? to empty output
5c308e5 [readme] clarify parseArrays and arrayLimit documentation
6addf8c [Fix] parse: mark overflow objects for indexed notation exceeding arrayLimit
cfc108f [Fix] arrayLimit means max count, not max index, in combine/merge/`pars...
febb644 [Fix] parse: throw on arrayLimit exceeded with indexed notation when `thr...
f6a7abf [Fix] parse: enforce arrayLimit on comma-parsed values
fbc5206 [Fix] parse: fix error message to reflect arrayLimit as max index; remove e...
1b9a8b4 [actions] fix rebase workflow permissions
2a35775 [meta] fix changelog typo (arrayLength → arrayLimit)
- Additional commits viewable in compare view
Updates express from 4.18.2 to 4.22.1
Release notes
Sourced from express's releases.
v4.22.1
What's Changed
[!IMPORTANT]
The prior release (4.22.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.
Full Changelog: expressjs/express@4.22.0...v4.22.1
4.22.0
Important: Security
What's Changed
Full Changelog: expressjs/express@4.21.2...4.22.0
4.21.2
What's Changed
Full Changelog: expressjs/express@4.21.1...4.21.2
4.21.1
What's Changed
Full Changelog: expressjs/express@4.21.0...4.21.1
... (truncated)
Changelog
Sourced from express's changelog.
4.22.1 / 2025年12月01日
4.22.0 / 2025年12月01日
4.21.2 / 2024年11月06日
- deps: path-to-regexp@0.1.12
- Fix backtracking protection
- deps: path-to-regexp@0.1.11
- Throws an error on invalid path values
4.21.1 / 2024年10月08日
4.21.0 / 2024年09月11日
- Deprecate
res.location("back") and res.redirect("back") magic string
- deps: serve-static@1.16.2
- deps: finalhandler@1.3.1
- deps: qs@6.13.0
4.20.0 / 2024年09月10日
- deps: serve-static@0.16.0
- Remove link renderization in html while redirecting
- deps: send@0.19.0
- Remove link renderization in html while redirecting
- deps: body-parser@0.6.0
- add
depth option to customize the depth level in the parser
- IMPORTANT: The default
depth level for parsing URL-encoded data is now 32 (previously was Infinity)
- Remove link renderization in html while using
res.redirect
- deps: path-to-regexp@0.1.10
- Adds support for named matching groups in the routes using a regex
- Adds backtracking protection to parameters without regexes defined
- deps: encodeurl@~2.0.0
- Removes encoding of
\, |, and ^ to align better with URL spec
- Deprecate passing
options.maxAge and options.expires to res.clearCookie
... (truncated)
Commits
Maintainer changes
This version was pushed to npm by jonchurch, a new releaser for express since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Bumps qs and express. These dependencies needed to be updated together.
Updates
qsfrom 6.11.0 to 6.14.2Changelog
Sourced from qs's changelog.
... (truncated)
Commits
bdcf0c7v6.14.2294db90[readme] document thataddQueryPrefixdoes not add?to empty output5c308e5[readme] clarifyparseArraysandarrayLimitdocumentation6addf8c[Fix]parse: mark overflow objects for indexed notation exceedingarrayLimitcfc108f[Fix]arrayLimitmeans max count, not max index, incombine/merge/`pars...febb644[Fix]parse: throw onarrayLimitexceeded with indexed notation when `thr...f6a7abf[Fix]parse: enforcearrayLimitoncomma-parsed valuesfbc5206[Fix]parse: fix error message to reflect arrayLimit as max index; remove e...1b9a8b4[actions] fix rebase workflow permissions2a35775[meta] fix changelog typo (arrayLength→arrayLimit)Updates
expressfrom 4.18.2 to 4.22.1Release notes
Sourced from express's releases.
... (truncated)
Changelog
Sourced from express's changelog.
... (truncated)
Commits
12fae144.22.15ddf311Revert "sec: security patch for CVE-2024-51999"49744ab4.22.0 (#6921)6e97452sec: security patch for CVE-2024-519996a23d34deps: use tilde notation forqs(#6919)8c12cdfdeps: qs@6.14.0 (#6909)7fea74fdeps: use tilde notation for certain dependencies (#6905)dac7a04chore: wider range for query test skip (#6513)997919bci: add node.js 24 to test matrix (#6506)36fb59cfix(ci): reordernpm isteps to fix ci for older node versions (#6336)Maintainer changes
This version was pushed to npm by jonchurch, a new releaser for express since your current version.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.