Skip to content

Conversation

renovate-pagopa[bot]
Copy link

@renovate-pagopa renovate-pagopa bot commented Sep 23, 2024

This PR contains the following updates:

Package Type Update Change
express (source) dependencies minor 4.19.1 -> 4.20.0

Warning

Some dependencies could not be looked up. Check the warning logs for more information.

For further information on security, please refer to the Confluence page link


Release Notes

expressjs/express (express)

v4.20.0

Compare Source

==========

  • deps: [email protected]
    • Remove link renderization in html while redirecting
  • deps: [email protected]
    • Remove link renderization in html while redirecting
  • deps: [email protected]
    • add depth option to customize the depth level in the parser
    • IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)
  • Remove link renderization in html while using res.redirect
  • deps: [email protected]
    • Adds support for named matching groups in the routes using a regex
    • Adds backtracking protection to parameters without regexes defined
  • deps: encodeurl@~2.0.0
    • Removes encoding of \, |, and ^ to align better with URL spec
  • Deprecate passing options.maxAge and options.expires to res.clearCookie
    • Will be ignored in v5, clearCookie will set a cookie with an expires in the past to instruct clients to delete the cookie

v4.19.2

Compare Source

==========

  • Improved fix for open redirect allow list bypass

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@renovate-pagopa renovate-pagopa bot requested a review from a team as a code owner September 23, 2024 05:45
@renovate-pagopa renovate-pagopa bot added the OER label Sep 23, 2024
Copy link

Jira Pull request Link

It seems this Pull Request has no issues that refers to Jira!!!
Please check it out.

@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from d86d1c2 to 4725f1a Compare October 9, 2024 05:44
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from 4725f1a to b2fa608 Compare November 11, 2024 05:43
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch 5 times, most recently from 2796718 to ed51e7e Compare December 9, 2024 05:52
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch 4 times, most recently from 48164c2 to 8fd396f Compare December 17, 2024 05:51
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from 8fd396f to 55a012b Compare December 20, 2024 05:50
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from 55a012b to 58b57fe Compare January 3, 2025 05:52
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from 58b57fe to ce4c55a Compare February 5, 2025 05:52
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from ce4c55a to e59466f Compare February 13, 2025 05:51
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from e59466f to ec405f1 Compare February 24, 2025 05:43
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from ec405f1 to b8b3900 Compare March 4, 2025 05:42
@renovate-pagopa renovate-pagopa bot changed the title Bump express from 4.19.1 to 4.20.0 Bump express from 4.19.1 to 4.20.0 - autoclosed Aug 5, 2025
@renovate-pagopa renovate-pagopa bot closed this Aug 5, 2025
@renovate-pagopa renovate-pagopa bot deleted the renovate/express-to-4.20.0 branch August 5, 2025 04:50
@renovate-pagopa renovate-pagopa bot changed the title Bump express from 4.19.1 to 4.20.0 - autoclosed Bump express from 4.19.1 to 4.20.0 Aug 5, 2025
@renovate-pagopa renovate-pagopa bot reopened this Aug 5, 2025
@renovate-pagopa renovate-pagopa bot restored the renovate/express-to-4.20.0 branch August 5, 2025 08:56
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from b8b3900 to d579e38 Compare August 5, 2025 08:56
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from d579e38 to 838a465 Compare September 30, 2025 04:53
@renovate-pagopa renovate-pagopa bot force-pushed the renovate/express-to-4.20.0 branch from 838a465 to 33df5fd Compare October 1, 2025 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants