Skip to content

📦 Update dependencies (major) - #223

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-dependencies
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-dependencies

Conversation

@renovate

@renovate renovate Bot commented Mar 31, 2025 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@google-cloud/logging (source) 11.2.0 → 12.2.0 age confidence
@google-cloud/storage (source) 7.17.0 → 8.4.0 age confidence
express (source) 4.21.2 → 5.3.0 age confidence

Release Notes

googleapis/google-cloud-node (@​google-cloud/logging)

v12.2.0

Features
  • tools: Add individual CLI flags for Bun monkey patches (#​9533) (a5eec89)

v12.1.0

Features

v12.0.1

Bug Fixes
  • Ensure node 22 dependencies are up to date so they get the latest patches for core and handwritten libraries (#​9116) (fad57ff)

v12.0.0

⚠ BREAKING CHANGES
  • Update logging to minimum Node version of 22. (#​9048)
Features

v11.4.0

Features
  • logging: Split GAPIC from the logging handwritten package (#​8929) (ee21766)

v11.3.0

Features
  • Consolidate prettierignore and prettierrc files: handwritten (#​8081) (a241532)
Bug Fixes

v11.2.3

Bug Fixes

v11.2.2

Bug Fixes

v11.2.1

Bug Fixes
  • logging: Specifying resourceNames should fetch logs only from those resources (#​1597) (ff7899f)
googleapis/google-cloud-node (@​google-cloud/storage)

v8.4.0

Features

v8.3.0

Features
  • tools: Add individual CLI flags for Bun monkey patches (#​9533) (a5eec89)

v8.2.0

Features

v8.1.0

Features
  • storage: Add IpFilter support to bucket metadata (#​8623) (30c91c8)
  • storage: Add x-goog-gcs-idempotency-token header (#​8837) (0df2e55)
  • storage: Support copying CSEK-encrypted files to non-CSEK destinations (#​8771) (953328f)
Bug Fixes
  • storage: Resolve strict linter and TypeScript errors (#​9198) (cee5338)

v8.0.1

Bug Fixes
  • Upgrade storage dependencies to corresponding Node 22 versions for core, handwritten and generated libraries (#​9135) (a3d9092)

v8.0.0

⚠ BREAKING CHANGES
  • Update storage to minimum Node version of 22. (#​9079)
Features

v7.22.0

Features
  • storage: Add deleteSourceObjects option to combine/compose method (#​8444) (43abc45)
Bug Fixes
  • storage: Destroy local read stream on upload write failure to prevent resource leaks (#​8752) (77dab53), refs #​7325
  • storage: Pass signingEndpoint to URLSigner in file.getSignedUrl (#​8982) (b001807)
  • storage: Resolve Node compatibility crashes, security vulnerability, and stream hangs (#​8622) (512ba79)
  • storage: Set application/json Content-Type for impersonated ADC requests (#​8419) (292c688)

v7.21.0

Features
  • storage: Enable CRC32C validation by default in transfer manager (#​8350) (86086a6)
Bug Fixes

v7.19.0

Features
Bug Fixes
  • deps: Update dependency fast-xml-parser to v5 [security] (#​2713) (420935a)

v7.18.0

Features
  • listBuckets: Add support for returning partial success (#​2678) (c7004da)

v7.17.3

Bug Fixes
  • 🐛 fix the issue 2667, do not mutate object given to options … (#​2668) (8a9f259)
  • Revert implement path containment to prevent traversal attacks (254b6b2)

v7.17.2

Bug Fixes

v7.17.1

Bug Fixes
  • Respect useAuthWithCustomEndpoint flag for resumable uploads (#​2637) (707b4f2)
expressjs/express (express)

v5.3.0

Compare Source

=====

🐞 Bug fixes

  • Fixed HTTP header conflict between Content-Length and Transfer-Encoding in res.send - by @​YuryShkoda in #​4893

    Fixed the behavior of res.send() to prevent conflicts between Content-Length and Transfer-Encoding HTTP headers in responses. The Content-Length header in res.send() is now only added when a Transfer-Encoding header is not present, complying with the HTTP specification that states both headers should not coexist in the same response. ETag generation is unaffected by the presence of a Transfer-Encoding header - by @​cuishuang in #​7459

🚀 Improvements

  • Allow conditional revalidation for QUERY requests. req.fresh previously only validated freshness for GET and HEAD requests, so QUERY responses never returned 304 despite a matching validator. Since QUERY is a safe, idempotent, and cacheable method that supports conditional requests, it is now included in the freshness check - by @​Cherry in #​7366

    // QUERY /reports with If-None-Match: "12345"
    app.query('/reports', (req, res) => {
      res.set('ETag', '"12345"');
      res.send(results); // now responds 304 Not Modified
    });
  • Improve HTML structure in res.redirect() responses when HTML format is accepted by adding <!DOCTYPE html>, <title>, and <body> tags for better browser compatibility - by @​Bernice55231 in #​5167

  • When calling app.render with options set to null, the locals object is handled correctly, preventing unexpected errors and making the method behave the same as when options is omitted or an empty object is passed - by AkaHarshit in #​6903

    app.render('index', null, callback); // now works as expected
  • Upgrade content-type to ^2.0.0, bringing a faster parser (~1.5x quicker Content-Type parsing/formatting in res.send()) along with a behavior change: res.send() now keeps any existing parameters when adding the charset and no longer throws on a Content-Type that fails to parse. type-is is upgraded to ^2.1.0 as part of the same change - by @​blakeembrey in #​7234

    res.set('Content-Type', 'text/plain; foo=bar').send('hey');
    // -> Content-Type: text/plain; foo=bar; charset=utf-8
  • The default error handler now logs the full error object instead of only its stack trace, so nested details such as Error.cause and library-specific properties (e.g. Sequelize's parent/original) are no longer swallowed - by @​Nitin-Mohapatra in #​6464

  • Upgrade content-disposition to ^2.0.1, which changes the Content-Disposition header emitted by res.download(), res.attachment(), and res.sendFile(): file names that are valid HTTP tokens are no longer wrapped in quotes. This is equivalent per RFC 6266, but applications asserting on the exact header bytes should update their expectations - by @​blakeembrey in #​7233

    res.attachment('user.html');
    // before -> Content-Disposition: attachment; filename="user.html"
    // after  -> Content-Disposition: attachment; filename=user.html
  • Upgrade body-parser to ^2.3.0, which fixes CVE-2026-12590 (GHSA-v422-hmwv-36x6): an invalid limit option value caused request body size enforcement to be silently disabled (fail-open), allowing a denial of service via arbitrarily large payloads. Invalid limit values now throw at parser initialization instead of being ignored - by @​Mayvis in #​7390

⚡ Performance

  • Avoid duplicate Content-Type header processing in res.send() when sending string responses without an explicit Content-Type header - by @​bjohansebas in #​6991

v5.2.1

Compare Source

=======================

  • Revert security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
    • The prior release (5.2.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.

v5.2.0

Compare Source

========================

  • Security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
  • deps: body-parser@^2.2.1
  • A deprecation warning was added when using res.redirect with undefined arguments, Express now emits a warning to help detect calls that pass undefined as the status or URL and make them easier to fix.

v5.1.0

Compare Source

========================

  • Add support for Uint8Array in res.send()
  • Add support for ETag option in res.sendFile()
  • Add support for multiple links with the same rel in res.links()
  • Add funding field to package.json
  • perf: use loop for acceptParams
  • refactor: prefix built-in node module imports
  • deps: remove setprototypeof
  • deps: remove safe-buffer
  • deps: remove utils-merge
  • deps: remove methods
  • deps: remove depd
  • deps: debug@^4.4.0
  • deps: body-parser@^2.2.0
  • deps: router@^2.2.0
  • deps: content-type@^1.0.5
  • deps: finalhandler@^2.1.0
  • deps: qs@^6.14.0
  • deps: server-static@2.2.0
  • deps: type-is@2.0.1

v5.0.1

Compare Source

==========

v5.0.0

Compare Source

=========================

  • remove:
    • path-is-absolute dependency - use path.isAbsolute instead
  • breaking:
    • res.status() accepts only integers, and input must be greater than 99 and less than 1000
      • will throw a RangeError: Invalid status code: ${code}. Status code must be greater than 99 and less than 1000. for inputs outside this range
      • will throw a TypeError: Invalid status code: ${code}. Status code must be an integer. for non integer inputs
    • deps: send@​1.0.0
    • res.redirect('back') and res.location('back') is no longer a supported magic string, explicitly use req.get('Referrer') || '/'.
  • change:
    • res.clearCookie will ignore user provided maxAge and expires options
  • deps: cookie-signature@^1.2.1
  • deps: debug@​4.3.6
  • deps: merge-descriptors@^2.0.0
  • deps: serve-static@^2.1.0
  • deps: qs@​6.13.0
  • deps: accepts@^2.0.0
  • deps: mime-types@^3.0.0
    • application/javascript => text/javascript
  • deps: type-is@^2.0.0
  • deps: content-disposition@^1.0.0
  • deps: finalhandler@^2.0.0
  • deps: fresh@^2.0.0
  • deps: body-parser@^2.0.1
  • deps: send@^1.1.0

v4.22.3

Compare Source

What's Changed
New Contributors

Full Changelog: expressjs/express@v4.22.2...v4.22.3

v4.22.2

Compare Source

What's Changed

  • fix: restore >20 array parsing for req.query repeated keys (8d09bfe6)
    • This also unifies array-cap behavior across notations. Indexed notation (a[0]=...) was historically capped at qs's default arrayLimit of 20 even in older qs versions; after this change it also allows up to 1000 items.
  • deps: qs@~6.15.1
  • deps: body-parser@~1.20.5

New Contributors

Full Changelog: expressjs/express@v4.22.1...v4.22.2

v4.22.1

Compare Source

What's Changed

[!IMPORTANT]
The prior release (4.22.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.

Full Changelog: expressjs/express@4.22.0...v4.22.1

v4.22.0

Compare Source

Important: Security

What's Changed

Full Changelog: expressjs/express@4.21.2...4.22.0


Configuration

📅 Schedule: (in timezone America/Los_Angeles)

  • Branch creation
    • "after 12am every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 88f0f7a to cfa4353 Compare August 10, 2025 13:29
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 5 times, most recently from c43e311 to 8e9d06c Compare September 4, 2025 17:27
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 8e9d06c to 0eeb199 Compare September 25, 2025 13:53
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 0eeb199 to 0fea4bd Compare November 19, 2025 00:45
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 2 times, most recently from cc866d3 to f665d78 Compare December 1, 2025 21:41
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from f665d78 to e286393 Compare December 31, 2025 16:15
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from e286393 to 9e92459 Compare January 8, 2026 19:06
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 2 times, most recently from 9d67c51 to 62d5b51 Compare February 17, 2026 14:44
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 2 times, most recently from 47883ca to 9d05bf9 Compare April 8, 2026 19:17
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 9d05bf9 to f2cda36 Compare April 29, 2026 13:47
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 2 times, most recently from 4f6f2a9 to 4ab2d15 Compare May 18, 2026 10:53
@renovate renovate Bot changed the title 📦 Update dependency express to v5 📦 Update dependencies to v5 Jun 2, 2026
@renovate renovate Bot changed the title 📦 Update dependencies to v5 📦 Update dependencies (major) Jun 22, 2026
@renovate renovate Bot changed the title 📦 Update dependencies (major) 📦 Update dependency express to v5 Jun 25, 2026
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 4ab2d15 to 2405070 Compare July 12, 2026 11:07
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 2405070 to 8a559ec Compare July 24, 2026 19:46
@renovate renovate Bot changed the title 📦 Update dependency express to v5 📦 Update dependencies (major) Aug 5, 2026
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 8a559ec to 1362936 Compare August 5, 2026 04:57
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 4 times, most recently from 153888d to 03700c2 Compare August 18, 2026 22:37
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 03700c2 to fbdd1b7 Compare August 26, 2026 13:54
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 3 times, most recently from fe5ffe1 to c35e62a Compare September 8, 2026 14:49
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 3 times, most recently from d4fb405 to f16813a Compare September 16, 2026 20:12
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from f16813a to cf27e32 Compare September 17, 2026 22:20
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 2 times, most recently from 0e518c0 to b1e91f4 Compare October 1, 2026 00:55
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch 3 times, most recently from 7e7f43a to 9beaf48 Compare October 9, 2026 04:23
@renovate
renovate Bot force-pushed the renovate/major-dependencies branch from 9beaf48 to 49bdbae Compare October 9, 2026 16:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants