Skip to content

chore(deps): update dependency body-parser to v1.20.4 (main)#102

Open
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/main-body-parser-1.20.x-lockfile
Open

chore(deps): update dependency body-parser to v1.20.4 (main)#102
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/main-body-parser-1.20.x-lockfile

Conversation

@mend-for-github-com
Copy link

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
body-parser 1.20.11.20.4 age adoption passing confidence

This PR resolves the vulnerabilities described in Issue #64


Version 1.20.1
Risk Change Critical High Medium Low
N/A 0 1 0 2
Version 1.20.4
Risk Change Critical High Medium Low
-100% 0 (--) 0 (-1 ) 0 (--) 0 (-2 )

Mend ensures you have the greatest risk reduction ("Recommended Fix"-highlighted in green) by removing as many vulnerabilities as possible. Click to see how we calculate risk reduction.


Release Notes

expressjs/body-parser (body-parser)

v1.20.4

Compare Source

===================

  • deps: qs@~6.14.0
  • deps: use tilde notation for dependencies
  • deps: http-errors@~2.0.1
  • deps: raw-body@~2.5.3

v1.20.3

Compare Source

===================

  • deps: qs@​6.13.0
  • add depth option to customize the depth level in the parser
  • IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)

v1.20.2

Compare Source

===================

  • Fix strict json error message on Node.js 19+
  • deps: content-type@~1.0.5
    • perf: skip value escaping when unnecessary
  • deps: raw-body@​2.5.2

  • If you want to rebase/retry this PR, check this box

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants