Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deprecate "back" magic string in redirects #5935

Merged
merged 2 commits into from
Sep 11, 2024

Conversation

blakeembrey
Copy link
Member

Related to #5933, deprecates this and directs users to read security best practices for open redirects.

@blakeembrey blakeembrey requested a review from a team September 10, 2024 03:35
@blakeembrey blakeembrey changed the title Deprecate back magic string Deprecate "back" magic string in redirects Sep 10, 2024
Copy link
Member

@LinusU LinusU left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great! 👍

@wesleytodd
Copy link
Member

We are preparing a release to fix some mis-aligned versions. Do we want to ship this deprecation as well?

@blakeembrey blakeembrey changed the base branch from master to 4.x September 11, 2024 18:55
@blakeembrey
Copy link
Member Author

Yes, I think we should. Changed the base, feel free to merge.

@blakeembrey
Copy link
Member Author

The only question is whether you'd prefer I use a link shortener instead? That way we can change the URL if docs move around.

@wesleytodd
Copy link
Member

Hm, yeah I guess that makes sense. We can always add a html redirect page at that url if we wanted. Do you want to use the link shortener you used for the path to regex ones?

@blakeembrey
Copy link
Member Author

Done, I'm just using dub.co but they only support git.new for GitHub URLs, so it's dub.sh for this one. We can buy a custom short domain if we care a lot about this too, or alias a sub-domain of the existing express domain later.

@wesleytodd
Copy link
Member

Sounds good to me, we good to merge this?

@blakeembrey blakeembrey merged commit 77ada90 into expressjs:4.x Sep 11, 2024
47 checks passed
@blakeembrey blakeembrey deleted the be/deprecate-back-string branch September 11, 2024 19:24
aviator-app bot referenced this pull request in nordic-game-lab/advertising-sdk Sep 12, 2024
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [express](http://expressjs.com/) ([source](https://redirect.github.com/expressjs/express)) | [`4.20.0` -> `4.21.0`](https://renovatebot.com/diffs/npm/express/4.20.0/4.21.0) | [![age](https://developer.mend.io/api/mc/badges/age/npm/express/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/express/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/express/4.20.0/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/express/4.20.0/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) |

---

### Release Notes

<details>
<summary>expressjs/express (express)</summary>

### [`v4.21.0`](https://redirect.github.com/expressjs/express/releases/tag/4.21.0)

[Compare Source](https://redirect.github.com/expressjs/express/compare/4.20.0...4.21.0)

#### What's Changed

-   Deprecate `"back"` magic string in redirects by [@&#8203;blakeembrey](https://redirect.github.com/blakeembrey) in [https://github.com/expressjs/express/pull/5935](https://redirect.github.com/expressjs/express/pull/5935)
-   [email protected] by [@&#8203;wesleytodd](https://redirect.github.com/wesleytodd) in [https://github.com/expressjs/express/pull/5954](https://redirect.github.com/expressjs/express/pull/5954)
-   fix(deps): [email protected] by [@&#8203;wesleytodd](https://redirect.github.com/wesleytodd) in [https://github.com/expressjs/express/pull/5951](https://redirect.github.com/expressjs/express/pull/5951)
-   Upgraded dependency qs to 6.13.0 to match qs in body-parser by [@&#8203;agadzinski93](https://redirect.github.com/agadzinski93) in [https://github.com/expressjs/express/pull/5946](https://redirect.github.com/expressjs/express/pull/5946)

#### New Contributors

-   [@&#8203;agadzinski93](https://redirect.github.com/agadzinski93) made their first contribution in [https://github.com/expressjs/express/pull/5946](https://redirect.github.com/expressjs/express/pull/5946)

**Full Changelog**: expressjs/express@4.20.0...4.21.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/nordic-game-lab/advertising-sdk).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC43NC4xIiwidXBkYXRlZEluVmVyIjoiMzguNzQuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYXV0b21lcmdlIl19-->
renovate bot referenced this pull request in line/line-bot-sdk-nodejs Sep 12, 2024
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [express](http://expressjs.com/)
([source](https://redirect.github.com/expressjs/express)) | [`4.20.0` ->
`4.21.0`](https://renovatebot.com/diffs/npm/express/4.20.0/4.21.0) |
[![age](https://developer.mend.io/api/mc/badges/age/npm/express/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/express/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/express/4.20.0/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/express/4.20.0/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

### Release Notes

<details>
<summary>expressjs/express (express)</summary>

###
[`v4.21.0`](https://redirect.github.com/expressjs/express/releases/tag/4.21.0)

[Compare
Source](https://redirect.github.com/expressjs/express/compare/4.20.0...4.21.0)

#### What's Changed

- Deprecate `"back"` magic string in redirects by
[@&#8203;blakeembrey](https://redirect.github.com/blakeembrey) in
[https://github.com/expressjs/express/pull/5935](https://redirect.github.com/expressjs/express/pull/5935)
- [email protected] by
[@&#8203;wesleytodd](https://redirect.github.com/wesleytodd) in
[https://github.com/expressjs/express/pull/5954](https://redirect.github.com/expressjs/express/pull/5954)
- fix(deps): [email protected] by
[@&#8203;wesleytodd](https://redirect.github.com/wesleytodd) in
[https://github.com/expressjs/express/pull/5951](https://redirect.github.com/expressjs/express/pull/5951)
- Upgraded dependency qs to 6.13.0 to match qs in body-parser by
[@&#8203;agadzinski93](https://redirect.github.com/agadzinski93) in
[https://github.com/expressjs/express/pull/5946](https://redirect.github.com/expressjs/express/pull/5946)

#### New Contributors

- [@&#8203;agadzinski93](https://redirect.github.com/agadzinski93) made
their first contribution in
[https://github.com/expressjs/express/pull/5946](https://redirect.github.com/expressjs/express/pull/5946)

**Full Changelog**:
expressjs/express@4.20.0...4.21.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/line/line-bot-sdk-nodejs).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC43NC4xIiwidXBkYXRlZEluVmVyIjoiMzguNzQuMSIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJkZXBlbmRlbmN5IHVwZ3JhZGUiXX0=-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
aviator-app bot referenced this pull request in nordic-game-lab/learnhub-sdk Sep 12, 2024
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [express](http://expressjs.com/) ([source](https://redirect.github.com/expressjs/express)) | [`4.20.0` -> `4.21.0`](https://renovatebot.com/diffs/npm/express/4.20.0/4.21.0) | [![age](https://developer.mend.io/api/mc/badges/age/npm/express/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/express/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/express/4.20.0/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) | [![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/express/4.20.0/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/) |

---

### Release Notes

<details>
<summary>expressjs/express (express)</summary>

### [`v4.21.0`](https://redirect.github.com/expressjs/express/releases/tag/4.21.0)

[Compare Source](https://redirect.github.com/expressjs/express/compare/4.20.0...4.21.0)

#### What's Changed

-   Deprecate `"back"` magic string in redirects by [@&#8203;blakeembrey](https://redirect.github.com/blakeembrey) in [https://github.com/expressjs/express/pull/5935](https://redirect.github.com/expressjs/express/pull/5935)
-   [email protected] by [@&#8203;wesleytodd](https://redirect.github.com/wesleytodd) in [https://github.com/expressjs/express/pull/5954](https://redirect.github.com/expressjs/express/pull/5954)
-   fix(deps): [email protected] by [@&#8203;wesleytodd](https://redirect.github.com/wesleytodd) in [https://github.com/expressjs/express/pull/5951](https://redirect.github.com/expressjs/express/pull/5951)
-   Upgraded dependency qs to 6.13.0 to match qs in body-parser by [@&#8203;agadzinski93](https://redirect.github.com/agadzinski93) in [https://github.com/expressjs/express/pull/5946](https://redirect.github.com/expressjs/express/pull/5946)

#### New Contributors

-   [@&#8203;agadzinski93](https://redirect.github.com/agadzinski93) made their first contribution in [https://github.com/expressjs/express/pull/5946](https://redirect.github.com/expressjs/express/pull/5946)

**Full Changelog**: expressjs/express@4.20.0...4.21.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/nordic-game-lab/learnhub-sdk).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC43NC4xIiwidXBkYXRlZEluVmVyIjoiMzguNzQuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiYXV0b21lcmdlIl19-->
patricebender referenced this pull request in cap-js/cds-dbs Sep 12, 2024
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [express](http://expressjs.com/)
([source](https://redirect.github.com/expressjs/express)) | [`4.20.0` ->
`4.21.0`](https://renovatebot.com/diffs/npm/express/4.20.0/4.21.0) |
[![age](https://developer.mend.io/api/mc/badges/age/npm/express/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/express/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/express/4.20.0/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/express/4.20.0/4.21.0?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

### Release Notes

<details>
<summary>expressjs/express (express)</summary>

###
[`v4.21.0`](https://redirect.github.com/expressjs/express/releases/tag/4.21.0)

[Compare
Source](https://redirect.github.com/expressjs/express/compare/4.20.0...4.21.0)

#### What's Changed

- Deprecate `"back"` magic string in redirects by
[@&#8203;blakeembrey](https://redirect.github.com/blakeembrey) in
[https://github.com/expressjs/express/pull/5935](https://redirect.github.com/expressjs/express/pull/5935)
- [email protected] by
[@&#8203;wesleytodd](https://redirect.github.com/wesleytodd) in
[https://github.com/expressjs/express/pull/5954](https://redirect.github.com/expressjs/express/pull/5954)
- fix(deps): [email protected] by
[@&#8203;wesleytodd](https://redirect.github.com/wesleytodd) in
[https://github.com/expressjs/express/pull/5951](https://redirect.github.com/expressjs/express/pull/5951)
- Upgraded dependency qs to 6.13.0 to match qs in body-parser by
[@&#8203;agadzinski93](https://redirect.github.com/agadzinski93) in
[https://github.com/expressjs/express/pull/5946](https://redirect.github.com/expressjs/express/pull/5946)

#### New Contributors

- [@&#8203;agadzinski93](https://redirect.github.com/agadzinski93) made
their first contribution in
[https://github.com/expressjs/express/pull/5946](https://redirect.github.com/expressjs/express/pull/5946)

**Full Changelog**:
expressjs/express@4.20.0...4.21.0

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/cap-js/cds-dbs).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC43NC4xIiwidXBkYXRlZEluVmVyIjoiMzguNzQuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
otc-zuul bot pushed a commit to opentelekomcloud-infra/backstage that referenced this pull request Nov 19, 2024
chore(deps): Bump the npm_and_yarn group with 9 updates

Bumps the npm_and_yarn group with 9 updates:



Package
From
To




@backstage/plugin-app-backend
0.3.74
0.3.75


cross-spawn
7.0.3
7.0.6


dset
3.1.3
3.1.4


express
4.19.2
4.21.1


http-proxy-middleware
2.0.6
2.0.7


path-to-regexp
0.1.7
0.1.10


rollup
4.21.2
4.27.3


send
0.18.0
0.19.0


serve-static
1.15.0
1.16.2



Updates @backstage/plugin-app-backend from 0.3.74 to 0.3.75

Changelog
Sourced from @​backstage/plugin-app-backend's changelog.

@​backstage/plugin-app-backend
0.4.0
Minor Changes

815b702: Configuration is no longer injected into static assets if a index.html.tmpl file is present.

Patch Changes

815b702: The index.html templating is now done and served from memory rather than written to the filesystem. This means that you can now use config injection with a read-only filesystem, and you no longer need to use the app.disableConfigInjection flag.
Updated dependencies

@​backstage/config@​1.3.0
@​backstage/types@​1.2.0
@​backstage/config-loader@​1.9.2
@​backstage/plugin-auth-node@​0.5.4
@​backstage/backend-plugin-api@​1.0.2
@​backstage/errors@​1.2.5
@​backstage/plugin-app-node@​0.1.27



0.3.77-next.2
Patch Changes

Updated dependencies

@​backstage/plugin-auth-node@​0.5.4-next.2
@​backstage/backend-plugin-api@​1.0.2-next.2
@​backstage/config@​1.2.0
@​backstage/config-loader@​1.9.2-next.0
@​backstage/errors@​1.2.4
@​backstage/types@​1.1.1
@​backstage/plugin-app-node@​0.1.27-next.2



0.3.77-next.1
Patch Changes

Updated dependencies

@​backstage/backend-plugin-api@​1.0.2-next.1
@​backstage/config@​1.2.0
@​backstage/config-loader@​1.9.2-next.0
@​backstage/errors@​1.2.4
@​backstage/types@​1.1.1
@​backstage/plugin-app-node@​0.1.27-next.1
@​backstage/plugin-auth-node@​0.5.4-next.1



0.3.77-next.0
Patch Changes


... (truncated)


Commits

See full diff in compare view



Updates cross-spawn from 7.0.3 to 7.0.6

Changelog
Sourced from cross-spawn's changelog.

7.0.6 (2024-11-18)
Bug Fixes

update cross-spawn version to 7.0.5 in package-lock.json (f700743)

7.0.5 (2024-11-07)
Bug Fixes

fix escaping bug introduced by backtracking (640d391)

7.0.4 (2024-11-07)
Bug Fixes

disable regexp backtracking (#160) (5ff3a07)




Commits

77cd97f chore(release): 7.0.6
6717de4 chore: upgrade standard-version
f700743 fix: update cross-spawn version to 7.0.5 in package-lock.json
9a7e3b2 chore: fix build status badge
0852683 chore(release): 7.0.5
640d391 fix: fix escaping bug introduced by backtracking
bff0c87 chore: remove codecov
a7c6abc chore: replace travis with github workflows
9b9246e chore(release): 7.0.4
5ff3a07 fix: disable regexp backtracking (#160)
Additional commits viewable in compare view



Updates dset from 3.1.3 to 3.1.4

Commits

05b1ec0 3.1.4
16d6154 fix: prevent proto assignment via implicit string
See full diff in compare view



Updates express from 4.19.2 to 4.21.1

Release notes
Sourced from express's releases.

4.21.1
What's Changed

Backport a fix for CVE-2024-47764 to the 4.x branch by @​joshbuker in expressjs/express#6029
Release: 4.21.1 by @​UlisesGascon in expressjs/express#6031

Full Changelog: expressjs/[email protected]
4.21.0
What's Changed

Deprecate "back" magic string in redirects by @​blakeembrey in expressjs/express#5935
[email protected] by @​wesleytodd in expressjs/express#5954
fix(deps): [email protected] by @​wesleytodd in expressjs/express#5951
Upgraded dependency qs to 6.13.0 to match qs in body-parser by @​agadzinski93 in expressjs/express#5946

New Contributors

@​agadzinski93 made their first contribution in expressjs/express#5946

Full Changelog: expressjs/[email protected]
4.20.0
What's Changed
Important

IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)
Remove link renderization in html while using res.redirect

Other Changes

4.19.2 Staging by @​wesleytodd in expressjs/express#5561
remove duplicate location test for data uri by @​wesleytodd in expressjs/express#5562
feat: document beta releases expectations by @​marco-ippolito in expressjs/express#5565
Cut down on duplicated CI runs by @​jonchurch in expressjs/express#5564
Add a Threat Model by @​UlisesGascon in expressjs/express#5526
Assign captain of encodeurl by @​blakeembrey in expressjs/express#5579
Nominate jonchurch as repo captain for http-errors, expressjs.com, morgan, cors, body-parser by @​jonchurch in expressjs/express#5587
docs: update Security.md by @​inigomarquinez in expressjs/express#5590
docs: update triage nomination policy by @​UlisesGascon in expressjs/express#5600
Add CodeQL (SAST) by @​UlisesGascon in expressjs/express#5433
docs: add UlisesGascon as triage initiative captain by @​UlisesGascon in expressjs/express#5605
deps: encodeurl@~2.0.0 by @​blakeembrey in expressjs/express#5569
skip QUERY method test by @​jonchurch in expressjs/express#5628
ignore ETAG query test on 21 and 22, reuse skip util by @​jonchurch in expressjs/express#5639
add support Node.js@22 in the CI by @​mertcanaltin in expressjs/express#5627
doc: add table of contents, tc/triager lists to readme by @​mertcanaltin in expressjs/express#5619
List and sort all projects, add captains by @​blakeembrey in expressjs/express#5653
docs: add @​UlisesGascon as captain for cookie-parser by @​UlisesGascon in expressjs/express#5666
✨ bring back query tests for node 21 by @​ctcpip in expressjs/express#5690
[v4] Deprecate res.clearCookie accepting options.maxAge and options.expires by @​jonchurch in expressjs/express#5672
skip QUERY tests for Node 21 only, still not supported by @​jonchurch in expressjs/express#5695



... (truncated)


Changelog
Sourced from express's changelog.

4.21.1 / 2024-10-08

Backported a fix for CVE-2024-47764

4.21.0 / 2024-09-11

Deprecate res.location("back") and res.redirect("back") magic string
deps: [email protected]

includes [email protected]


deps: [email protected]
deps: [email protected]

4.20.0 / 2024-09-10

deps: [email protected]

Remove link renderization in html while redirecting


deps: [email protected]

Remove link renderization in html while redirecting


deps: [email protected]

add depth option to customize the depth level in the parser
IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)


Remove link renderization in html while using res.redirect
deps: [email protected]

Adds support for named matching groups in the routes using a regex
Adds backtracking protection to parameters without regexes defined


deps: encodeurl@~2.0.0

Removes encoding of \, |, and ^ to align better with URL spec


Deprecate passing options.maxAge and options.expires to res.clearCookie

Will be ignored in v5, clearCookie will set a cookie with an expires in the past to instruct clients to delete the cookie






Commits

8e229f9 4.21.1
a024c8a fix(deps): [email protected]
7e562c6 4.21.0
1bcde96 fix(deps): [email protected] (#5946)
7d36477 fix(deps): [email protected] (#5951)
40d2d8f fix(deps): [email protected]
77ada90 Deprecate "back" magic string in redirects (#5935)
21df421 4.20.0
4c9ddc1 feat: upgrade to [email protected]
9ebe5d5 feat: upgrade to [email protected] (#5928)
Additional commits viewable in compare view



Updates http-proxy-middleware from 2.0.6 to 2.0.7

Release notes
Sourced from http-proxy-middleware's releases.

v2.0.7
Full Changelog: chimurai/[email protected]
v2.0.7-beta.1
Full Changelog: chimurai/[email protected]
v2.0.7-beta.0
Full Changelog: chimurai/[email protected]



Changelog
Sourced from http-proxy-middleware's changelog.

v2.0.7

ci(github actions): add publish.yml
fix(filter): handle errors




Commits

1e92339 ci(github-actions): fix npm tag
90afb7c chore(package): v2.0.7
0b4274e fix(filter): handle errors
1bd6dd5 ci(github actions): add publish.yml
See full diff in compare view



Updates path-to-regexp from 0.1.7 to 0.1.10

Release notes
Sourced from path-to-regexp's releases.

Backtrack protection
Fixed

Add backtrack protection to parameters  29b96b4

This will break some edge cases but should improve performance



pillarjs/[email protected]
Support non-lookahead regex output
Added

Allow a non-lookahead regex (#312)  c4272e4

component/[email protected]
Support named matching groups in RegExp
Added

Add support for named matching groups (#301)  114f62d

pillarjs/[email protected]



Commits

c827fce 0.1.10
29b96b4 Add backtrack protection to parameters
ac4c234 Update repo url (#314)
bdb6635 0.1.9
c4272e4 Allow a non-lookahead regex (#312)
51a1955 0.1.8
114f62d Add support for named matching groups (#301)
See full diff in compare view



Updates rollup from 4.21.2 to 4.27.3

Release notes
Sourced from rollup's releases.

v4.27.3
4.27.3
2024-11-18
Bug Fixes

Revert object property tree-shaking for now (#5736)

Pull Requests

#5736: Revert object tree-shaking until some issues have been resolved (@​lukastaegert)

v4.27.2
4.27.2
2024-11-15
Bug Fixes

Ensure unused variables in patterns are always deconflicted if rendered (#5728)

Pull Requests

#5728: Fix more variable deconflicting issues (@​lukastaegert)

v4.27.1
4.27.1
2024-11-15
Bug Fixes

Fix some situations where parameter declarations could put Rollup into an infinite loop (#5727)

Pull Requests

#5727: Debug out-of-memory issues with Rollup v4.27.0 (@​lukastaegert)

v4.27.0
4.27.0
2024-11-15
Features

Tree-shake unused properties in object literals (#5420)

Bug Fixes


... (truncated)


Changelog
Sourced from rollup's changelog.

4.27.3
2024-11-18
Bug Fixes

Revert object property tree-shaking for now (#5736)

Pull Requests

#5736: Revert object tree-shaking until some issues have been resolved (@​lukastaegert)

4.27.2
2024-11-15
Bug Fixes

Ensure unused variables in patterns are always deconflicted if rendered (#5728)

Pull Requests

#5728: Fix more variable deconflicting issues (@​lukastaegert)

4.27.1
2024-11-15
Bug Fixes

Fix some situations where parameter declarations could put Rollup into an infinite loop (#5727)

Pull Requests

#5727: Debug out-of-memory issues with Rollup v4.27.0 (@​lukastaegert)

4.27.0
2024-11-15
Features

Tree-shake unused properties in object literals (#5420)

Bug Fixes

Change hash length limit to 21 to avoid inconsistent hash length (#5423)

Pull Requests


... (truncated)


Commits

7c0b1f8 4.27.3
10bc150 Revert  object tree-shaking (#5420) until some issues have been resolved (#5736)
a503a4d 4.27.2
6c68455 Fix more variable deconflicting issues (#5728)
aaf38b7 4.27.1
faeb905 Debug out-of-memory issues with Rollup v4.27.0 (#5727)
c035068 4.27.0
b58e48b fix(deps): update swc monorepo (major) (#5724)
50697b8 Reduce max hash size to 21 (#5723)
a9acb57 feat: implement object tree-shaking (#5420)
Additional commits viewable in compare view



Updates send from 0.18.0 to 0.19.0

Release notes
Sourced from send's releases.

0.19.0
What's Changed

Remove link renderization in html while redirecting (pillarjs/send#235)

New Contributors

@​UlisesGascon made their first contribution in pillarjs/send#235

Full Changelog: pillarjs/[email protected]



Changelog
Sourced from send's changelog.

0.19.0 / 2024-09-10

Remove link renderization in html while redirecting




Commits

9d2db99 0.19.0
ae4f298 Merge commit from fork
See full diff in compare view



Maintainer changes
This version was pushed to npm by ulisesgascon, a new releaser for send since your current version.


Updates serve-static from 1.15.0 to 1.16.2

Release notes
Sourced from serve-static's releases.

1.16.0
What's Changed

Remove link renderization in html while redirecting (expressjs/serve-static#173)

New Contributors

@​UlisesGascon made their first contribution in expressjs/serve-static#173

Full Changelog: expressjs/[email protected]



Changelog
Sourced from serve-static's changelog.

1.16.2 / 2024-09-11

deps: encodeurl@~2.0.0

1.16.1 / 2024-09-11

deps: [email protected]

1.16.0 / 2024-09-10

Remove link renderization in html while redirecting




Commits

ec9c5ec 1.16.2
f454d37 fix(deps): encodeurl@~2.0.0
77a8255 1.16.1
4263f49 fix(deps): [email protected]
48c7397 1.16.0
0c11fad Merge commit from fork
See full diff in compare view



Maintainer changes
This version was pushed to npm by wesleytodd, a new releaser for serve-static since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
@dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
@dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
@dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
@dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
You can disable automated security fix PRs for this repo from the Security Alerts page.

Reviewed-by: Vladimir Vshivkov
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants