Skip to content

chore(deps): bump lodash and express - #1

Open
matteo-sung wants to merge 96 commits into
mainfrom
bump-deps
Open

chore(deps): bump lodash and express#1
matteo-sung wants to merge 96 commits into
mainfrom
bump-deps

Conversation

@matteo-sung

Copy link
Copy Markdown
Owner

Bumps lodash 4.17.19 → 4.17.21 and express 4.17.1 → 4.18.2. lockvet should explain this diff below.

@github-actions

github-actions Bot commented Jul 24, 2026

Copy link
Copy Markdown

🔍 lockvet report

40 packages changed: 3 major ⚠️, 13 minor, 6 patch, 18 added, 3 direct, 37 transitive

Vulnerabilities: 0 introduced, 3 fixed, 11 unresolved (via OSV.dev)

.github/workflows/lockvet.yml — 1 change
Package From To Level Age
🔼 matteo-sung/lockvet direct v0.5.20 v0.6.4 minor
📝 matteo-sung/lockvet release notes (1 release)

v0.6.4 — lockvet v0.6.4

pdm.lock support — format #61

PDM's lockfile completes lockvet's Python lineup: uv, poetry, pipenv,
requirements.txt, PEP 751 pylock.toml — and now PDM.

Every locked package gets the full PyPI treatment: OSV advisories with
the exact fixed in release, publish ages, registry-verified unlisted
checks, typosquat screening, and via-chains read from the lockfile's own
PEP 508 dependencies arrays:

pdm.lock (PyPI)
…
package-lock.json — 39 changes
Package From To Level Age
🔼 depd via express 1.1.2 2.0.0 MAJOR 7y
🔼 http-errors via express 1.7.2 2.0.0 MAJOR 4y
🔼 statuses via express 1.5.0 2.0.1 MAJOR 5y
🔼 body-parser via express 1.19.0 1.20.1 minor 3y
🟡 ↳ 2 known advisories affect both versions worst: high, GHSA-qwcr-r2fm-qrc7 — all fixed in ≥ 1.20.6
🔼 cookie via express 0.4.0 0.5.0 minor 4y
🟡 ↳ 1 known advisory affects both versions worst: low, GHSA-pxg6-pf52-xh8x — all fixed in ≥ 0.7.0
🔼 destroy via express › body-parser 1.0.4 1.2.0 minor 4y
🔼 express direct 4.17.1 4.18.2 minor 3y
🟡 ↳ 2 known advisories affect both versions worst: moderate, GHSA-rv95-896h-c2vc — all fixed in ≥ 4.20.0
🔼 finalhandler via express 1.1.2 1.2.0 minor 4y
🔼 on-finished via express 2.3.0 2.4.1 minor 4y
🔼 qs via express 6.7.0 6.11.0 minor 4y
↳ fixes GHSA-hrpp-h998-j3pp (high) qs vulnerable to Prototype Pollution
🟡 ↳ 2 known advisories affect both versions worst: moderate, GHSA-6rw7-vpxm-498p — all fixed in ≥ 6.14.2
🔼 raw-body via express › body-parser 2.4.0 2.5.1 minor 4y
🔼 safe-buffer via express 5.1.2 5.2.1 minor 6y
🔼 send via express 0.17.1 0.18.0 minor 4y
🟡 ↳ 1 known advisory affects both versions worst: low, GHSA-m6fv-jmcg-4jfg — all fixed in ≥ 0.19.0
🔼 serve-static via express 1.14.1 1.15.0 minor 4y
🟡 ↳ 1 known advisory affects both versions worst: low, GHSA-cm22-4g7w-348p — all fixed in ≥ 1.16.0
🔼 setprototypeof via express 1.1.1 1.2.0 minor 7y
🔼 bytes via express › body-parser 3.1.0 3.1.2 patch 4y
🔼 content-disposition via express 0.5.3 0.5.4 patch 4y
🔼 inherits via express › http-errors 2.0.3 2.0.4 patch 7y
🔼 lodash direct 4.17.19 4.17.21 patch 5y
↳ fixes GHSA-35jh-r3h4-6jhm (high) Command Injection in lodash
↳ fixes GHSA-29mw-wpgm-hmr9 (moderate) Regular Expression Denial of Service (ReDoS) in lodash
🟡 ↳ 2 known advisories affect both versions worst: high, GHSA-r5fr-rjxr-66jc — all fixed in ≥ 4.18.0
🔼 toidentifier via express › http-errors 1.0.0 1.0.1 patch 4y
🔼 ms via express › debug 2.0.0, 2.1.1 2.0.0, 2.1.3 patch 5y
call-bind-apply-helpers via express › qs › side-channel › side-channel-map › call-bound 1.0.2 added 18mo
call-bound via express › qs › side-channel › side-channel-map 1.0.4 added 17mo
dunder-proto via express › qs › side-channel › side-channel-map › get-intrinsic › get-proto 1.0.1 added 20mo
es-define-property via express › qs › side-channel › side-channel-map › get-intrinsic 1.0.1 added 20mo
es-errors via express › qs › side-channel 1.3.0 added 2y
es-object-atoms via express › qs › side-channel › side-channel-map › get-intrinsic 1.1.2 added 2mo
function-bind via express › qs › side-channel › side-channel-map › get-intrinsic 1.1.2 added 2y
get-intrinsic via express › qs › side-channel › side-channel-map 1.3.0 added 17mo
get-proto via express › qs › side-channel › side-channel-map › get-intrinsic 1.0.1 added 19mo
gopd via express › qs › side-channel › side-channel-map › get-intrinsic 1.2.0 added 20mo
has-symbols via express › qs › side-channel › side-channel-map › get-intrinsic 1.1.0 added 20mo
hasown via express › qs › side-channel › side-channel-map › get-intrinsic 2.0.4 added 2mo
math-intrinsics via express › qs › side-channel › side-channel-map › get-intrinsic 1.1.0 added 19mo
object-inspect via express › qs › side-channel 1.13.4 added 18mo
side-channel via express › qs 1.1.1 added 2mo
side-channel-list via express › qs › side-channel 1.0.1 added 4mo
side-channel-map via express › qs › side-channel 1.0.1 added 20mo
side-channel-weakmap via express › qs › side-channel 1.0.2 added 20mo
📝 depd release notes (1 release)

v2.0.0

  • Drop support for Node.js 0.6
  • Replace internal eval usage with Function constructor
  • Use instance methods on process to check for listeners
📝 http-errors release notes (1 release)

2.0.0 — / 2021-12-17

  • Drop support for Node.js 0.6
  • Remove I'mateapot export; use ImATeapot instead
  • Remove support for status being non-first argument
  • Rename UnorderedCollection constructor to TooEarly
  • deps: depd@2.0.0
    • Replace internal eval usage with Function constructor
    • Use instance methods on process to check for listeners
  • deps: statuses@2.0.1
    • Fix messaging casing of 418 I'm a Teapot
    • Remove code 306
    • Rename 425 Unordered Collection to standard 425 Too Early

📝 statuses release notes (2 releases)

2.0.1 — / 2021-01-03

  • Fix returning values from Object.prototype

2.0.0 — / 2020-04-19

  • Drop support for Node.js 0.6
  • Fix messaging casing of 418 I'm a Teapot
  • Remove code 306
  • Remove status[code] exports; use status.message[code]
  • Remove status[msg] exports; use status.code[msg]
  • Rename 425 Unordered Collection to standard 425 Too Early
  • Rename STATUS_CODES export to message
  • Return status message for statuses(code) when given code
📝 body-parser release notes (4 releases)

1.20.1

  • deps: qs@6.11.0
  • perf: remove unnecessary object clone

1.20.0

  • Fix error message for json parse whitespace in strict
  • Fix internal error when inflated body exceeds limit
  • Prevent loss of async hooks context
  • Prevent hanging when request already read
  • deps: depd@2.0.0
    • Replace internal eval usage with Function constructor
    • Use instance methods on process to check for listeners
  • deps: http-errors@2.0.0
    • deps: depd@2.0.0
    • deps: statuses@2.0.1
  • deps: on-finished@2.4.1
  • deps: qs@6.10.3

1.19.2

  • deps: bytes@3.1.2
  • deps: qs@6.9.7
    • Fix handling of __proto__ keys
  • deps: raw-body@2.4.3
    • deps: bytes@3.1.2

1.19.1

  • deps: bytes@3.1.1
  • deps: http-errors@1.8.1
    • deps: inherits@2.0.4
    • deps: toidentifier@1.0.1
    • deps: setprototypeof@1.2.0
  • deps: qs@6.9.6
  • deps: raw-body@2.4.2
    • deps: bytes@3.1.1
    • deps: http-errors@1.8.1
  • deps: safe-buffer@5.2.1
  • deps: type-is@~1.6.18
📝 cookie release notes (3 releases)

v0.5.0

  • Add priority option
  • Fix expires option to reject invalid dates
  • pref: improve default decode speed
  • pref: remove slow string split in parse

v0.4.2

  • pref: read value only when assigning in parse
  • pref: remove unnecessary regexp in parse

v0.4.1

  • Fix maxAge option to reject invalid values
📝 destroy release notes (3 releases)

1.2.0 — / 2022-03-20

  • Add suppress argument

1.1.1 — / 2022-02-28

  • Work around Zlib close bug in Node.js < 4.5.5

1.1.0 — / 2022-01-25

  • Add Zlib steam support and Node.js leak work around
📝 express release notes (5 releases)

4.18.2

  • Fix regression routing a large stack in a single route
  • deps: body-parser@1.20.1
    • deps: qs@6.11.0
    • perf: remove unnecessary object clone
  • deps: qs@6.11.0

4.18.1

  • Fix hanging on large stack of sync routes

4.18.0

  • Add "root" option to res.download
  • Allow options without filename in res.download
  • Deprecate string and non-integer arguments to res.status
  • Fix behavior of null/undefined as maxAge in res.cookie
  • Fix handling very large stacks of sync middleware
  • Ignore Object.prototype values in settings through app.set/app.get
  • Invoke default with same arguments as types in res.format
  • Support proper 205 responses using res.send
  • Use http-errors for res.format error
  • deps: body-parser@1.20.0
    • Fix error message for json parse whitespace in strict
    • Fix internal error when inflated body exceeds limit

4.17.3

  • deps: accepts@~1.3.8
    • deps: mime-types@~2.1.34
    • deps: negotiator@0.6.3
  • deps: body-parser@1.19.2
    • deps: bytes@3.1.2
    • deps: qs@6.9.7
    • deps: raw-body@2.4.3
  • deps: cookie@0.4.2
  • deps: qs@6.9.7
    • Fix handling of __proto__ keys
  • pref: remove unnecessary regexp for trust proxy

4.17.2

  • Fix handling of undefined in res.jsonp
  • Fix handling of undefined when "json escape" is enabled
  • Fix incorrect middleware execution with unanchored RegExps
  • Fix res.jsonp(obj, status) deprecation message
  • Fix typo in res.is JSDoc
  • deps: body-parser@1.19.1
    • deps: bytes@3.1.1
    • deps: http-errors@1.8.1
    • deps: qs@6.9.6
    • deps: raw-body@2.4.2
    • deps: safe-buffer@5.2.1
    • deps: type-is@~1.6.18
📝 finalhandler release notes (1 release)

v1.2.0

  • Remove set content headers that break response
  • deps: on-finished@2.4.1
  • deps: statuses@2.0.1
    • Rename 425 Unordered Collection to standard 425 Too Early
📝 on-finished release notes (2 releases)

v2.4.1

  • Fix error on early async hooks implementations

v2.4.0

  • Prevent loss of async hooks context
📝 raw-body release notes (5 releases)

2.5.1 — / 2022-02-28

  • Fix error on early async hooks implementations

2.5.0 — / 2022-02-21

  • Prevent loss of async hooks context
  • Prevent hanging when stream is not readable
  • deps: http-errors@2.0.0
    • deps: depd@2.0.0
    • deps: statuses@2.0.1

2.4.3 — / 2022-02-14

  • deps: bytes@3.1.2

2.4.2 — / 2021-11-16

  • deps: bytes@3.1.1
  • deps: http-errors@1.8.1
    • deps: setprototypeof@1.2.0
    • deps: toidentifier@1.0.1

2.4.1 — / 2019-06-25

  • deps: http-errors@1.7.3
    • deps: inherits@2.0.4
📝 send release notes (2 releases)

0.18.0 — / 2022-03-23

  • Fix emitted 416 error missing headers property
  • Limit the headers removed for 304 response
  • deps: depd@2.0.0
    • Replace internal eval usage with Function constructor
    • Use instance methods on process to check for listeners
  • deps: destroy@1.2.0
  • deps: http-errors@2.0.0
    • deps: depd@2.0.0
    • deps: statuses@2.0.1
  • deps: on-finished@2.4.1
  • deps: statuses@2.0.1

0.17.2 — / 2021-12-11

  • pref: ignore empty http tokens
  • deps: http-errors@1.8.1
    • deps: inherits@2.0.4
    • deps: toidentifier@1.0.1
    • deps: setprototypeof@1.2.0
  • deps: ms@2.1.3
📝 serve-static release notes (2 releases)

v1.15.0

  • deps: send@0.18.0
    • Fix emitted 416 error missing headers property
    • Limit the headers removed for 304 response
    • deps: depd@2.0.0
    • deps: destroy@1.2.0
    • deps: http-errors@2.0.0
    • deps: on-finished@2.4.1
    • deps: statuses@2.0.1

v1.14.2

  • deps: send@0.17.2
    • deps: http-errors@1.8.1
    • deps: ms@2.1.3
    • pref: ignore empty http tokens
📝 content-disposition release notes (1 release)

v0.5.4

  • deps: safe-buffer@5.2.1
📝 toidentifier release notes (1 release)

1.0.1 — / 2021-11-14

  • pref: enable strict mode
📝 call-bind-apply-helpers release notes (1 release)

v1.0.2 — https://github.com/ljharb/call-bind-apply-helpers/compare/v1.0.1...v1.0.2) - 2025-02-12

Commits

  • [types] improve inferred types e6f9586
  • [Dev Deps] update @arethetypeswrong/cli, @ljharb/tsconfig, @types/tape, es-value-fixtures, for-each, has-strict-mode, object-inspect e43d540
📝 call-bound release notes (1 release)

v1.0.4 — https://github.com/ljharb/call-bound/compare/v1.0.3...v1.0.4) - 2025-03-03

Commits

  • [types] improve types e648922
  • [Dev Deps] update @arethetypeswrong/cli, @ljharb/tsconfig, @types/tape, es-value-fixtures, for-each, has-strict-mode, object-inspect a42a5eb
  • [Deps] update call-bind-apply-helpers, get-intrinsic f529eac
📝 dunder-proto release notes (1 release)

v1.0.1 — https://github.com/es-shims/dunder-proto/compare/v1.0.0...v1.0.1) - 2024-12-16

Commits

  • [Fix] do not crash when --disable-proto=throw 6c367d9
  • [Tests] ensure noproto tests only use the current version of dunder-proto b02365b
  • [Dev Deps] update @arethetypeswrong/cli, @types/tape e3c5c3b
  • [Deps] update call-bind-apply-helpers 19f1da0
📝 es-define-property release notes (1 release)

v1.0.1 — https://github.com/ljharb/es-define-property/compare/v1.0.0...v1.0.1) - 2024-12-06

Commits

  • [types] use shared tsconfig 954a663
  • [actions] split out node 10-20, and 20+ 3a8e84b
  • [Dev Deps] update @ljharb/eslint-config, @ljharb/tsconfig, @types/get-intrinsic, @types/tape, auto-changelog, gopd, tape 86ae27b
  • [Refactor] avoid using get-intrinsic 02480c0
  • [Tests] replace aud with npm audit f6093ff
📝 es-errors release notes (1 release)

v1.3.0 — https://github.com/ljharb/es-errors/compare/v1.2.1...v1.3.0) - 2024-02-05

Commits

  • [New] add EvalError and URIError 1927627

release notes for 13 more packages omitted to keep this comment small — run lockvet locally for the rest

generated by lockvet

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Comment thread package-lock.json
"express": "4.17.1",
"lodash": "4.17.19"
"express": "4.18.2",
"lodash": "4.17.21"
Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.19.0.tgz",
"integrity": "sha512-dhEPs72UPbDnAQJ9ZKMNTP6ptJaionhP5cBb541nXPlW60Jepo9RV/a4fX4XWW9CuFNK22krhrj1+rgzifNCsw==",
"version": "1.20.1",
"resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.20.1.tgz",
Comment thread package-lock.json
"dependencies": {
"express": "4.17.1",
"lodash": "4.17.19"
"express": "4.18.2",
Comment thread package-lock.json Fixed
Comment thread package-lock.json
"raw-body": "2.4.0",
"type-is": "~1.6.17"
"on-finished": "2.4.1",
"qs": "6.11.0",
Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.19.0.tgz",
"integrity": "sha512-dhEPs72UPbDnAQJ9ZKMNTP6ptJaionhP5cBb541nXPlW60Jepo9RV/a4fX4XWW9CuFNK22krhrj1+rgzifNCsw==",
"version": "1.20.1",
"resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.20.1.tgz",
Comment thread package-lock.json
"raw-body": "2.4.0",
"type-is": "~1.6.17"
"on-finished": "2.4.1",
"qs": "6.11.0",
Comment thread package-lock.json
"resolved": "https://registry.npmjs.org/cookie/-/cookie-0.4.0.tgz",
"integrity": "sha512-+Hp8fLp57wnUSt0tY0tHEXh4voZRDnoIrZPqlo3DPiI4y9lwg/jqx+1Om94/W6ZaPDOUbnjOt/99w66zk+l1Xg==",
"version": "0.5.0",
"resolved": "https://registry.npmjs.org/cookie/-/cookie-0.5.0.tgz",
Comment thread package-lock.json
"setprototypeof": "1.1.1",
"statuses": "~1.5.0",
"safe-buffer": "5.2.1",
"send": "0.18.0",
Comment thread package-lock.json
"statuses": "~1.5.0",
"safe-buffer": "5.2.1",
"send": "0.18.0",
"serve-static": "1.15.0",
Comment thread package-lock.json
"express": "4.17.1",
"lodash": "4.17.19"
"express": "4.18.2",
"lodash": "4.17.21"
@github-actions github-actions Bot mentioned this pull request Jul 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants