Skip to content

build(deps): bump qs and express in /docs - #332

Merged
glennko merged 2 commits into
mainfrom
dependabot/npm_and_yarn/docs/multi-a07fd7252a
Sep 3, 2026
Merged

build(deps): bump qs and express in /docs#332
glennko merged 2 commits into
mainfrom
dependabot/npm_and_yarn/docs/multi-a07fd7252a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 14, 2026

Copy link
Copy Markdown
Contributor

Bumps qs and express. These dependencies needed to be updated together.
Updates qs from 6.13.0 to 6.14.2

Changelog

Sourced from qs's changelog.

6.14.2

  • [Fix] parse: mark overflow objects for indexed notation exceeding arrayLimit (#546)
  • [Fix] arrayLimit means max count, not max index, in combine/merge/parseArrayValue
  • [Fix] parse: throw on arrayLimit exceeded with indexed notation when throwOnLimitExceeded is true (#529)
  • [Fix] parse: enforce arrayLimit on comma-parsed values
  • [Fix] parse: fix error message to reflect arrayLimit as max index; remove extraneous comments (#545)
  • [Robustness] avoid .push, use void
  • [readme] document that addQueryPrefix does not add ? to empty output (#418)
  • [readme] clarify parseArrays and arrayLimit documentation (#543)
  • [readme] replace runkit CI badge with shields.io check-runs badge
  • [meta] fix changelog typo (arrayLengtharrayLimit)
  • [actions] fix rebase workflow permissions

6.14.1

  • [Fix] ensure arrayLimit applies to [] notation as well
  • [Fix] parse: when a custom decoder returns null for a key, ignore that key
  • [Refactor] parse: extract key segment splitting helper
  • [meta] add threat model
  • [actions] add workflow permissions
  • [Tests] stringify: increase coverage
  • [Dev Deps] update eslint, @ljharb/eslint-config, npmignore, es-value-fixtures, for-each, object-inspect

6.14.0

  • [New] parse: add throwOnParameterLimitExceeded option (#517)
  • [Refactor] parse: use utils.combine more
  • [patch] parse: add explicit throwOnLimitExceeded default
  • [actions] use shared action; re-add finishers
  • [meta] Fix changelog formatting bug
  • [Deps] update side-channel
  • [Dev Deps] update es-value-fixtures, has-bigints, has-proto, has-symbols
  • [Tests] increase coverage

6.13.3

[Fix] fix regressions from robustness refactor [actions] update reusable workflows

6.13.2

  • [Robustness] avoid .push, use void
  • [readme] clarify parseArrays and arrayLimit documentation (#543)
  • [readme] document that addQueryPrefix does not add ? to empty output (#418)
  • [readme] replace runkit CI badge with shields.io check-runs badge
  • [actions] fix rebase workflow permissions

6.13.1

  • [Fix] stringify: avoid a crash when a filter key is null
  • [Fix] utils.merge: functions should not be stringified into keys
  • [Fix] parse: avoid a crash with interpretNumericEntities: true, comma: true, and iso charset
  • [Fix] stringify: ensure a non-string filter does not crash
  • [Refactor] use __proto__ syntax instead of Object.create for null objects
  • [Refactor] misc cleanup

... (truncated)

Commits
  • bdcf0c7 v6.14.2
  • 294db90 [readme] document that addQueryPrefix does not add ? to empty output
  • 5c308e5 [readme] clarify parseArrays and arrayLimit documentation
  • 6addf8c [Fix] parse: mark overflow objects for indexed notation exceeding arrayLimit
  • cfc108f [Fix] arrayLimit means max count, not max index, in combine/merge/`pars...
  • febb644 [Fix] parse: throw on arrayLimit exceeded with indexed notation when `thr...
  • f6a7abf [Fix] parse: enforce arrayLimit on comma-parsed values
  • fbc5206 [Fix] parse: fix error message to reflect arrayLimit as max index; remove e...
  • 1b9a8b4 [actions] fix rebase workflow permissions
  • 2a35775 [meta] fix changelog typo (arrayLengtharrayLimit)
  • Additional commits viewable in compare view

Updates express from 4.21.2 to 4.22.1

Release notes

Sourced from express's releases.

v4.22.1

What's Changed

[!IMPORTANT]
The prior release (4.22.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.

Full Changelog: expressjs/express@4.22.0...v4.22.1

4.22.0

Important: Security

What's Changed

Full Changelog: expressjs/express@4.21.2...4.22.0

Changelog

Sourced from express's changelog.

4.22.1 / 2025-12-01

4.22.0 / 2025-12-01

Commits

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [qs](https://github.com/ljharb/qs) and [express](https://github.com/expressjs/express). These dependencies needed to be updated together.

Updates `qs` from 6.13.0 to 6.14.2
- [Changelog](https://github.com/ljharb/qs/blob/main/CHANGELOG.md)
- [Commits](ljharb/qs@v6.13.0...v6.14.2)

Updates `express` from 4.21.2 to 4.22.1
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.1/History.md)
- [Commits](expressjs/express@4.21.2...v4.22.1)

---
updated-dependencies:
- dependency-name: qs
  dependency-version: 6.14.2
  dependency-type: indirect
- dependency-name: express
  dependency-version: 4.22.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Feb 14, 2026
@glennko

glennko commented Aug 29, 2026

Copy link
Copy Markdown
Member

Superseded by #342 (leaving open until that merges).

Partial fix: this brings qs to 6.14.2, but CVE-2026-8723 requires 6.15.2, and the old 6.13.0 copy stays in the tree alongside. express currently has no open advisories, so that half is not security-driven.

#342 resolves qs to 6.15.3 and express to 4.22.2.

@glennko glennko left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile-only dependency bump; CI green.

@glennko
glennko merged commit f16dce5 into main Sep 3, 2026
4 checks passed
@glennko
glennko deleted the dependabot/npm_and_yarn/docs/multi-a07fd7252a branch September 3, 2026 02:52
glennko added a commit that referenced this pull request Sep 3, 2026
Single `npm audit fix --package-lock-only` pass on the docs site.
package.json is untouched -- no declared range changes, only the
resolved tree.

Regenerated against current main, which now carries the merged
dependabot bumps (#347, #346, #332, #326, #314, #352, #351, #349,
#348). Those bumps did not reach either critical, and dependabot
never proposed a fix for websocket-driver at all.

           before  after
critical        2      0
high           27     18
moderate       14      8
low             5      0
total          48     26

Both criticals cleared:
- shell-quote     1.8.3 -> 1.10.0  (CVE-2026-9277)
- websocket-driver 0.7.4 -> 0.7.5  (CVE-2026-54466)

Also lodash 4.17.23 -> 4.18.1 and node-forge dropped from the tree.

The remaining 26 sit inside the Docusaurus dependency tree --
image-size, serialize-javascript, and the webpack-dev-server ->
sockjs -> uuid chain. Most report no non-breaking fix and would need
a Docusaurus major upgrade. The dev-server chain affects
`docusaurus start`, not `docusaurus build`.

`npm audit fix --force` was deliberately not used -- it would churn
the Docusaurus major version and risk the docs build, for issues that
are dev-time only.
glennko added a commit that referenced this pull request Sep 3, 2026
…342)

Single `npm audit fix --package-lock-only` pass on the docs site.
package.json is untouched -- no declared range changes, only the
resolved tree.

Regenerated against current main, which now carries the merged
dependabot bumps (#347, #346, #332, #326, #314, #352, #351, #349,
#348). Those bumps did not reach either critical, and dependabot
never proposed a fix for websocket-driver at all.

           before  after
critical        2      0
high           27     18
moderate       14      8
low             5      0
total          48     26

Both criticals cleared:
- shell-quote     1.8.3 -> 1.10.0  (CVE-2026-9277)
- websocket-driver 0.7.4 -> 0.7.5  (CVE-2026-54466)

Also lodash 4.17.23 -> 4.18.1 and node-forge dropped from the tree.

The remaining 26 sit inside the Docusaurus dependency tree --
image-size, serialize-javascript, and the webpack-dev-server ->
sockjs -> uuid chain. Most report no non-breaking fix and would need
a Docusaurus major upgrade. The dev-server chain affects
`docusaurus start`, not `docusaurus build`.

`npm audit fix --force` was deliberately not used -- it would churn
the Docusaurus major version and risk the docs build, for issues that
are dev-time only.

Co-authored-by: Glenn Ko <glennko@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant