Skip to content

fix(deps): update dependency body-parser to v2#218

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/body-parser-2.x
Open

fix(deps): update dependency body-parser to v2#218
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/body-parser-2.x

Conversation

@renovate

@renovate renovate Bot commented Mar 27, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
body-parser ^1.20.3^2.0.0 age confidence

Release Notes

expressjs/body-parser (body-parser)

v2.3.0

Compare Source

========================

  • fix: use static exports instead of lazy getters to improve ESM compatibility
  • feat: add subpath exports for individual parsers
  • fix: improve limit option validation (#​698)
    • Invalid limit values (e.g. unparseable strings or NaN) now throw instead of being silently ignored, which previously disabled size limit enforcement
    • null and undefined fall back to the default 100kb limit
  • deps:
    • content-type@^2.0.0
    • http-errors@^2.0.1
    • iconv-lite^0.7.2
    • qs@^6.15.2
    • raw-body@^3.0.2
    • type-is@^2.1.0

v2.2.2

Compare Source

=========================

  • deps: qs@^6.14.1
  • refactor(json): simplify strict mode error string construction

v2.2.1

Compare Source

=========================

  • Security fix for GHSA-wqch-xfxh-vrr4
  • deps:
    • type-is@^2.0.1
    • iconv-lite@^0.7.0
      • Handle split surrogate pairs when encoding UTF-8
      • Avoid false positives in encodingExists by using prototype-less objects
    • raw-body@^3.0.1
    • debug@^4.4.3

v2.2.0

Compare Source

=========================

  • refactor: normalize common options for all parsers
  • deps:
    • iconv-lite@^0.6.3

v2.1.0

Compare Source

=========================

  • deps:
    • type-is@^2.0.0
    • debug@^4.4.0
    • Removed destroy
  • refactor: prefix built-in node module imports
  • use the node require cache instead of custom caching

v2.0.2

Compare Source

=========================

  • remove unpipe package and use native unpipe() method

v2.0.1

Compare Source

=========================

  • Restore expected behavior extended to false

v2.0.0

Compare Source

=========================

Breaking Changes

  • Node.js 18 is the minimum supported version
  • req.body is no longer always initialized to {}
    • it is left undefined unless a body is parsed
  • Remove deprecated bodyParser() combination middleware
  • urlencoded parser now defaults extended to false as released, this is not the case, fixed in 2.0.1
  • urlencoded simple parser now uses qs module instead of querystring module

Features

  • Add brotli support #​406
  • urlencoded: Add option to customize the depth with a default value of 32
  • urlencoded: Support iso-8859-1, utf8 sentinel, and numeric entities
  • Use on-finished to determine when body read

Dependencies

  • deps: raw-body@^3.0.0
  • deps: qs@​6.12.3
  • deps: debug@​3.1.0
  • deps: iconv-lite@​0.5.2

v1.20.6

Compare Source

What's Changed

Full Changelog: expressjs/body-parser@1.20.5...1.20.6

v1.20.5

Compare Source

What's Changed

The reason for this release is a fix to the extended urlencoded parser returning objects instead of arrays for large array inputs (> 100) on qs@​6.14.2+. (#​716)

New Contributors

Special thanks to triager @​krzysdz for keeping this on our radar and effectively triaging the specific issue!

Full Changelog: expressjs/body-parser@1.20.4...1.20.5

v1.20.4

Compare Source

===================

  • deps: qs@~6.14.0
  • deps: use tilde notation for dependencies
  • deps: http-errors@~2.0.1
  • deps: raw-body@~2.5.3

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch from d90102a to 7ae1572 Compare May 24, 2025 16:24
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch from 7ae1572 to 50c986d Compare September 25, 2025 14:02
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch from 50c986d to 4e23d69 Compare November 24, 2025 21:05
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch 2 times, most recently from 9fee237 to 23f5342 Compare January 7, 2026 10:33
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch from 23f5342 to 5000af7 Compare January 8, 2026 18:59
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch 2 times, most recently from 8183085 to 61a0d47 Compare February 17, 2026 17:36
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch from 61a0d47 to 3e47d77 Compare April 8, 2026 19:52
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch from 3e47d77 to 64bd704 Compare May 18, 2026 19:54
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch from 64bd704 to 49685c9 Compare June 16, 2026 00:49
@renovate
renovate Bot force-pushed the renovate/body-parser-2.x branch from 49685c9 to f1d046e Compare July 12, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants