Skip to content

Update dependency body-parser to v1.20.3#8

Open
mend-for-github-com[bot] wants to merge 1 commit intoalphafrom
whitesource-remediate/body-parser-1.x-lockfile
Open

Update dependency body-parser to v1.20.3#8
mend-for-github-com[bot] wants to merge 1 commit intoalphafrom
whitesource-remediate/body-parser-1.x-lockfile

Conversation

@mend-for-github-com
Copy link
Copy Markdown

@mend-for-github-com mend-for-github-com bot commented Oct 28, 2025

This PR contains the following updates:

Package Type Update Change
body-parser dependencies minor 1.19.01.20.3

By merging this PR, the issue #75 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
High High 7.5 CVE-2024-45590

Unreachable


Release Notes

expressjs/body-parser (body-parser)

v1.20.3

Compare Source

===================

  • deps: qs@​6.13.0
  • add depth option to customize the depth level in the parser
  • IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)

v1.20.2

Compare Source

===================

  • Fix strict json error message on Node.js 19+
  • deps: content-type@~1.0.5
    • perf: skip value escaping when unnecessary
  • deps: raw-body@​2.5.2

v1.20.1

Compare Source

===================

  • deps: qs@​6.11.0
  • perf: remove unnecessary object clone

v1.20.0

Compare Source

===================

  • Fix error message for json parse whitespace in strict
  • Fix internal error when inflated body exceeds limit
  • Prevent loss of async hooks context
  • Prevent hanging when request already read
  • deps: depd@​2.0.0
    • Replace internal eval usage with Function constructor
    • Use instance methods on process to check for listeners
  • deps: http-errors@​2.0.0
    • deps: depd@​2.0.0
    • deps: statuses@​2.0.1
  • deps: on-finished@​2.4.1
  • deps: qs@​6.10.3
  • deps: raw-body@​2.5.1
    • deps: http-errors@​2.0.0

v1.19.2

Compare Source

===================

  • deps: bytes@​3.1.2
  • deps: qs@​6.9.7
    • Fix handling of __proto__ keys
  • deps: raw-body@​2.4.3
    • deps: bytes@​3.1.2

v1.19.1

Compare Source

===================

  • deps: bytes@​3.1.1
  • deps: http-errors@​1.8.1
    • deps: inherits@​2.0.4
    • deps: toidentifier@​1.0.1
    • deps: setprototypeof@​1.2.0
  • deps: qs@​6.9.6
  • deps: raw-body@​2.4.2
    • deps: bytes@​3.1.1
    • deps: http-errors@​1.8.1
  • deps: safe-buffer@​5.2.1
  • deps: type-is@~1.6.18

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Oct 28, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch 7 times, most recently from dbda2a2 to d129477 Compare November 4, 2025 10:30
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from d129477 to 1799478 Compare November 4, 2025 13:02
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.20.3 Update dependency body-parser to v1.20.3 - autoclosed Nov 26, 2025
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/body-parser-1.x-lockfile branch November 26, 2025 00:30
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.20.3 - autoclosed Update dependency body-parser to v1.20.3 Nov 26, 2025
@mend-for-github-com mend-for-github-com bot reopened this Nov 26, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch 3 times, most recently from 2dfbe75 to ce8aa1c Compare December 2, 2025 05:17
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch 2 times, most recently from ebf8a52 to c7be15a Compare December 30, 2025 11:19
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from c7be15a to 6ca38e0 Compare February 12, 2026 09:40
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from 6ca38e0 to 20e6925 Compare March 28, 2026 03:00
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from 20e6925 to 733fa61 Compare April 9, 2026 00:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants