Skip to content

chore(deps): update dependency express to v5.2.0#11

Open
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/express-5.x-lockfile
Open

chore(deps): update dependency express to v5.2.0#11
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/express-5.x-lockfile

Conversation

@mend-for-github-com
Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
express (source) dependencies minor 5.1.05.2.0

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability Reachability
Low Low 3.7 CVE-2025-15284
Low Low 3.7 CVE-2026-2391

Release Notes

expressjs/express (express)

v5.2.0

Compare Source

========================

  • Security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
  • deps: body-parser@^2.2.1
  • A deprecation warning was added when using res.redirect with undefined arguments, Express now emits a warning to help detect calls that pass undefined as the status or URL and make them easier to fix.

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Feb 26, 2026
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/express-5.x-lockfile branch from 75b72a0 to 8c4b068 Compare April 9, 2026 01:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants