Skip to content

[Snyk] Security upgrade express from 4.21.1 to 4.22.2#42

Closed
CryptoJones wants to merge 1 commit into
masterfrom
snyk-fix-7a36c8d38e64565c5f22b045c2138b41
Closed

[Snyk] Security upgrade express from 4.21.1 to 4.22.2#42
CryptoJones wants to merge 1 commit into
masterfrom
snyk-fix-7a36c8d38e64565c5f22b045c2138b41

Conversation

@CryptoJones
Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue
medium severity NULL Pointer Dereference
SNYK-JS-QS-16721866

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 NULL Pointer Dereference

CryptoJones added a commit that referenced this pull request May 17, 2026
…major (#48)

`npm audit fix` cleared 10 transitive-dep vulnerabilities
(dottie, moment, moment-timezone, path-to-regexp, qs, underscore,
validator). All within the existing major lines; no breaking
changes expected.

Also bumps the direct deps that had open Snyk PRs against them to
the latest patch in their current major:

  express                4.21.1 → 4.22.2   (Snyk #23, #42)
  pg                     8.6.0  → 8.20.0   (Snyk #9)
  express-promise-router 4.0.1  → 4.1.1    (Snyk #12)
  sequelize              6.6.5  → 6.37.8   (Snyk #18)

`npm audit` post-fix: 0 vulnerabilities.
Test suite: 24 files / 167 tests still passing.

Supersedes Snyk PRs #9, #12, #18, #23, #42. Closes #30 (the
Snyk-backlog-triage tracker). The ancient PRs that target
already-removed deps (#13 body-parser) get closed separately
with a "no longer applicable" comment.

Co-authored-by: Aaron K. Clark <akclark@thenetwerk.net>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@CryptoJones
Copy link
Copy Markdown
Owner Author

Superseded by PR #48 (chore(deps): npm audit fix + bump direct deps to latest patch within major). The target upgrade in this Snyk PR is either already past the version proposed (so this PR would be a downgrade), or rolled into the consolidated upgrade. Closing to clear the backlog.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants