Skip to content

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented Jan 9, 2025

This PR contains the following updates:

Package Type Update Change
body-parser dependencies patch 1.20.2 -> 1.20.3

By merging this PR, the issue #4 will be automatically resolved and closed:

Severity CVSS Score Vulnerability
High High 7.5 CVE-2024-45590

Release Notes

expressjs/body-parser (body-parser)

v1.20.3

Compare Source

===================

  • deps: qs@6.13.0
  • add depth option to customize the depth level in the parser
  • IMPORTANT: The default depth level for parsing URL-encoded data is now 32 (previously was Infinity)

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Jan 9, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch 2 times, most recently from 30f03c7 to 798fa25 Compare January 16, 2025 06:58
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch 2 times, most recently from e0de4e2 to 9c9690c Compare February 13, 2025 07:43
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from 9c9690c to b45daad Compare February 23, 2025 08:03
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from b45daad to cbfaf82 Compare March 4, 2025 07:21
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.20.3 Update dependency body-parser to v1.20.3 - autoclosed Mar 24, 2025
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/body-parser-1.x-lockfile branch March 24, 2025 18:55
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.20.3 - autoclosed Update dependency body-parser to v1.20.3 Mar 30, 2025
@mend-for-github-com mend-for-github-com bot reopened this Mar 30, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/body-parser-1.x-lockfile branch from 95b6ad0 to cbfaf82 Compare March 30, 2025 10:13
@mend-for-github-com mend-for-github-com bot changed the title Update dependency body-parser to v1.20.3 Update dependency body-parser to v1.20.3 - autoclosed Jul 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant