Repository navigation
11.41.2
Security maintenance: fixes for multer and nodemailer. Projects that accept file uploads need one override, because multer's fix does not reach your tree through this package alone.
Update
pnpm update @lenne.tech/nest-serverDo I need to do anything?
Yes, if pnpm why multer shows a version below 2.3.0. @nestjs/platform-express exact-pins multer 2.2.0, and FileInterceptor uploads go through that copy, which has three high advisories (DoS via crafted multipart input) and one low one (file size limit bypass). pnpm overrides do not travel with a package, so add this to your project's pnpm-workspace.yaml and run pnpm install:
overrides:
'multer@>=2.0.0 <2.3.0': '2.3.0'If you declare multer directly, raise it to 2.3.0 too. Projects created from nest-server-starter after 2026-09-15 already have both.
nodemailer: nothing to do. 9.1.1 (one high, three moderate advisories) arrives with this package.
Details: migration-guides/11.41.1-to-11.41.2.md
Under the hood
The rest does not reach consumers:
oxlint --fix-suggestionsis gone from this repository'slint:fix, pre-commit hook andscripts/check.mjs. Itsno-consolesuggestion deletedconsole.logcalls on commit.- The
honoandjs-yaml4.x overrides were raised (both inert). .gitattributespins LF line endings for Windows checkouts.- A non-blocking Windows CI job runs install, build and unit tests.