Skip to content

breaking: the dependency express has been updated to a new major version (5.2.1), which may include breaking changes. #major#48

Open
public-glueops-renovatebot[bot] wants to merge 2 commits into
mainfrom
renovate/express-5.x
Open

breaking: the dependency express has been updated to a new major version (5.2.1), which may include breaking changes. #major#48
public-glueops-renovatebot[bot] wants to merge 2 commits into
mainfrom
renovate/express-5.x

Conversation

@public-glueops-renovatebot

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
express (source) ^4.21.2^5.0.0 age confidence

Release Notes

expressjs/express (express)

v5.2.1

Compare Source

=======================

  • Revert security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
    • The prior release (5.2.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.

v5.2.0

Compare Source

========================

  • Security fix for CVE-2024-51999 (GHSA-pj86-cfqh-vqx6)
  • deps: body-parser@^2.2.1
  • A deprecation warning was added when using res.redirect with undefined arguments, Express now emits a warning to help detect calls that pass undefined as the status or URL and make them easier to fix.

v5.1.0

Compare Source

========================

  • Add support for Uint8Array in res.send()
  • Add support for ETag option in res.sendFile()
  • Add support for multiple links with the same rel in res.links()
  • Add funding field to package.json
  • perf: use loop for acceptParams
  • refactor: prefix built-in node module imports
  • deps: remove setprototypeof
  • deps: remove safe-buffer
  • deps: remove utils-merge
  • deps: remove methods
  • deps: remove depd
  • deps: debug@^4.4.0
  • deps: body-parser@^2.2.0
  • deps: router@^2.2.0
  • deps: content-type@^1.0.5
  • deps: finalhandler@^2.1.0
  • deps: qs@^6.14.0
  • deps: server-static@2.2.0
  • deps: type-is@2.0.1

v5.0.1

Compare Source

==========

v5.0.0

Compare Source

=========================

  • remove:
    • path-is-absolute dependency - use path.isAbsolute instead
  • breaking:
    • res.status() accepts only integers, and input must be greater than 99 and less than 1000
      • will throw a RangeError: Invalid status code: ${code}. Status code must be greater than 99 and less than 1000. for inputs outside this range
      • will throw a TypeError: Invalid status code: ${code}. Status code must be an integer. for non integer inputs
    • deps: send@​1.0.0
    • res.redirect('back') and res.location('back') is no longer a supported magic string, explicitly use req.get('Referrer') || '/'.
  • change:
    • res.clearCookie will ignore user provided maxAge and expires options
  • deps: cookie-signature@^1.2.1
  • deps: debug@​4.3.6
  • deps: merge-descriptors@^2.0.0
  • deps: serve-static@^2.1.0
  • deps: qs@​6.13.0
  • deps: accepts@^2.0.0
  • deps: mime-types@^3.0.0
    • application/javascript => text/javascript
  • deps: type-is@^2.0.0
  • deps: content-disposition@^1.0.0
  • deps: finalhandler@^2.0.0
  • deps: fresh@^2.0.0
  • deps: body-parser@^2.0.1
  • deps: send@^1.1.0

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

yesterdaysrebel and others added 2 commits June 23, 2026 16:46
* feat: add OTEL backend service and wire extension to in-cluster API

* chore: add missing labeler config for CI

* feat: update otel-extension to version 0.1.1 and patch deployment configurations

* feat: update version to 0.1.1 and enhance backend service validation

* feat: improve service existence check for otel-extension-api in deployment script

* feat: enhance input validation with range checks for PORT and REQUEST_TIMEOUT_MS

* refactor: remove backend ownership from UI repo (transferred to argo-cd-extention-backend)

- Remove backend Deployment/Service/image publishing from argo-cd-ui-extention
- All backend source code removed (Dockerfile, package.json, src/)
- Release workflow now publishes only extension tarball (not Docker image)
- Updated all service references to argocd-extension-backend-api
- Removed EXTENSION_ENABLED toggle from all config layers
- helm-values.yaml, deploy.sh, and verify script updated to use external backend service
- Backend ownership now fully transferred to dedicated argo-cd-extention-backend repo

* feat(phase-2): add context-aware links component to UI extension
…rsion (5.2.1), which may include breaking changes. #major
@public-glueops-renovatebot

Copy link
Copy Markdown
Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant