Skip to content

Commit 4d97a0f

Browse files
dependency: update dependency express to v4.19.2 [security] (#29211)
* chore(deps): update dependency express to v4.19.2 [security] * empty commit * dependency: add changelog item --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Jennifer Shehane <jennifer@cypress.io>
1 parent 77b43ef commit 4d97a0f

File tree

9 files changed

+169
-13
lines changed

9 files changed

+169
-13
lines changed

cli/CHANGELOG.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,10 @@ _Released 4/2/2024 (PENDING)_
1414
- Fixed a hang where Cypress would run indefinitely while recording to the cloud when CDP disconnects during the middle of a test. Fixes [#29209](https://github.com/cypress-io/cypress/issues/29209).
1515
- Fixed a bug where option values containing quotation marks could not be selected. Fixes [#29213](https://github.com/cypress-io/cypress/issues/29213)
1616

17+
**Dependency Updates:**
18+
19+
- Updated express from `4.17.3` to `4.19.2`. Addressed in [#29211](https://github.com/cypress-io/cypress/pull/29211).
20+
1721
## 13.7.1
1822

1923
_Released 3/21/2024_

npm/puppeteer/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424
"@types/node": "^18.17.5",
2525
"chai-as-promised": "^7.1.1",
2626
"chokidar": "^3.5.3",
27-
"express": "4.17.3",
27+
"express": "4.19.2",
2828
"mocha": "^9.2.2",
2929
"rimraf": "^5.0.1",
3030
"semantic-release": "19.0.3",

packages/driver/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@
5454
"error-stack-parser": "2.0.6",
5555
"errorhandler": "1.5.1",
5656
"eventemitter2": "6.4.7",
57-
"express": "4.17.3",
57+
"express": "4.19.2",
5858
"is-valid-domain": "0.0.20",
5959
"is-valid-hostname": "1.0.1",
6060
"jimp": "0.22.12",

packages/graphql/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@
2222
"@graphql-tools/wrap": "8.1.1",
2323
"@urql/core": "2.4.4",
2424
"dedent": "^0.7.0",
25-
"express": "4.17.3",
25+
"express": "4.19.2",
2626
"express-graphql": "^0.12.0",
2727
"graphql": "^15.5.1",
2828
"graphql-resolve-batch": "1.0.3",

packages/network/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
"@packages/socket": "0.0.0-development",
3434
"@packages/ts": "0.0.0-development",
3535
"@types/concat-stream": "1.6.0",
36-
"express": "4.17.3",
36+
"express": "4.19.2",
3737
"mocha": "6.2.2",
3838
"sinon": "7.3.1",
3939
"sinon-chai": "3.3.0",

packages/proxy/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@
3737
"@types/express": "4.17.2",
3838
"@types/supertest": "2.0.10",
3939
"devtools-protocol": "0.0.927104",
40-
"express": "4.17.3",
40+
"express": "4.19.2",
4141
"supertest": "6.0.1",
4242
"typescript": "^4.7.4"
4343
},

packages/server/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,7 @@
6565
"errorhandler": "1.5.1",
6666
"evil-dns": "0.2.0",
6767
"execa": "1.0.0",
68-
"express": "4.17.3",
68+
"express": "4.19.2",
6969
"fetch-retry-ts": "^1.3.1",
7070
"find-process": "1.4.7",
7171
"firefox-profile": "4.3.2",

system-tests/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@
5858
"dockerode": "3.3.1",
5959
"esbuild": "^0.15.3",
6060
"execa": "4",
61-
"express": "4.17.3",
61+
"express": "4.19.2",
6262
"express-session": "1.16.1",
6363
"express-useragent": "1.0.15",
6464
"fluent-ffmpeg": "2.1.2",

yarn.lock

Lines changed: 158 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -10630,6 +10630,24 @@ body-parser@1.19.2:
1063010630
raw-body "2.4.3"
1063110631
type-is "~1.6.18"
1063210632

10633+
body-parser@1.20.2:
10634+
version "1.20.2"
10635+
resolved "https://registry.yarnpkg.com/body-parser/-/body-parser-1.20.2.tgz#6feb0e21c4724d06de7ff38da36dad4f57a747fd"
10636+
integrity sha512-ml9pReCu3M61kGlqoTm2umSXTlRTuGTx0bfYj+uIUKKYycG5NtSbeetV3faSU6R7ajOPw0g/J1PvK4qNy7s5bA==
10637+
dependencies:
10638+
bytes "3.1.2"
10639+
content-type "~1.0.5"
10640+
debug "2.6.9"
10641+
depd "2.0.0"
10642+
destroy "1.2.0"
10643+
http-errors "2.0.0"
10644+
iconv-lite "0.4.24"
10645+
on-finished "2.4.1"
10646+
qs "6.11.0"
10647+
raw-body "2.5.2"
10648+
type-is "~1.6.18"
10649+
unpipe "1.0.0"
10650+
1063310651
body@^5.1.0:
1063410652
version "5.1.0"
1063510653
resolved "https://registry.yarnpkg.com/body/-/body-5.1.0.tgz#e4ba0ce410a46936323367609ecb4e6553125069"
@@ -12455,6 +12473,11 @@ content-type@1.0.4, content-type@^1.0.4, content-type@~1.0.4:
1245512473
resolved "https://registry.yarnpkg.com/content-type/-/content-type-1.0.4.tgz#e138cc75e040c727b1966fe5e5f8c9aee256fe3b"
1245612474
integrity sha512-hIP3EEPs8tB9AT1L+NUqtwOAps4mk2Zob89MWXMHjHWg9milF/j4osnnQLXBCBFBk/tvIG/tUc9mOUJiPBhPXA==
1245712475

12476+
content-type@~1.0.5:
12477+
version "1.0.5"
12478+
resolved "https://registry.yarnpkg.com/content-type/-/content-type-1.0.5.tgz#8b773162656d1d1086784c8f23a54ce6d73d7918"
12479+
integrity sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81ldF0pAopTvyrFGVbcR6P/VAAd5G7N+0tTr8QqiU0tFadD6FK4NtJwOA==
12480+
1245812481
continuable-cache@^0.3.1:
1245912482
version "0.3.1"
1246012483
resolved "https://registry.yarnpkg.com/continuable-cache/-/continuable-cache-0.3.1.tgz#bd727a7faed77e71ff3985ac93351a912733ad0f"
@@ -12590,6 +12613,11 @@ cookie@0.4.2, cookie@~0.4.1:
1259012613
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.4.2.tgz#0e41f24de5ecf317947c82fc789e06a884824432"
1259112614
integrity sha512-aSWTXFzaKWkvHO1Ny/s+ePFpvKsPnjc551iI41v3ny/ow6tBG5Vd+FuqGNhh1LxOmVzOlGUriIlOaokOvhaStA==
1259212615

12616+
cookie@0.6.0:
12617+
version "0.6.0"
12618+
resolved "https://registry.yarnpkg.com/cookie/-/cookie-0.6.0.tgz#2798b04b071b0ecbff0dbb62a505a8efa4e19051"
12619+
integrity sha512-U71cyTamuh1CRNCfpGY6to28lxvNwPG4Guz/EVjgf3Jmzv0vlDp1atT9eS5dDjMYHucpHbWns6Lwf3BKz6svdw==
12620+
1259312621
cookiejar@^2.1.0, cookiejar@^2.1.2:
1259412622
version "2.1.2"
1259512623
resolved "https://registry.yarnpkg.com/cookiejar/-/cookiejar-2.1.2.tgz#dd8a235530752f988f9a0844f3fc589e3111125c"
@@ -13514,16 +13542,16 @@ delegates@^1.0.0:
1351413542
resolved "https://registry.yarnpkg.com/delegates/-/delegates-1.0.0.tgz#84c6e159b81904fdca59a0ef44cd870d31250f9a"
1351513543
integrity sha1-hMbhWbgZBP3KWaDvRM2HDTElD5o=
1351613544

13545+
depd@2.0.0, depd@~2.0.0:
13546+
version "2.0.0"
13547+
resolved "https://registry.yarnpkg.com/depd/-/depd-2.0.0.tgz#b696163cc757560d09cf22cc8fad1571b79e76df"
13548+
integrity sha512-g7nH6P6dyDioJogAAGprGpCtVImJhpPk/roCzdb3fIh61/s/nPsfR6onyMwkCAR/OlC3yBC0lESvUoQEAssIrw==
13549+
1351713550
depd@^1.1.2, depd@~1.1.2:
1351813551
version "1.1.2"
1351913552
resolved "https://registry.yarnpkg.com/depd/-/depd-1.1.2.tgz#9bcd52e14c097763e749b274c4346ed2e560b5a9"
1352013553
integrity sha1-m81S4UwJd2PnSbJ0xDRu0uVgtak=
1352113554

13522-
depd@~2.0.0:
13523-
version "2.0.0"
13524-
resolved "https://registry.yarnpkg.com/depd/-/depd-2.0.0.tgz#b696163cc757560d09cf22cc8fad1571b79e76df"
13525-
integrity sha512-g7nH6P6dyDioJogAAGprGpCtVImJhpPk/roCzdb3fIh61/s/nPsfR6onyMwkCAR/OlC3yBC0lESvUoQEAssIrw==
13526-
1352713555
dependency-check@2.9.1:
1352813556
version "2.9.1"
1352913557
resolved "https://registry.yarnpkg.com/dependency-check/-/dependency-check-2.9.1.tgz#228bdba768e3bf819a2a68c36f3f6a773c426ebf"
@@ -13585,6 +13613,11 @@ des.js@^1.0.0:
1358513613
inherits "^2.0.1"
1358613614
minimalistic-assert "^1.0.0"
1358713615

13616+
destroy@1.2.0:
13617+
version "1.2.0"
13618+
resolved "https://registry.yarnpkg.com/destroy/-/destroy-1.2.0.tgz#4803735509ad8be552934c67df614f94e66fa015"
13619+
integrity sha512-2sJGJTaXIIaR1w4iJSNoN0hnMY7Gpc/n8D4qSCJw8QqFWXf7cuAgnEHxBpweaVcPevC2l3KpjYCx3NypQQgaJg==
13620+
1358813621
destroy@~1.0.4:
1358913622
version "1.0.4"
1359013623
resolved "https://registry.yarnpkg.com/destroy/-/destroy-1.0.4.tgz#978857442c44749e4206613e37946205826abd80"
@@ -15453,7 +15486,44 @@ express-useragent@1.0.15:
1545315486
resolved "https://registry.yarnpkg.com/express-useragent/-/express-useragent-1.0.15.tgz#cefda5fa4904345d51d3368b117a8dd4124985d9"
1545415487
integrity sha512-eq5xMiYCYwFPoekffMjvEIk+NWdlQY9Y38OsTyl13IvA728vKT+q/CSERYWzcw93HGBJcIqMIsZC5CZGARPVdg==
1545515488

15456-
express@4.17.3, express@^4.17.1, express@^4.17.3:
15489+
express@4.19.2:
15490+
version "4.19.2"
15491+
resolved "https://registry.yarnpkg.com/express/-/express-4.19.2.tgz#e25437827a3aa7f2a827bc8171bbbb664a356465"
15492+
integrity sha512-5T6nhjsT+EOMzuck8JjBHARTHfMht0POzlA60WV2pMD3gyXw2LZnZ+ueGdNxG+0calOJcWKbpFcuzLZ91YWq9Q==
15493+
dependencies:
15494+
accepts "~1.3.8"
15495+
array-flatten "1.1.1"
15496+
body-parser "1.20.2"
15497+
content-disposition "0.5.4"
15498+
content-type "~1.0.4"
15499+
cookie "0.6.0"
15500+
cookie-signature "1.0.6"
15501+
debug "2.6.9"
15502+
depd "2.0.0"
15503+
encodeurl "~1.0.2"
15504+
escape-html "~1.0.3"
15505+
etag "~1.8.1"
15506+
finalhandler "1.2.0"
15507+
fresh "0.5.2"
15508+
http-errors "2.0.0"
15509+
merge-descriptors "1.0.1"
15510+
methods "~1.1.2"
15511+
on-finished "2.4.1"
15512+
parseurl "~1.3.3"
15513+
path-to-regexp "0.1.7"
15514+
proxy-addr "~2.0.7"
15515+
qs "6.11.0"
15516+
range-parser "~1.2.1"
15517+
safe-buffer "5.2.1"
15518+
send "0.18.0"
15519+
serve-static "1.15.0"
15520+
setprototypeof "1.2.0"
15521+
statuses "2.0.1"
15522+
type-is "~1.6.18"
15523+
utils-merge "1.0.1"
15524+
vary "~1.1.2"
15525+
15526+
express@^4.17.1, express@^4.17.3:
1545715527
version "4.17.3"
1545815528
resolved "https://registry.yarnpkg.com/express/-/express-4.17.3.tgz#f6c7302194a4fb54271b73a1fe7a06478c8f85a1"
1545915529
integrity sha512-yuSQpz5I+Ch7gFrPCk4/c+dIBKlQUxtgwqzph132bsT6qhuzss6I8cLJQz7B3rFblzd6wtcI0ZbGltH/C4LjUg==
@@ -15883,6 +15953,19 @@ fill-range@^7.0.1:
1588315953
dependencies:
1588415954
to-regex-range "^5.0.1"
1588515955

15956+
finalhandler@1.2.0:
15957+
version "1.2.0"
15958+
resolved "https://registry.yarnpkg.com/finalhandler/-/finalhandler-1.2.0.tgz#7d23fe5731b207b4640e4fcd00aec1f9207a7b32"
15959+
integrity sha512-5uXcUVftlQMFnWC9qu/svkWv3GTd2PfUhK/3PLkYNAe7FbqJMt3515HaxE6eRL74GdsriiwujiawdaB1BpEISg==
15960+
dependencies:
15961+
debug "2.6.9"
15962+
encodeurl "~1.0.2"
15963+
escape-html "~1.0.3"
15964+
on-finished "2.4.1"
15965+
parseurl "~1.3.3"
15966+
statuses "2.0.1"
15967+
unpipe "~1.0.0"
15968+
1588615969
finalhandler@~1.1.2:
1588715970
version "1.1.2"
1588815971
resolved "https://registry.yarnpkg.com/finalhandler/-/finalhandler-1.1.2.tgz#b7e7d000ffd11938d0fdb053506f6ebabe9f587d"
@@ -17912,6 +17995,17 @@ http-errors@1.8.1:
1791217995
statuses ">= 1.5.0 < 2"
1791317996
toidentifier "1.0.1"
1791417997

17998+
http-errors@2.0.0:
17999+
version "2.0.0"
18000+
resolved "https://registry.yarnpkg.com/http-errors/-/http-errors-2.0.0.tgz#b7774a1486ef73cf7667ac9ae0858c012c57b9d3"
18001+
integrity sha512-FtwrG/euBzaEjYeRqOgly7G0qviiXoJWnvEH2Z1plBdXgbyjv34pHTSb9zoeHMyDy33+DWy5Wt9Wo+TURtOYSQ==
18002+
dependencies:
18003+
depd "2.0.0"
18004+
inherits "2.0.4"
18005+
setprototypeof "1.2.0"
18006+
statuses "2.0.1"
18007+
toidentifier "1.0.1"
18008+
1791518009
http-errors@~1.6.2:
1791618010
version "1.6.3"
1791718011
resolved "https://registry.yarnpkg.com/http-errors/-/http-errors-1.6.3.tgz#8b55680bb4be283a0b5bf4ea2e38580be1d9320d"
@@ -23597,6 +23691,13 @@ omggif@^1.0.10, omggif@^1.0.9:
2359723691
resolved "https://registry.yarnpkg.com/omggif/-/omggif-1.0.10.tgz#ddaaf90d4a42f532e9e7cb3a95ecdd47f17c7b19"
2359823692
integrity sha512-LMJTtvgc/nugXj0Vcrrs68Mn2D1r0zf630VNtqtpI1FEO7e+O9FP4gqs9AcnBaSEeoHIPm28u6qgPR0oyEpGSw==
2359923693

23694+
on-finished@2.4.1:
23695+
version "2.4.1"
23696+
resolved "https://registry.yarnpkg.com/on-finished/-/on-finished-2.4.1.tgz#58c8c44116e54845ad57f14ab10b03533184ac3f"
23697+
integrity sha512-oVlzkg3ENAhCk2zdv7IJwd/QUD4z2RxRwpkcGY8psCVcCYZNq4wYnVWALHM+brtuJjePWiYF/ClmuDr8Ch5+kg==
23698+
dependencies:
23699+
ee-first "1.1.1"
23700+
2360023701
on-finished@^2.3.0, on-finished@~2.3.0:
2360123702
version "2.3.0"
2360223703
resolved "https://registry.yarnpkg.com/on-finished/-/on-finished-2.3.0.tgz#20f1336481b083cd75337992a16971aa2d906947"
@@ -25442,6 +25543,13 @@ qrcode-terminal@^0.12.0:
2544225543
resolved "https://registry.yarnpkg.com/qrcode-terminal/-/qrcode-terminal-0.12.0.tgz#bb5b699ef7f9f0505092a3748be4464fe71b5819"
2544325544
integrity sha512-EXtzRZmC+YGmGlDFbXKxQiMZNwCLEO6BANKXG4iCtSIM0yqc/pappSx3RIKr4r0uh5JsBckOXeKrB3Iz7mdQpQ==
2544425545

25546+
qs@6.11.0:
25547+
version "6.11.0"
25548+
resolved "https://registry.yarnpkg.com/qs/-/qs-6.11.0.tgz#fd0d963446f7a65e1367e01abd85429453f0c37a"
25549+
integrity sha512-MvjoMCJwEarSbUYk5O+nmoSzSutSsTwF85zcHPQ9OrlFoZOYIjaqBAJIqIXjptyD5vThxGq52Xu/MaJzRkIk4Q==
25550+
dependencies:
25551+
side-channel "^1.0.4"
25552+
2544525553
qs@6.7.0:
2544625554
version "6.7.0"
2544725555
resolved "https://registry.yarnpkg.com/qs/-/qs-6.7.0.tgz#41dc1a015e3d581f1621776be31afb2876a9b1bc"
@@ -25619,6 +25727,16 @@ raw-body@2.4.3, raw-body@^2.4.1:
2561925727
iconv-lite "0.4.24"
2562025728
unpipe "1.0.0"
2562125729

25730+
raw-body@2.5.2:
25731+
version "2.5.2"
25732+
resolved "https://registry.yarnpkg.com/raw-body/-/raw-body-2.5.2.tgz#99febd83b90e08975087e8f1f9419a149366b68a"
25733+
integrity sha512-8zGqypfENjCIqGhgXToC8aB2r7YrBX+AQAfIPs/Mlk+BtPTztOvTS01NRW/3Eh60J+a48lt8qsCzirQ6loCVfA==
25734+
dependencies:
25735+
bytes "3.1.2"
25736+
http-errors "2.0.0"
25737+
iconv-lite "0.4.24"
25738+
unpipe "1.0.0"
25739+
2562225740
raw-body@~1.1.0:
2562325741
version "1.1.7"
2562425742
resolved "https://registry.yarnpkg.com/raw-body/-/raw-body-1.1.7.tgz#1d027c2bfa116acc6623bca8f00016572a87d425"
@@ -27199,6 +27317,25 @@ send@0.17.2:
2719927317
range-parser "~1.2.1"
2720027318
statuses "~1.5.0"
2720127319

27320+
send@0.18.0:
27321+
version "0.18.0"
27322+
resolved "https://registry.yarnpkg.com/send/-/send-0.18.0.tgz#670167cc654b05f5aa4a767f9113bb371bc706be"
27323+
integrity sha512-qqWzuOjSFOuqPjFe4NOsMLafToQQwBSOEpS+FwEt3A2V3vKubTquT3vmLTQpFgMXp8AlFWFuP1qKaJZOtPpVXg==
27324+
dependencies:
27325+
debug "2.6.9"
27326+
depd "2.0.0"
27327+
destroy "1.2.0"
27328+
encodeurl "~1.0.2"
27329+
escape-html "~1.0.3"
27330+
etag "~1.8.1"
27331+
fresh "0.5.2"
27332+
http-errors "2.0.0"
27333+
mime "1.6.0"
27334+
ms "2.1.3"
27335+
on-finished "2.4.1"
27336+
range-parser "~1.2.1"
27337+
statuses "2.0.1"
27338+
2720227339
sentence-case@^2.1.0:
2720327340
version "2.1.1"
2720427341
resolved "https://registry.yarnpkg.com/sentence-case/-/sentence-case-2.1.1.tgz#1f6e2dda39c168bf92d13f86d4a918933f667ed4"
@@ -27288,6 +27425,16 @@ serve-static@1.14.2:
2728827425
parseurl "~1.3.3"
2728927426
send "0.17.2"
2729027427

27428+
serve-static@1.15.0:
27429+
version "1.15.0"
27430+
resolved "https://registry.yarnpkg.com/serve-static/-/serve-static-1.15.0.tgz#faaef08cffe0a1a62f60cad0c4e513cff0ac9540"
27431+
integrity sha512-XGuRDNjXUijsUL0vl6nSD7cwURuzEgglbOaFuZM9g3kwDXOWVTck0jLzjPzGD+TazWbboZYu52/9/XPdUgne9g==
27432+
dependencies:
27433+
encodeurl "~1.0.2"
27434+
escape-html "~1.0.3"
27435+
parseurl "~1.3.3"
27436+
send "0.18.0"
27437+
2729127438
serve@14.2.1:
2729227439
version "14.2.1"
2729327440
resolved "https://registry.yarnpkg.com/serve/-/serve-14.2.1.tgz#3f078d292ed5e7b2c5a64f957af2765b0459798b"
@@ -28363,6 +28510,11 @@ static-extend@^0.1.1:
2836328510
define-property "^0.2.5"
2836428511
object-copy "^0.1.0"
2836528512

28513+
statuses@2.0.1:
28514+
version "2.0.1"
28515+
resolved "https://registry.yarnpkg.com/statuses/-/statuses-2.0.1.tgz#55cb000ccf1d48728bd23c685a063998cf1a1b63"
28516+
integrity sha512-RwNA9Z/7PrK06rYLIzFMlaF+l73iwpzsqRIFgbMLbTcLD6cOao82TaWefPXQvB2fOC4AjuYSEndS7N/mTCbkdQ==
28517+
2836628518
"statuses@>= 1.4.0 < 2", "statuses@>= 1.5.0 < 2", statuses@~1.5.0:
2836728519
version "1.5.0"
2836828520
resolved "https://registry.yarnpkg.com/statuses/-/statuses-1.5.0.tgz#161c7dac177659fd9811f43771fa99381478628c"

0 commit comments

Comments
 (0)