Skip to content

chore(deps): bump body-parser from 1.20.3 to 1.20.6 in /functions - #674

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/functions/body-parser-1.20.6
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/functions/body-parser-1.20.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps body-parser from 1.20.3 to 1.20.6.

Release notes

Sourced from body-parser's releases.

1.20.6

Important: Security

What's Changed

Full Changelog: expressjs/body-parser@1.20.5...1.20.6

v1.20.5

What's Changed

The reason for this release is a fix to the extended urlencoded parser returning objects instead of arrays for large array inputs (> 100) on qs@6.14.2+. (expressjs/body-parser#716)

New Contributors

Special thanks to triager @​krzysdz for keeping this on our radar and effectively triaging the specific issue!

Full Changelog: expressjs/body-parser@1.20.4...1.20.5

1.20.4

What's Changed

Full Changelog: expressjs/body-parser@1.20.3...1.20.4

Changelog

Sourced from body-parser's changelog.

1.20.6 / 2026-07-09

  • Security fix for GHSA-v422-hmwv-36x6
  • fix: improve limit option validation (#698)
    • Invalid limit values (e.g. unparseable strings or NaN) now throw instead of being silently ignored, which previously disabled size limit enforcement
    • null and undefined fall back to the default 100kb limit

1.20.5 / 2026-04-24

  • refactor(json): simplify strict mode error string construction
  • fix: extended urlencoded parsing of arrays with >100 elements (#716)
  • deps: qs@~6.15.1

1.20.4 / 2025-12-01

  • deps: qs@~6.14.0
  • deps: use tilde notation for dependencies
  • deps: http-errors@~2.0.1
  • deps: raw-body@~2.5.3
Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [body-parser](https://github.com/expressjs/body-parser) from 1.20.3 to 1.20.6.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@1.20.3...1.20.6)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 1.20.6
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Jul 28, 2026
@github-actions

Copy link
Copy Markdown

Hello 👋, this PR has been without activity for more than 28 days.

If you think this is a mistake please comment and ping a maintainer to get this merged ASAP! Thanks for contributing!

You have 15 days until this gets closed automatically.

@github-actions github-actions Bot added the Stale Issue with no recent activity label Aug 30, 2026
russellwheatley added a commit that referenced this pull request Sep 22, 2026
- actions/checkout, actions/setup-node, etc: bump the github-actions group across 1 directory with 7 updates (#684)
- cloud_firestore 6.9.0 -> 6.10.0, firebase_auth 6.6.1 -> 6.7.0, firebase_core 4.14.0 -> 4.15.0 (#704, #701, #702; bumped together since the native Firebase iOS SDK versions have to match across cloud_firestore/firebase_auth/firebase_core or CocoaPods can't resolve FirebaseFirestore)
- file_picker 6.2.1 -> 13.1.0 in firebase_ui_storage example (#703; unused dependency, firebase_ui_storage actually uses file_selector)
- js-yaml, browserslist, brace-expansion, body-parser: transitive lockfile bumps in /functions (#691, #686, #680, #674)

Also:
- use caret constraints instead of dependabot's exact pins for cloud_firestore/firebase_auth/firebase_core in the library pubspecs, matching the convention used elsewhere in the workspace and clearing the pub_dry_run 'dependency should allow more than one version' warning
- bump the tests/ios and tests/macos Podfile's pinned FirebaseFirestore tag (invertase/firestore-ios-sdk-frameworks) from 12.18.0 to 12.19.0 to match what cloud_firestore 6.10.0 now depends on
russellwheatley added a commit that referenced this pull request Sep 22, 2026
- actions/checkout, actions/setup-node, etc: bump the github-actions group across 1 directory with 7 updates (#684)
- cloud_firestore 6.9.0 -> 6.10.0, firebase_auth 6.6.1 -> 6.7.0, firebase_core 4.14.0 -> 4.15.0 (#704, #701, #702; bumped together since the native Firebase iOS SDK versions have to match across cloud_firestore/firebase_auth/firebase_core or CocoaPods can't resolve FirebaseFirestore)
- js-yaml, browserslist, brace-expansion, body-parser: transitive lockfile bumps in /functions (#691, #686, #680, #674)

Also:
- remove file_picker from firebase_ui_storage example instead of bumping it (#703); it's unused there, firebase_ui_storage actually uses file_selector
- use caret constraints instead of dependabot's exact pins for cloud_firestore/firebase_auth/firebase_core in the library pubspecs, matching the convention used elsewhere in the workspace and clearing the pub_dry_run 'dependency should allow more than one version' warning
- bump the tests/ios and tests/macos Podfile's pinned FirebaseFirestore tag (invertase/firestore-ios-sdk-frameworks) from 12.18.0 to 12.19.0 to match what cloud_firestore 6.10.0 now depends on
@russellwheatley

Copy link
Copy Markdown
Member

Superseded by #705.

@dependabot @github

dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/functions/body-parser-1.20.6 branch September 22, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code Stale Issue with no recent activity

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant