Skip to content

deps: qs@~6.16.0 - #7440

Merged
bjohansebas merged 2 commits into
expressjs:4.xfrom
lazerg:fix/issue-7439-qs-6.16.0
Sep 11, 2026
Merged

bjohansebas merged 2 commits into
expressjs:4.xfrom
lazerg:fix/issue-7439-qs-6.16.0

Conversation

@lazerg

@lazerg lazerg commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

4.x declares qs as ~6.15.1, which caps at 6.15.3. Both CVE-2026-82417 (GHSA-4mjr-xmp4-gh2g, affects >= 2.2.5, <= 6.15.3) and CVE-2026-82562 (GHSA-x5fp-wj9c-mxmx, affects >= 6.14.2, <= 6.15.3) are patched in [email protected], so a fresh npm install [email protected] still lands on a vulnerable qs.

Neither advisory is triggerable through Express itself. Express only calls qs.parse, and the first one needs qs.stringify. The second needs comma: true together with throwOnLimitExceeded: true, which Express never sets. The bump still moves the shipped qs to a version scanners do not flag.

Both advisories are recent enough that they haven't reached the feed npm audit reads, so it still reports 0 vulnerabilities here. The GHSA pages carry the affected ranges.

[email protected] now declares qs: ~6.16.0 and satisfies Express's own ~1.20.5 pin, so a fresh install already gets a clean qs tree without any change here.

Refs #7439

@socket-security

socket-security Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​qs@​6.16.010010010094100

View full report

@krzysdz

krzysdz commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

The first one is reachable through the extended query parser, since parseExtendedQueryString in lib/utils.js passes allowPrototypes: true.

GHSA-4mjr-xmp4-gh2g affects qs.stringify(), so it's not really reachable through Express, which uses only the parser. The reference to allowPrototypes: true is there, because this option is necessary to construct an object that can trigger the DoS (unexpected error) when using qs.parse() -> qs.stringify() round trip.

This covers the direct dependency only. [email protected], which is what ~1.20.5 resolves to, still declares qs: ~6.15.1 of its own, so its nested copy stays on 6.15.3 until that repo bumps too.

expressjs/body-parser#761

@lazerg

lazerg commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

You're right, and I dropped that line from the description. Express only calls qs.parse, so the stringify issue sits outside its path. The arrayLimit bypass needs comma: true with throwOnLimitExceeded: true, which Express never sets either. Grepping the tree, the only qs.stringify callers are superagent and formidable, both test-only.

So this is a bump of the shipped dependency, not a patch for a live hole in 4.x. The description says that now, and points at expressjs/body-parser#761 for the nested copy.

matz3 added a commit to SAP/ui5-cli that referenced this pull request Sep 7, 2026
Consumers who installed @ui5/cli and ran "npm ci" got:

  npm error Missing: [email protected] from lock file

The "overrides" entry forced a single [email protected] across the bundled
express/body-parser tree at pack time. Overrides are producer-only, so
consumers re-resolve without them, expect [email protected], and the lockfile no
longer matches, breaking "npm ci".

The GHSA-x5fp-wj9c-mxmx / GHSA-4mjr-xmp4-gh2g qs vulnerability that the
override addressed is not applicable to the way express / body-parser use
qs, so removing the override does not expose us to it.

Upstream fixes are in progress but not yet consumable: the qs bumps are
still open pull requests, not merged or released, so we cannot rely on the
transitive dependencies alone yet:

  expressjs/express#7440
  expressjs/body-parser#761

Dropping the override lets qs resolve naturally and keeps package.json and
package-lock.json in sync.
@krzysdz

krzysdz commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

[email protected] was released and includes the qs version bump. 1.20.8 is compatible with ~1.20.5 specified in package.json, so updating it is not necessary.

@lazerg

lazerg commented Sep 11, 2026

Copy link
Copy Markdown
Contributor Author

Confirmed: [email protected] ships qs@~6.16.0 and it satisfies our ~1.20.5 pin. I updated the PR body to drop the stale nested-dependency note. No package.json change needed here.

@bjohansebas
bjohansebas merged commit 4138650 into expressjs:4.x Sep 11, 2026
53 checks passed
@UlisesGascon UlisesGascon mentioned this pull request Sep 11, 2026
sickn33 added a commit to sickn33/agentic-awesome-skills that referenced this pull request Oct 6, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)

<h3>Snyk has created this PR to upgrade express from 4.22.2 to 4.22.3.</h3>

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

<hr/>

- The recommended version is **1 version** ahead of your current version.

- The recommended version was released **22 days ago**.

#### Breaking Change Risk

![Merge Risk: Low](https://img.shields.io/badge/Merge%20Risk%3A%20Low-006400?style=for-the-badge)

> **Notice:** This assessment is enhanced by AI.

<details>
<summary><b>Release notes</b></summary>
<br/>
  <details>
    <summary>Package name: <b>express</b></summary>
    <ul>
      <li>
        <b>4.22.3</b> - <a href="https://redirect.github.com/expressjs/express/releases/tag/v4.22.3">2026-09-14</a></br><h2>What's Changed</h2>
<ul>
<li>Update path-to-regexp to 0.1.13 to fix <a title="CVE-2026-4867" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-37ch-88jc-xwx2/hovercard" href="https://redirect.github.com/advisories/GHSA-37ch-88jc-xwx2">CVE-2026-4867</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baryman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/baryman">@ baryman</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4170816498" data-permission-text="Title is private" data-url="expressjs/express#7135" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7135/hovercard" href="https://redirect.github.com/expressjs/express/pull/7135">#7135</a></li>
<li>feat: allow conditional revalidation for QUERY requests (v4) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cherry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/Cherry">@ Cherry</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867995640" data-permission-text="Title is private" data-url="expressjs/express#7377" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7377/hovercard" href="https://redirect.github.com/expressjs/express/pull/7377">#7377</a></li>
<li>deps: qs@~6.16.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lazerg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/lazerg">@ lazerg</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5309974252" data-permission-text="Title is private" data-url="expressjs/express#7440" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7440/hovercard" href="https://redirect.github.com/expressjs/express/pull/7440">#7440</a></li>
<li>ci: add npm staged publication with dist-tag support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UlisesGascon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/UlisesGascon">@ UlisesGascon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5425994556" data-permission-text="Title is private" data-url="expressjs/express#7465" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7465/hovercard" href="https://redirect.github.com/expressjs/express/pull/7465">#7465</a></li>
<li>4.22.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UlisesGascon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/UlisesGascon">@ UlisesGascon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5426105923" data-permission-text="Title is private" data-url="expressjs/express#7466" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7466/hovercard" href="https://redirect.github.com/expressjs/express/pull/7466">#7466</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baryman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/baryman">@ baryman</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4170816498" data-permission-text="Title is private" data-url="expressjs/express#7135" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7135/hovercard" href="https://redirect.github.com/expressjs/express/pull/7135">#7135</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lazerg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/lazerg">@ lazerg</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5309974252" data-permission-text="Title is private" data-url="expressjs/express#7440" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7440/hovercard" href="https://redirect.github.com/expressjs/express/pull/7440">#7440</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://redirect.github.com/expressjs/express/compare/v4.22.2...v4.22.3"><tt>v4.22.2...v4.22.3</tt></a></p>
      </li>
      <li>
        <b>4.22.2</b> - <a href="https://redirect.github.com/expressjs/express/releases/tag/v4.22.2">2026-05-11</a></br><h2>What's Changed</h2>
<ul>
<li>fix: restore &gt;20 array parsing for <code>req.query</code> repeated keys (<a href="https://redirect.github.com/expressjs/express/commit/8d09bfe6d88983da5c3e12cfdd54782c4dc675db"><code>8d09bfe6</code></a>)
<ul>
<li>This also unifies array-cap behavior across notations. Indexed notation (<code>a[0]=...</code>) was historically capped at qs's default <code>arrayLimit</code> of 20 even in older qs versions; after this change it also allows up to 1000 items.</li>
</ul>
</li>
<li>deps: qs@~6.15.1</li>
<li>deps: body-parser@~1.20.5</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suuuuuuminnnnnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/suuuuuuminnnnnn">@ suuuuuuminnnnnn</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3905065919" data-permission-text="Title is private" data-url="expressjs/express#7021" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7021/hovercard" href="https://redirect.github.com/expressjs/express/pull/7021">#7021</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SAY-5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/SAY-5">@ SAY-5</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4266728030" data-permission-text="Title is private" data-url="expressjs/express#7181" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7181/hovercard" href="https://redirect.github.com/expressjs/express/pull/7181">#7181</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://redirect.github.com/expressjs/express/compare/v4.22.1...v4.22.2"><tt>v4.22.1...v4.22.2</tt></a></p>
      </li>
    </ul>
    from <a href="https://redirect.github.com/expressjs/express/releases">express GitHub release notes</a>
  </details>
</details>

---

> [!IMPORTANT]
>
> - Check the changes in this PR to ensure they won't cause issues with your project.
> - This PR was automatically created by Snyk using the credentials of a real user.

---

**Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs._

**For more information:** <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6ImZha2Uta2V5IiwiYW5vbnltb3VzSWQiOiJiNGE2MWUzMC1hOGM1LTQzY2YtOTI2Zi0yMGU4YWUxZWQ5YTUiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImI0YTYxZTMwLWE4YzUtNDNjZi05MjZmLTIwZThhZTFlZDlhNSJ9fQ==" width="0" height="0"/>

> - 🧐 [View latest project report](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/c6cb14ff-6962-4dca-92b2-b0578606cee5?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr)
> - 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates?utm_source=&utm_content=fix-pr-template)
> - 🛠 [Adjust upgrade PR settings](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/c6cb14ff-6962-4dca-92b2-b0578606cee5/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr)
> - 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/c6cb14ff-6962-4dca-92b2-b0578606cee5/settings/integration?pkg&#x3D;express&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades)

[//]: # 'snyk:metadata:{"breakingChangeRiskLevel":"low","FF_showPullRequestBreakingChanges":true,"FF_showPullRequestBreakingChangesWebSearch":false,"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"express","from":"4.22.2","to":"4.22.3"}],"env":"prod","hasFixes":false,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[],"prId":"b4a61e30-a8c5-43cf-926f-20e8ae1ed9a5","prPublicId":"b4a61e30-a8c5-43cf-926f-20e8ae1ed9a5","packageManager":"npm","priorityScoreList":[],"projectPublicId":"c6cb14ff-6962-4dca-92b2-b0578606cee5","projectUrl":"https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/c6cb14ff-6962-4dca-92b2-b0578606cee5?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":[],"type":"auto","upgrade":[],"upgradeInfo":{"versionsDiff":1,"publishedDate":"2026-09-14T06:46:38.631Z"},"vulns":[]}'
sickn33 added a commit to sickn33/agentic-awesome-skills that referenced this pull request Oct 6, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)

<h3>Snyk has created this PR to upgrade express from 4.22.2 to 4.22.3.</h3>

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

<hr/>

- The recommended version is **1 version** ahead of your current version.

- The recommended version was released **22 days ago**.

#### Breaking Change Risk

![Merge Risk: Low](https://img.shields.io/badge/Merge%20Risk%3A%20Low-006400?style=for-the-badge)

> **Notice:** This assessment is enhanced by AI.

<details>
<summary><b>Release notes</b></summary>
<br/>
  <details>
    <summary>Package name: <b>express</b></summary>
    <ul>
      <li>
        <b>4.22.3</b> - <a href="https://redirect.github.com/expressjs/express/releases/tag/v4.22.3">2026-09-14</a></br><h2>What's Changed</h2>
<ul>
<li>Update path-to-regexp to 0.1.13 to fix <a title="CVE-2026-4867" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-37ch-88jc-xwx2/hovercard" href="https://redirect.github.com/advisories/GHSA-37ch-88jc-xwx2">CVE-2026-4867</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baryman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/baryman">@ baryman</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4170816498" data-permission-text="Title is private" data-url="expressjs/express#7135" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7135/hovercard" href="https://redirect.github.com/expressjs/express/pull/7135">#7135</a></li>
<li>feat: allow conditional revalidation for QUERY requests (v4) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cherry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/Cherry">@ Cherry</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867995640" data-permission-text="Title is private" data-url="expressjs/express#7377" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7377/hovercard" href="https://redirect.github.com/expressjs/express/pull/7377">#7377</a></li>
<li>deps: qs@~6.16.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lazerg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/lazerg">@ lazerg</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5309974252" data-permission-text="Title is private" data-url="expressjs/express#7440" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7440/hovercard" href="https://redirect.github.com/expressjs/express/pull/7440">#7440</a></li>
<li>ci: add npm staged publication with dist-tag support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UlisesGascon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/UlisesGascon">@ UlisesGascon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5425994556" data-permission-text="Title is private" data-url="expressjs/express#7465" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7465/hovercard" href="https://redirect.github.com/expressjs/express/pull/7465">#7465</a></li>
<li>4.22.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UlisesGascon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/UlisesGascon">@ UlisesGascon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5426105923" data-permission-text="Title is private" data-url="expressjs/express#7466" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7466/hovercard" href="https://redirect.github.com/expressjs/express/pull/7466">#7466</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baryman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/baryman">@ baryman</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4170816498" data-permission-text="Title is private" data-url="expressjs/express#7135" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7135/hovercard" href="https://redirect.github.com/expressjs/express/pull/7135">#7135</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lazerg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/lazerg">@ lazerg</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5309974252" data-permission-text="Title is private" data-url="expressjs/express#7440" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7440/hovercard" href="https://redirect.github.com/expressjs/express/pull/7440">#7440</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://redirect.github.com/expressjs/express/compare/v4.22.2...v4.22.3"><tt>v4.22.2...v4.22.3</tt></a></p>
      </li>
      <li>
        <b>4.22.2</b> - <a href="https://redirect.github.com/expressjs/express/releases/tag/v4.22.2">2026-05-11</a></br><h2>What's Changed</h2>
<ul>
<li>fix: restore &gt;20 array parsing for <code>req.query</code> repeated keys (<a href="https://redirect.github.com/expressjs/express/commit/8d09bfe6d88983da5c3e12cfdd54782c4dc675db"><code>8d09bfe6</code></a>)
<ul>
<li>This also unifies array-cap behavior across notations. Indexed notation (<code>a[0]=...</code>) was historically capped at qs's default <code>arrayLimit</code> of 20 even in older qs versions; after this change it also allows up to 1000 items.</li>
</ul>
</li>
<li>deps: qs@~6.15.1</li>
<li>deps: body-parser@~1.20.5</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suuuuuuminnnnnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/suuuuuuminnnnnn">@ suuuuuuminnnnnn</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3905065919" data-permission-text="Title is private" data-url="expressjs/express#7021" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7021/hovercard" href="https://redirect.github.com/expressjs/express/pull/7021">#7021</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SAY-5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/SAY-5">@ SAY-5</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4266728030" data-permission-text="Title is private" data-url="expressjs/express#7181" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7181/hovercard" href="https://redirect.github.com/expressjs/express/pull/7181">#7181</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://redirect.github.com/expressjs/express/compare/v4.22.1...v4.22.2"><tt>v4.22.1...v4.22.2</tt></a></p>
      </li>
    </ul>
    from <a href="https://redirect.github.com/expressjs/express/releases">express GitHub release notes</a>
  </details>
</details>

---

> [!IMPORTANT]
>
> - Check the changes in this PR to ensure they won't cause issues with your project.
> - This PR was automatically created by Snyk using the credentials of a real user.

---

**Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs._

**For more information:** <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6ImZha2Uta2V5IiwiYW5vbnltb3VzSWQiOiJhNWNhZDZiYy1kMGU1LTQzNzgtOTI4Mi00YjM2ODcwMDE1NDAiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6ImE1Y2FkNmJjLWQwZTUtNDM3OC05MjgyLTRiMzY4NzAwMTU0MCJ9fQ==" width="0" height="0"/>

> - 🧐 [View latest project report](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/922576f9-727c-4a9f-922d-5954307979b4?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr)
> - 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates?utm_source=&utm_content=fix-pr-template)
> - 🛠 [Adjust upgrade PR settings](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/922576f9-727c-4a9f-922d-5954307979b4/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr)
> - 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/922576f9-727c-4a9f-922d-5954307979b4/settings/integration?pkg&#x3D;express&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades)

[//]: # 'snyk:metadata:{"breakingChangeRiskLevel":"low","FF_showPullRequestBreakingChanges":true,"FF_showPullRequestBreakingChangesWebSearch":false,"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"express","from":"4.22.2","to":"4.22.3"}],"env":"prod","hasFixes":false,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[],"prId":"a5cad6bc-d0e5-4378-9282-4b3687001540","prPublicId":"a5cad6bc-d0e5-4378-9282-4b3687001540","packageManager":"npm","priorityScoreList":[],"projectPublicId":"922576f9-727c-4a9f-922d-5954307979b4","projectUrl":"https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/922576f9-727c-4a9f-922d-5954307979b4?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":[],"type":"auto","upgrade":[],"upgradeInfo":{"versionsDiff":1,"publishedDate":"2026-09-14T06:46:38.631Z"},"vulns":[]}'
sickn33 added a commit to sickn33/agentic-awesome-skills that referenced this pull request Oct 6, 2026
![snyk-top-banner](https://res.cloudinary.com/snyk/image/upload/r-d/scm-platform/snyk-pull-requests/pr-banner-default.svg)

<h3>Snyk has created this PR to upgrade express from 4.22.2 to 4.22.3.</h3>

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

<hr/>

- The recommended version is **1 version** ahead of your current version.

- The recommended version was released **22 days ago**.

#### Breaking Change Risk

![Merge Risk: Low](https://img.shields.io/badge/Merge%20Risk%3A%20Low-006400?style=for-the-badge)

> **Notice:** This assessment is enhanced by AI.

<details>
<summary><b>Release notes</b></summary>
<br/>
  <details>
    <summary>Package name: <b>express</b></summary>
    <ul>
      <li>
        <b>4.22.3</b> - <a href="https://redirect.github.com/expressjs/express/releases/tag/v4.22.3">2026-09-14</a></br><h2>What's Changed</h2>
<ul>
<li>Update path-to-regexp to 0.1.13 to fix <a title="CVE-2026-4867" data-hovercard-type="advisory" data-hovercard-url="/advisories/GHSA-37ch-88jc-xwx2/hovercard" href="https://redirect.github.com/advisories/GHSA-37ch-88jc-xwx2">CVE-2026-4867</a> by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baryman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/baryman">@ baryman</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4170816498" data-permission-text="Title is private" data-url="expressjs/express#7135" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7135/hovercard" href="https://redirect.github.com/expressjs/express/pull/7135">#7135</a></li>
<li>feat: allow conditional revalidation for QUERY requests (v4) by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/Cherry/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/Cherry">@ Cherry</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4867995640" data-permission-text="Title is private" data-url="expressjs/express#7377" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7377/hovercard" href="https://redirect.github.com/expressjs/express/pull/7377">#7377</a></li>
<li>deps: qs@~6.16.0 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lazerg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/lazerg">@ lazerg</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5309974252" data-permission-text="Title is private" data-url="expressjs/express#7440" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7440/hovercard" href="https://redirect.github.com/expressjs/express/pull/7440">#7440</a></li>
<li>ci: add npm staged publication with dist-tag support by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UlisesGascon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/UlisesGascon">@ UlisesGascon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5425994556" data-permission-text="Title is private" data-url="expressjs/express#7465" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7465/hovercard" href="https://redirect.github.com/expressjs/express/pull/7465">#7465</a></li>
<li>4.22.3 by <a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/UlisesGascon/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/UlisesGascon">@ UlisesGascon</a> in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5426105923" data-permission-text="Title is private" data-url="expressjs/express#7466" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7466/hovercard" href="https://redirect.github.com/expressjs/express/pull/7466">#7466</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/baryman/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/baryman">@ baryman</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4170816498" data-permission-text="Title is private" data-url="expressjs/express#7135" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7135/hovercard" href="https://redirect.github.com/expressjs/express/pull/7135">#7135</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/lazerg/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/lazerg">@ lazerg</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="5309974252" data-permission-text="Title is private" data-url="expressjs/express#7440" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7440/hovercard" href="https://redirect.github.com/expressjs/express/pull/7440">#7440</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://redirect.github.com/expressjs/express/compare/v4.22.2...v4.22.3"><tt>v4.22.2...v4.22.3</tt></a></p>
      </li>
      <li>
        <b>4.22.2</b> - <a href="https://redirect.github.com/expressjs/express/releases/tag/v4.22.2">2026-05-11</a></br><h2>What's Changed</h2>
<ul>
<li>fix: restore &gt;20 array parsing for <code>req.query</code> repeated keys (<a href="https://redirect.github.com/expressjs/express/commit/8d09bfe6d88983da5c3e12cfdd54782c4dc675db"><code>8d09bfe6</code></a>)
<ul>
<li>This also unifies array-cap behavior across notations. Indexed notation (<code>a[0]=...</code>) was historically capped at qs's default <code>arrayLimit</code> of 20 even in older qs versions; after this change it also allows up to 1000 items.</li>
</ul>
</li>
<li>deps: qs@~6.15.1</li>
<li>deps: body-parser@~1.20.5</li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/suuuuuuminnnnnn/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/suuuuuuminnnnnn">@ suuuuuuminnnnnn</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="3905065919" data-permission-text="Title is private" data-url="expressjs/express#7021" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7021/hovercard" href="https://redirect.github.com/expressjs/express/pull/7021">#7021</a></li>
<li><a class="user-mention notranslate" data-hovercard-type="user" data-hovercard-url="/users/SAY-5/hovercard" data-octo-click="hovercard-link-click" data-octo-dimensions="link_type:self" href="https://redirect.github.com/SAY-5">@ SAY-5</a> made their first contribution in <a class="issue-link js-issue-link" data-error-text="Failed to load title" data-id="4266728030" data-permission-text="Title is private" data-url="expressjs/express#7181" data-hovercard-type="pull_request" data-hovercard-url="/expressjs/express/pull/7181/hovercard" href="https://redirect.github.com/expressjs/express/pull/7181">#7181</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a class="commit-link" href="https://redirect.github.com/expressjs/express/compare/v4.22.1...v4.22.2"><tt>v4.22.1...v4.22.2</tt></a></p>
      </li>
    </ul>
    from <a href="https://redirect.github.com/expressjs/express/releases">express GitHub release notes</a>
  </details>
</details>

---

> [!IMPORTANT]
>
> - Check the changes in this PR to ensure they won't cause issues with your project.
> - This PR was automatically created by Snyk using the credentials of a real user.

---

**Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs._

**For more information:** <img src="https://api.segment.io/v1/pixel/track?data=eyJ3cml0ZUtleSI6ImZha2Uta2V5IiwiYW5vbnltb3VzSWQiOiIwOGVhODUzYi0yMWZlLTRlNzUtOTBjYi0yZGU2YjE1ZDRjYWMiLCJldmVudCI6IlBSIHZpZXdlZCIsInByb3BlcnRpZXMiOnsicHJJZCI6IjA4ZWE4NTNiLTIxZmUtNGU3NS05MGNiLTJkZTZiMTVkNGNhYyJ9fQ==" width="0" height="0"/>

> - 🧐 [View latest project report](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/03c800b3-c3a6-4848-b6af-6f35a627adab?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr)
> - 📜 [Customise PR templates](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests/customize-pr-templates?utm_source=&utm_content=fix-pr-template)
> - 🛠 [Adjust upgrade PR settings](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/03c800b3-c3a6-4848-b6af-6f35a627adab/settings/integration?utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr)
> - 🔕 [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/03c800b3-c3a6-4848-b6af-6f35a627adab/settings/integration?pkg&#x3D;express&amp;utm_source&#x3D;github&amp;utm_medium&#x3D;referral&amp;page&#x3D;upgrade-pr#auto-dep-upgrades)

[//]: # 'snyk:metadata:{"breakingChangeRiskLevel":"low","FF_showPullRequestBreakingChanges":true,"FF_showPullRequestBreakingChangesWebSearch":false,"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"express","from":"4.22.2","to":"4.22.3"}],"env":"prod","hasFixes":false,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[],"prId":"08ea853b-21fe-4e75-90cb-2de6b15d4cac","prPublicId":"08ea853b-21fe-4e75-90cb-2de6b15d4cac","packageManager":"npm","priorityScoreList":[],"projectPublicId":"03c800b3-c3a6-4848-b6af-6f35a627adab","projectUrl":"https://app.eu.snyk.io/org/antigravity-awesome-skills-default/project/03c800b3-c3a6-4848-b6af-6f35a627adab?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":[],"type":"auto","upgrade":[],"upgradeInfo":{"versionsDiff":1,"publishedDate":"2026-09-14T06:46:38.631Z"},"vulns":[]}'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants