Release Proposal 2.2.1
envgap__expressjs__body-parser-644
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
b204886a6744b0b6d297cd0e849d75de836f3b63- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
expressjs/body-parser #644 · read the original issue
### What changed - **refactor:** move common request validation to `read` function - **deps:** - `type-is@^2.0.1` - `iconv-lite@^0.7.0` - `raw-body@^3.0.1` - `debug@^4.4.3` ---------------------------------------- ~~Additionally, I’d like to include #642 to update debug to `^4.4.3` to force users to update from the compromised `4.4.2` version.~~ Edit: #642 already merged The critical change here is the [`iconv-lite` update to 0.7.0](https://github.com/pillarjs/iconv-lite/releases/tag/v0.7.0), which addresses important issues. A new release is needed to deduplicate `iconv-lite` in our dependency tree ([see npmgraph](https://npmgraph.js.org/?q=body-parser)). Currently, two versions of `iconv-lite` are being pulled in. Since `iconv-lite` is pre-1.0.0, semver treats `^0.6.3` like `~0.6.3` (it matches only `0.6.x`), so it won’t float to `0.7.0`. Releasing with `iconv-lite@^0.7.0` lets npm dedupe our tree to a single `0.7.x`.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]