← All tasks
javascriptexpressjs/body-parser #644Not a task: already works

Release Proposal 2.2.1

envgap__expressjs__body-parser-644

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
b204886a6744b0b6d297cd0e849d75de836f3b63
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

expressjs/body-parser #644 · read the original issue
### What changed
- **refactor:** move common request validation to `read` function  
- **deps:**  
  - `type-is@^2.0.1`  
  - `iconv-lite@^0.7.0`  
  - `raw-body@^3.0.1`  
  - `debug@^4.4.3`
----------------------------------------
~~Additionally, I’d like to include #642 to update debug to `^4.4.3` to force users to update from the compromised `4.4.2` version.~~ Edit: #642 already merged

The critical change here is the [`iconv-lite` update to 0.7.0](https://github.com/pillarjs/iconv-lite/releases/tag/v0.7.0), which addresses important issues.  

A new release is needed to deduplicate `iconv-lite` in our dependency tree ([see npmgraph](https://npmgraph.js.org/?q=body-parser)). Currently, two versions of `iconv-lite` are being pulled in. Since `iconv-lite` is pre-1.0.0, semver treats `^0.6.3` like `~0.6.3` (it matches only `0.6.x`), so it won’t float to `0.7.0`. Releasing with `iconv-lite@^0.7.0` lets npm dedupe our tree to a single `0.7.x`.  
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]