Skip to content

fix(deps): upgrade express#2002

Merged
Abhijeet Prasad (AbhiPrasad) merged 1 commit into
mainfrom
abhi-fix-upgrade-express-security-deps
May 14, 2026
Merged

fix(deps): upgrade express#2002
Abhijeet Prasad (AbhiPrasad) merged 1 commit into
mainfrom
abhi-fix-upgrade-express-security-deps

Conversation

@AbhiPrasad
Copy link
Copy Markdown
Member

Upgrade the braintrust package to Express 5.2.1 to remove vulnerable transitive production dependencies from Express 4, including path-to-regexp 0.1.x and older qs versions.

resolves https://github.com/braintrustdata/braintrust-sdk-javascript/security/dependabot/422
resolves https://github.com/braintrustdata/braintrust-sdk-javascript/security/dependabot/105
resolves https://github.com/braintrustdata/braintrust-sdk-javascript/security/dependabot/211

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

stamp

Upgrade the braintrust package to Express 5.2.1 to remove vulnerable transitive production dependencies from Express 4, including path-to-regexp 0.1.x and older qs versions.
@AbhiPrasad Abhijeet Prasad (AbhiPrasad) force-pushed the abhi-fix-upgrade-express-security-deps branch from 83d5668 to 2afd6cc Compare May 14, 2026 04:17
@AbhiPrasad Abhijeet Prasad (AbhiPrasad) merged commit 38a6c52 into main May 14, 2026
45 of 47 checks passed
@AbhiPrasad Abhijeet Prasad (AbhiPrasad) deleted the abhi-fix-upgrade-express-security-deps branch May 14, 2026 14:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants