chore(deps): update dependency multer to v2.4.0 #8

Closed
EgorEast wants to merge 2 commits from renovate/multer-2.x-lockfile into main
Owner

This PR contains the following updates:

Package Change Age Confidence
multer 2.3.0 → 2.4.0 age confidence

Release Notes

expressjs/multer (multer)

v2.4.0

Compare Source

  • Fix CVE-2026-88932 (GHSA-3pph-fpjx-jg34)
  • Add filename to LIMIT_FILE_SIZE and LIMIT_UNEXPECTED_FILE errors (#​1416)
  • Accept a function for limits, called with the request, to set limits per request (#​1133)
  • Add opt-in flush option to DiskStorage to fsync files before the callback runs (#​1458)
  • Expose busboy's defCharset, highWaterMark and fileHwm options (#​1465)
  • Add streamHandler option to feed busboy from pre-consumed bodies (Google Cloud Functions, Firebase) (#​1466)
  • Allow multer.diskStorage() to be called without options (#​1471)
  • Decode WHATWG-escaped characters (%0A, %0D, %22) in field names, matching file.originalname since 2.3.0: req.body keys, file.fieldname and err.field now carry the real name. If you matched the escaped spelling as a workaround, use the real name now (#​1473)
  • Report the decoded filename in err.filename on LIMIT_FILE_SIZE errors, matching file.originalname (#​1478)
  • Reject non-integer or negative limits values at construction time; a float limit silently disabled the check (#​1395, #​1335)
  • Accept requests with exactly limits.parts parts; LIMIT_PART_COUNT now fires only when the limit is exceeded. If you set parts one higher to work around this, you can drop the extra one (#​1446)
  • Files skipped by fileFilter no longer count towards maxCount (#​1426)
  • Change the LIMIT_UNEXPECTED_FILE message to "Unexpected file field" (#​426)
  • Remove the concat-stream dependency (#​1356)
  • Docs: add JSDoc to the public API and document the storage engine stream contract (#​1467, #​1468)
  • Docs: add FormData upload examples (#​896)
  • Docs: remove the translated READMEs (#​1463)
  • Internal: run the test suite on macOS (#​1464)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 8am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [multer](https://github.com/expressjs/multer) | [`2.3.0` → `2.4.0`](https://renovatebot.com/diffs/npm/multer/2.3.0/2.4.0) | ![age](https://developer.mend.io/api/mc/badges/age/npm/multer/2.4.0?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/multer/2.3.0/2.4.0?slim=true) | --- ### Release Notes <details> <summary>expressjs/multer (multer)</summary> ### [`v2.4.0`](https://github.com/expressjs/multer/blob/HEAD/CHANGELOG.md#240) [Compare Source](https://github.com/expressjs/multer/compare/v2.3.0...v2.4.0) - Fix [CVE-2026-88932](https://www.cve.org/CVERecord?id=CVE-2026-88932) ([GHSA-3pph-fpjx-jg34](https://github.com/expressjs/multer/security/advisories/GHSA-3pph-fpjx-jg34)) - Add `filename` to `LIMIT_FILE_SIZE` and `LIMIT_UNEXPECTED_FILE` errors ([#&#8203;1416](https://github.com/expressjs/multer/pull/1416)) - Accept a function for `limits`, called with the request, to set limits per request ([#&#8203;1133](https://github.com/expressjs/multer/pull/1133)) - Add opt-in `flush` option to `DiskStorage` to fsync files before the callback runs ([#&#8203;1458](https://github.com/expressjs/multer/pull/1458)) - Expose busboy's `defCharset`, `highWaterMark` and `fileHwm` options ([#&#8203;1465](https://github.com/expressjs/multer/pull/1465)) - Add `streamHandler` option to feed busboy from pre-consumed bodies (Google Cloud Functions, Firebase) ([#&#8203;1466](https://github.com/expressjs/multer/pull/1466)) - Allow `multer.diskStorage()` to be called without options ([#&#8203;1471](https://github.com/expressjs/multer/pull/1471)) - Decode WHATWG-escaped characters (`%0A`, `%0D`, `%22`) in field names, matching `file.originalname` since 2.3.0: `req.body` keys, `file.fieldname` and `err.field` now carry the real name. If you matched the escaped spelling as a workaround, use the real name now ([#&#8203;1473](https://github.com/expressjs/multer/pull/1473)) - Report the decoded filename in `err.filename` on `LIMIT_FILE_SIZE` errors, matching `file.originalname` ([#&#8203;1478](https://github.com/expressjs/multer/pull/1478)) - Reject non-integer or negative `limits` values at construction time; a float limit silently disabled the check ([#&#8203;1395](https://github.com/expressjs/multer/pull/1395), [#&#8203;1335](https://github.com/expressjs/multer/pull/1335)) - Accept requests with exactly `limits.parts` parts; `LIMIT_PART_COUNT` now fires only when the limit is exceeded. If you set `parts` one higher to work around this, you can drop the extra one ([#&#8203;1446](https://github.com/expressjs/multer/pull/1446)) - Files skipped by `fileFilter` no longer count towards `maxCount` ([#&#8203;1426](https://github.com/expressjs/multer/pull/1426)) - Change the `LIMIT_UNEXPECTED_FILE` message to "Unexpected file field" ([#&#8203;426](https://github.com/expressjs/multer/pull/426)) - Remove the `concat-stream` dependency ([#&#8203;1356](https://github.com/expressjs/multer/pull/1356)) - Docs: add JSDoc to the public API and document the storage engine stream contract ([#&#8203;1467](https://github.com/expressjs/multer/pull/1467), [#&#8203;1468](https://github.com/expressjs/multer/pull/1468)) - Docs: add FormData upload examples ([#&#8203;896](https://github.com/expressjs/multer/pull/896)) - Docs: remove the translated READMEs ([#&#8203;1463](https://github.com/expressjs/multer/pull/1463)) - Internal: run the test suite on macOS ([#&#8203;1464](https://github.com/expressjs/multer/pull/1464)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "before 8am on monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
chore(deps): update dependency multer to v2.4.0
All checks were successful
CI / check-and-build (pull_request) Successful in 43s
4e1695864f
EgorEast force-pushed renovate/multer-2.x-lockfile from 4e1695864f
All checks were successful
CI / check-and-build (pull_request) Successful in 43s
to 7425cce05c
All checks were successful
CI / check-and-build (pull_request) Successful in 49s
2026-10-03 06:03:05 +00:00
Compare
EgorEast force-pushed renovate/multer-2.x-lockfile from 7425cce05c
All checks were successful
CI / check-and-build (pull_request) Successful in 49s
to e76b2a0c08
All checks were successful
CI / check-and-build (pull_request) Successful in 1m38s
2026-10-06 06:05:07 +00:00
Compare
Merge branch 'main' into renovate/multer-2.x-lockfile
All checks were successful
CI / check-and-build (pull_request) Successful in 39s
75fd18adb7
EgorEast closed this pull request 2026-10-06 08:36:52 +00:00
All checks were successful
CI / check-and-build (pull_request) Successful in 39s

Pull request closed

Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Slovo_Propovedi/slovo-propovedi-backend!8
No description provided.