Skip to content

build(deps): bump multer and node-red - #2215

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-0fb9c934a6
Open

build(deps): bump multer and node-red#2215
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-0fb9c934a6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps multer to 2.3.0 and updates ancestor dependency node-red. These dependencies need to be updated together.

Updates multer from 2.2.0 to 2.3.0

Release notes

Sourced from multer's releases.

v2.3.0

Important

What's Changed

New Contributors

... (truncated)

Changelog

Sourced from multer's changelog.

2.3.0

Commits
  • 4e8edf5 2.3.0 (#1455)
  • 87a584e fix: reject invalid field names instead of crashing on append-field errors
  • ab6aeae fix: enforce file size limit with async fileFilter
  • eef7444 fix: destroy disk write stream on aborted uploads to prevent fd leak
  • 25ec9bb docs: refresh all README translations (#1462)
  • 73c1759 feat: add an opt-in fieldArrayIndexLimit (#1438)
  • ece6735 Update 'README-zh-cn.md' up to now (#1264)
  • 3278e1b docs: add Japanese translation to README (#1354)
  • 3c0bc5e test: accept files exactly at fileSize limit (#1382)
  • b6d84b0 docs: add Indonesian translation for README (#1431)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for multer since your current version.


Updates node-red from 4.1.13 to 5.0.7

Release notes

Sourced from node-red's releases.

5.0.7: Maintenance Release

What's Changed

New Contributors

Full Changelog: node-red/node-red@5.0.6...5.0.7

5.0.6: Maintenance Release

What's Changed

Full Changelog: node-red/node-red@5.0.5...5.0.6

5.0.5: Maintenance Release

What's Changed

New Contributors

Full Changelog: node-red/node-red@5.0.4...5.0.5

5.0.4

What's Changed

Full Changelog: node-red/node-red@5.0.3...5.0.4

5.0.3: Maintenance Release

What's Changed

... (truncated)

Changelog

Sourced from node-red's changelog.

5.0.7: Maintenance Release

5.0.6: Maintenance Release

  • Revert @​node-rs/bcrypt update due to OS/arch compatibility issues

5.0.5: Maintenance Release

5.0.4: Maintenance Release

  • Revert JSONata update further due to regression in behaviour

5.0.3: Maintenance Release

  • Revert JSONata update due to regression in behaviour

5.0.2: Maintenance Release

5.0.1: Maintenance Release

... (truncated)

Commits
  • d9644c4 Merge pull request #5936 from node-red/rel507
  • 4b48745 Update changelog
  • 1394534 Merge pull request #5934 from GogoVega/fix-5698-typedInput-render
  • a55e6fc Bump for 5.0.7
  • 7d229f2 Update body-parser
  • f435a0b Fix incorrect rendering of typedInput with a single type
  • 95dcd47 Merge pull request #5931 from R0CKing666/fix/file-in-jsonata-done-5928
  • 737ab97 Merge pull request #5926 from Bryandero98/fix/dark-mode-disabled-wire-visibility
  • 53a5c30 Merge pull request #5933 from node-red/patch-jsonata
  • dfb760f Remove only test modifier
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [multer](https://github.com/expressjs/multer) to 2.3.0 and updates ancestor dependency [node-red](https://github.com/node-red/node-red). These dependencies need to be updated together.


Updates `multer` from 2.2.0 to 2.3.0
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](expressjs/multer@v2.2.0...v2.3.0)

Updates `node-red` from 4.1.13 to 5.0.7
- [Release notes](https://github.com/node-red/node-red/releases)
- [Changelog](https://github.com/node-red/node-red/blob/main/CHANGELOG.md)
- [Commits](node-red/node-red@4.1.13...5.0.7)

---
updated-dependencies:
- dependency-name: multer
  dependency-version: 2.3.0
  dependency-type: indirect
- dependency-name: node-red
  dependency-version: 5.0.7
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants