Add this suggestion to a batch that can be applied as a single commit. This suggestion is invalid because no changes were made to the code. Suggestions cannot be applied while the pull request is closed. Suggestions cannot be applied while viewing a subset of changes. Only one suggestion per line can be applied in a batch. Add this suggestion to a batch that can be applied as a single commit. Applying suggestions on deleted lines is not supported. You must change the existing code in this line in order to create a valid suggestion. Outdated suggestions cannot be applied. This suggestion has been applied or marked resolved. Suggestions cannot be applied from pending reviews. Suggestions cannot be applied on multi-line comments. Suggestions cannot be applied while the pull request is queued to merge. Suggestion cannot be applied right now. Please check back later.
This PR was automatically created by Snyk using the credentials of a real user.

Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@nestjs/common
from 10.3.2 to 10.3.8 | 6 versions ahead of your current version | 2 months ago
on 2024-04-19
@nestjs/core
from 10.3.2 to 10.3.8 | 6 versions ahead of your current version | 2 months ago
on 2024-04-19
@nestjs/platform-express
from 10.3.2 to 10.3.8 | 6 versions ahead of your current version | 2 months ago
on 2024-04-19
Issues fixed by the recommended upgrade:
SNYK-JS-EXPRESS-6474509
Release notes
Package name: @nestjs/common
- 10.3.8 - 2024-04-19
- 10.3.7 - 2024-03-28
- 10.3.6 - 2024-03-27
- #13367 Revert "fix(microservices): fix redundant code to emit error" (@ kamilmysliwiec)
- #13366 fix(core): break reference chain to instance object (@ breeeew)
- Other
- #13362 chore(deps-dev): bump @ grpc/proto-loader from 0.7.10 to 0.7.11 (@ dependabot[bot])
- #13358 chore(deps-dev): bump @ typescript-eslint/eslint-plugin from 7.3.1 to 7.4.0 (@ dependabot[bot])
- #13361 chore(deps-dev): bump mocha from 10.3.0 to 10.4.0 (@ dependabot[bot])
- #13363 chore(deps-dev): bump @ grpc/grpc-js from 1.10.3 to 1.10.4 (@ dependabot[bot])
- #13364 chore(deps-dev): bump mysql2 from 3.9.2 to 3.9.3 (@ dependabot[bot])
- #13355 chore(deps-dev): bump @ apollo/server from 4.10.1 to 4.10.2 (@ dependabot[bot])
- #13359 chore(deps-dev): bump @ typescript-eslint/parser from 7.3.1 to 7.4.0 (@ dependabot[bot])
- #13343 chore(deps-dev): bump core-js from 3.36.0 to 3.36.1 (@ dependabot[bot])
- #13344 chore(deps-dev): bump @ commitlint/cli from 19.2.0 to 19.2.1 (@ dependabot[bot])
- #13347 chore(deps-dev): bump typescript from 5.4.2 to 5.4.3 (@ dependabot[bot])
- #13345 chore(deps-dev): bump @ types/node from 20.11.29 to 20.11.30 (@ dependabot[bot])
- #13348 chore(deps-dev): bump @ fastify/multipart from 8.1.0 to 8.2.0 (@ dependabot[bot])
- #13352 chore(deps-dev): bump mongoose from 8.2.2 to 8.2.3 (@ dependabot[bot])
- #13357 chore(deps): bump express from 4.19.1 to 4.19.2 (@ dependabot[bot])
- #13349 chore(deps): bump express from 4.18.3 to 4.19.1 (@ dependabot[bot])
- Abdulla Bayramov (@ breeeew)
- Kamil Mysliwiec (@ kamilmysliwiec)
- 10.3.5 - 2024-03-22
- 10.3.4 - 2024-03-18
- #13337 fix(core): middleware is not executed for root route when global prefix is set (@ kamilmysliwiec)
- #13285 fix(microservices): fix rabbitmq no-assert not being applied correctly (@ sorooshme)
- #13317 fix(common): fix stacktrace regex (@ hokaccha)
- #13225 feat(core,common): Add
- #13221 docs(common): remove incorrect constructor signature of HttpException (@ kalmanbendeguz)
- Other
- #13133 chore(deps): update dependency webpack to v5.90.3 (@ renovate[bot])
- #13335 chore(deps): bump undici and mercurius in /sample/33-graphql-mercurius (@ dependabot[bot])
- #13331 chore(deps-dev): bump @ grpc/grpc-js from 1.10.2 to 1.10.3 (@ dependabot[bot])
- #13332 chore(deps-dev): bump @ types/node from 20.11.27 to 20.11.28 (@ dependabot[bot])
- #13333 chore(deps-dev): bump mongoose from 8.2.1 to 8.2.2 (@ dependabot[bot])
- #13334 chore(deps-dev): bump @ commitlint/cli from 19.1.0 to 19.2.0 (@ dependabot[bot])
- #13314 chore(deps-dev): bump @ commitlint/config-angular from 19.0.3 to 19.1.0 (@ dependabot[bot])
- #13320 chore(deps-dev): bump mqtt from 5.3.6 to 5.4.0 (@ dependabot[bot])
- #13321 chore(deps-dev): bump @ types/node from 20.11.26 to 20.11.27 (@ dependabot[bot])
- #13323 chore(deps-dev): bump socket.io-client from 4.7.4 to 4.7.5 (@ dependabot[bot])
- #13329 chore(deps-dev): bump follow-redirects from 1.15.4 to 1.15.6 (@ dependabot[bot])
- #13315 chore(deps): bump fast-json-stringify from 5.12.0 to 5.13.0 (@ dependabot[bot])
- #13307 chore(deps-dev): bump @ typescript-eslint/parser from 7.1.1 to 7.2.0 (@ dependabot[bot])
- #13316 chore(deps-dev): bump @ commitlint/cli from 19.0.3 to 19.1.0 (@ dependabot[bot])
- #13305 chore(deps-dev): bump ts-morph from 21.0.1 to 22.0.0 (@ dependabot[bot])
- #13306 chore(deps-dev): bump @ typescript-eslint/eslint-plugin from 7.1.1 to 7.2.0 (@ dependabot[bot])
- #13308 chore(deps-dev): bump @ types/node from 20.11.25 to 20.11.26 (@ dependabot[bot])
- #13309 chore(deps-dev): bump @ grpc/grpc-js from 1.10.1 to 1.10.2 (@ dependabot[bot])
- #13291 chore(deps-dev): bump @ typescript-eslint/parser from 7.1.0 to 7.1.1 (@ dependabot[bot])
- #13299 chore(deps-dev): bump @ types/node from 20.11.24 to 20.11.25 (@ dependabot[bot])
- #13300 chore(deps-dev): bump typescript from 5.3.3 to 5.4.2 (@ dependabot[bot])
- #13280 chore(deps-dev): bump @ types/node from 20.11.22 to 20.11.24 (@ dependabot[bot])
- #13281 chore(deps): bump cli-color from 2.0.3 to 2.0.4 (@ dependabot[bot])
- #13289 chore(deps-dev): bump artillery from 2.0.6 to 2.0.7 (@ dependabot[bot])
- #13290 chore(deps-dev): bump mongoose from 8.2.0 to 8.2.1 (@ dependabot[bot])
- #13292 chore(deps-dev): bump @ typescript-eslint/eslint-plugin from 7.1.0 to 7.1.1 (@ dependabot[bot])
- #13296 chore(deps-dev): bump @ apollo/server from 4.10.0 to 4.10.1 (@ dependabot[bot])
- #13263 chore(deps-dev): bump @ typescript-eslint/eslint-plugin from 7.0.2 to 7.1.0 (@ dependabot[bot])
- #13274 chore(deps-dev): bump @ commitlint/cli from 18.6.1 to 19.0.3 (@ dependabot[bot])
- #13269 chore(deps-dev): bump @ types/amqplib from 0.10.4 to 0.10.5 (@ dependabot[bot])
- #13273 chore(deps-dev): bump @ types/node from 20.11.20 to 20.11.22 (@ dependabot[bot])
- #13275 chore(deps-dev): bump @ commitlint/config-angular from 18.6.1 to 19.0.3 (@ dependabot[bot])
- #13258 chore(deps-dev): bump eslint from 8.56.0 to 8.57.0 (@ dependabot[bot])
- #13259 chore(deps-dev): bump graphql-tools from 9.0.0 to 9.0.1 (@ dependabot[bot])
- #13262 chore(deps-dev): bump mysql2 from 3.9.1 to 3.9.2 (@ dependabot[bot])
- #13264 chore(deps-dev): bump mqtt from 5.3.5 to 5.3.6 (@ dependabot[bot])
- #13265 chore(deps-dev): bump @ typescript-eslint/parser from 7.0.2 to 7.1.0 (@ dependabot[bot])
- #13266 chore(deps): bump es5-ext from 0.10.49 to 0.10.63 (@ dependabot[bot])
- #13217 chore(deps-dev): bump @ grpc/grpc-js from 1.10.0 to 1.10.1 (@ dependabot[bot])
- #13230 chore(deps-dev): bump @ typescript-eslint/eslint-plugin from 6.21.0 to 7.0.2 (@ dependabot[bot])
- #13232 chore(deps-dev): bump artillery from 2.0.5 to 2.0.6 (@ dependabot[bot])
- #13240 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/32-graphql-federation-schema-first/posts-application (@ dependabot[bot])
- #13231 chore(deps-dev): bump @ typescript-eslint/parser from 7.0.1 to 7.0.2 (@ dependabot[bot])
- #13209 chore(deps-dev): bump @ commitlint/config-angular from 18.6.0 to 18.6.1 (@ dependabot[bot])
- #13229 chore(deps-dev): bump @ fastify/view from 8.2.0 to 9.0.0 (@ dependabot[bot])
- #13235 chore(deps-dev): bump ip from 1.1.8 to 1.1.9 (@ dependabot[bot])
- #13236 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/31-graphql-federation-code-first/gateway (@ dependabot[bot])
- #13237 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/32-graphql-federation-schema-first/users-application (@ dependabot[bot])
- #13238 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/31-graphql-federation-code-first/posts-application (@ dependabot[bot])
- #13239 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/31-graphql-federation-code-first/users-application (@ dependabot[bot])
- #13241 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/32-graphql-federation-schema-first/gateway (@ dependabot[bot])
- #13242 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/14-mongoose-base (@ dependabot[bot])
- #13243 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/06-mongoose (@ dependabot[bot])
- #13244 chore(deps): bump ip from 2.0.0 to 2.0.1 in /sample/13-mongo-typeorm (@ dependabot[bot])
- #13248 chore(deps-dev): bump @ types/node from 20.11.17 to 20.11.20 (@ dependabot[bot])
- #13249 chore(deps-dev): bump nodemon from 3.0.3 to 3.1.0 (@ dependabot[bot])
- #13250 chore(deps-dev): bump mongoose from 8.1.2 to 8.2.0 (@ dependabot[bot])
- #12831 chore(deps): update dependency prettier to v3.2.5 (@ renovate[bot])
- #13207 chore(deps-dev): bump husky from 9.0.10 to 9.0.11 (@ dependabot[bot])
- #13175 chore(deps): update dependency @ types/jest to v29.5.12 (@ renovate[bot])
- #13122 fix(deps): update dependency typeorm to v0.3.20 (@ renovate[bot])
- #13174 chore(deps): update dependency @ nestjs/cli to v10.3.2 (@ renovate[bot])
- #13213 chore(deps-dev): bump core-js from 3.35.1 to 3.36.0 (@ dependabot[bot])
- #13208 chore(deps-dev): bump @ commitlint/cli from 18.6.0 to 18.6.1 (@ dependabot[bot])
- #13202 chore(deps-dev): bump @ typescript-eslint/parser from 6.21.0 to 7.0.1 (@ dependabot[bot])
- #13181 fix(deps): update dependency @ fastify/static to v7 (@ renovate[bot])
- #13179 fix(deps): update dependency @ nestjs/bull to v10.1.0 (@ renovate[bot])
- #13324 chore(deps): bump socket.io from 4.7.4 to 4.7.5 (@ dependabot[bot])
- #13303 chore(deps): bump light-my-request from 5.11.1 to 5.12.0 (@ dependabot[bot])
- #13287 chore(deps): bump fastify from 4.26.1 to 4.26.2 (@ dependabot[bot])
- #13257 chore(deps): bump light-my-request from 5.11.0 to 5.11.1 (@ dependabot[bot])
- #13203 chore(deps): bump fastify from 4.26.0 to 4.26.1 (@ dependabot[bot])
- #13279 chore(deps): bump express from 4.18.2 to 4.18.3 (@ dependabot[bot])
- Bendegúz Kálmán (@ kalmanbendeguz)
- Justin Timmons (@ jtimmons)
- Kamil Mysliwiec (@ kamilmysliwiec)
- Kazuhito Hokamura (@ hokaccha)
- Maximiliano Kazanski (@ wokcito)
- Soroosh Merajiyan (@ sorooshme)
- Tolga Paksoy (@ tolgap)
- Version 13 (@ version13)
- YoungKi Lyu (@ youngkiu)
- @ 719media
- @ le-harivansh
- apeltop (@ apeltop)
- blackgerman (@ blackgerman)
- dudu_1 (@ dygma0)
- 10.3.3 - 2024-02-12
- 10.3.2 - 2024-02-07
- #12974 fix(microservices): send rmq nack without matching message handler (@ toxol)
- #13084 fix: #13077 KafkaJs typing consistency (@ edeesis)
- #13151 fix(packages/microservices): pass inboxPrefix as argument to createInbox (@ leandrogenas)
- #13000 fix(core,common): 🐛 missing registration handling of
- #12955 feat: Implement getHeader and appendHeader methods in adapters (@ josesilveiraa07)
- #13105 feat(microservices): add type for rmq connection options (@ Deniks)
- #13152 fix: allow @ fastify/static v7 (@ alexfriesen)
- #12943 fix(deps): update dependency reflect-metadata to v0.2.1 (@ renovate[bot])
- Other
- #13101 chore(deps-dev): bump @ commitlint/config-angular from 18.5.0 to 18.6.0 (@ dependabot[bot])
- #13173 chore(deps-dev): bump @ grpc/grpc-js from 1.9.14 to 1.10.0 (@ dependabot[bot])
- #13162 chore(deps-dev): bump prettier from 3.2.4 to 3.2.5 (@ dependabot[bot])
- #13166 chore(deps): bump fast-json-stringify from 5.11.1 to 5.12.0 (@ dependabot[bot])
- #13170 chore(deps-dev): bump @ typescript-eslint/eslint-plugin from 6.20.0 to 6.21.0 (@ dependabot[bot])
- #13167 chore(deps-dev): bump redis from 4.6.12 to 4.6.13 (@ dependabot[bot])
- #13168 chore(deps-dev): bump artillery from 2.0.4 to 2.0.5 (@ dependabot[bot])
- #13171 chore(deps-dev): bump lint-staged from 15.2.1 to 15.2.2 (@ dependabot[bot])
- #13172 chore(deps-dev): bump @ typescript-eslint/parser from 6.20.0 to 6.21.0 (@ dependabot[bot])
- #13129 chore(deps-dev): bump @ typescript-eslint/eslint-plugin from 6.19.1 to 6.20.0 (@ dependabot[bot])
- #13134 chore(deps): update mysql docker tag to v8.3.0 (@ renovate[bot])
- #13142 fix(deps): update dependency mysql2 to v3.9.1 (@ renovate[bot])
- #13149 chore(deps-dev): bump lint-staged from 15.2.0 to 15.2.1 (@ dependabot[bot])
- #13154 chore(deps-dev): bump @ fastify/static from 6.12.0 to 7.0.0 (@ dependabot[bot])
- #13155 chore(deps-dev): bump husky from 9.0.7 to 9.0.10 (@ dependabot[bot])
- #13156 chore(deps-dev): bump @ types/node from 20.11.13 to 20.11.16 (@ dependabot[bot])
- #13157 chore(deps): bump fast-json-stringify from 5.10.0 to 5.11.1 (@ dependabot[bot])
- #13114 chore(deps): update dependency eslint-plugin-prettier to v5.1.3 (@ renovate[bot])
- #13117 chore(deps): update dependency ts-jest to v29.1.2 (@ renovate[bot])
- #13118 fix(deps): update dependency @ graphql-tools/utils to v10.0.13 (@ renovate[bot])
- #13120 fix(deps): update dependency class-validator to v0.14.1 (@ renovate[bot])
- #13127 chore(deps-dev): bump mysql2 from 3.9.0 to 3.9.1 (@ dependabot[bot])
- #13130 chore(deps-dev): bump @ typescript-eslint/parser from 6.19.1 to 6.20.0 (@ dependabot[bot])
- #13131 chore(deps-dev): bump husky from 9.0.6 to 9.0.7 (@ dependabot[bot])
- #13137 chore(deps-dev): bump @ types/node from 20.11.10 to 20.11.13 (@ dependabot[bot])
- #13138 fix(deps): update dependency @ nestjs/cache-manager to v2.2.0 (@ renovate[bot])
- #13139 fix(deps): update dependency @ nestjs/swagger to v7.2.0 (@ renovate[bot])
- #13140 fix(deps): update dependency cache-manager to v5.4.0 (@ renovate[bot])
- #13141 fix(deps): update dependency dotenv to v16.4.1 (@ renovate[bot])
- #13124 chore(deps): update dependency @ nestjs/cli to v10.3.0 (@ renovate[bot])
- #13085 chore(deps-dev): bump mqtt from 5.3.4 to 5.3.5 (@ dependabot[bot])
- #13111 chore(deps-dev): bump mysql2 from 3.8.0 to 3.9.0 (@ dependabot[bot])
- #13113 chore(deps): update babel monorepo to v7.23.9 (@ renovate[bot])
- #13116 chore(deps): update dependency nodemon to v3.0.3 (@ renovate[bot])
- #13119 fix(deps): update dependency @ grpc/grpc-js to v1.9.14 (@ renovate[bot])
- #13121 fix(deps): update dependency socket.io to v4.7.4 (@ renovate[bot])
- #13086 chore(deps-dev): bump cache-manager from 5.3.2 to 5.4.0 (@ dependabot[bot])
- #13097 chore(deps-dev): bump mongoose from 8.1.0 to 8.1.1 (@ dependabot[bot])
- #13102 chore(deps-dev): bump husky from 8.0.3 to 9.0.6 (@ dependabot[bot])
- #13103 chore(deps-dev): bump @ commitlint/cli from 18.4.4 to 18.6.0 (@ dependabot[bot])
- #13112 chore(deps-dev): bump @ types/node from 20.11.5 to 20.11.10 (@ dependabot[bot])
- #13087 chore(deps-dev): bump mongoose from 8.0.4 to 8.1.0 (@ dependabot[bot])
- #13088 chore(deps-dev): bump mysql2 from 3.7.1 to 3.8.0 (@ dependabot[bot])
- #13090 chore(deps-dev): bump core-js from 3.35.0 to 3.35.1 (@ dependabot[bot])
- #13091 chore(deps-dev): bump @ commitlint/config-angular from 18.4.4 to 18.5.0 (@ dependabot[bot])
- #13092 chore(deps-dev): bump @ types/node from 20.11.4 to 20.11.5 (@ dependabot[bot])
- #13148 chore(deps): bump @ fastify/cors from 9.0.0 to 9.0.1 (@ dependabot[bot])
- #13128 chore(deps): bump fastify from 4.25.2 to 4.26.0 (@ dependabot[bot])
- #13109 chore(deps): bump @ fastify/cors from 8.5.0 to 9.0.0 (@ dependabot[bot])
- Alex (@ alexfriesen)
- Deniss Rezanovičs (@ Deniks)
- Doron Guttman (@ doronguttman)
- Ed Mitchell (@ edeesis)
- Leandro Fabri Pereira (@ leandrogenas)
- Toxol (@ toxol)
- @ josesilveiraa07
from @nestjs/common GitHub release notesv10.3.8
v10.3.7
v10.3.6 (2024-03-27)
Bug fixes
microservicescoreDependencies
platform-expressCommitters: 2
v10.3.5
v10.3.4 (2024-03-18)
Bug fixes
core,platform-fastifymicroservicescommonEnhancements
common,core@ RawBody()decorator (@ tolgap)Docs
commonDependencies
platform-socket.ioplatform-fastifyplatform-expressCommitters: 14
v10.3.3
v10.3.2 (2024-02-07)
Bug fixes
microservicescommon,coreSEARCHhttp verb (@ doronguttman)Enhancements
core,platform-express,platform-fastifymicroservicesplatform-fastifyDependencies
common,core,microservices,websocketsplatform-fastifyCommitters: 7
Package name: @nestjs/core
v10.3.8
v10.3.7
v10.3.6 (2024-03-27)
Bug fixes
microservicescoreDependencies
platform-expressCommitters: 2
v10.3.5
v10.3.4 (2024-03-18)
Bug fixes
core,platform-fastifymicroservicescommonEnhancements
common,core@ RawBody()decorator (@ tolgap)Docs
commonDependencies