[PR #7140] [MERGED] Bump express-rate-limit from 8.2.1 to 8.2.2 #56263

Closed
opened 2026-05-01 03:57:15 -05:00 by GiteaMirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/actualbudget/actual/pull/7140
Author: @dependabot[bot]
Created: 3/6/2026
Status: Merged
Merged: 3/7/2026
Merged by: @MatissJanis

Base: masterHead: dependabot/npm_and_yarn/express-rate-limit-8.2.2


📝 Commits (4)

  • fbcdf13 Bump express-rate-limit from 8.2.1 to 8.2.2
  • 4a1f510 [AI] Update express-rate-limit to 8.3.0 to fix GHSA-46wh-pxpv-q5gq vulnerability
  • d04dbd8 Add release notes for PR #7140
  • 9839e70 [AI] Update release notes to reflect version 8.3.0

📊 Changes

3 files changed (+21 additions, -8 deletions)

View changed files

📝 packages/sync-server/package.json (+1 -1)
upcoming-release-notes/7140.md (+6 -0)
📝 yarn.lock (+14 -7)

📄 Description

Bumps express-rate-limit from 8.2.1 to 8.2.2.

Commits
Maintainer changes

This version was pushed to npm by gamemaker1, a new releaser for express-rate-limit since your current version.

Attestation changes

This version has no provenance attestation, while the previous version (8.2.1) was attested. Review the package versions before updating.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bundle Stats

Bundle Files count Total bundle size % Changed
desktop-client 27 14.89 MB → 14.89 MB (-1.15 kB) -0.01%
loot-core 1 5.82 MB 0%
api 1 4.43 MB 0%
View detailed bundle stats

desktop-client

Total

Files count Total bundle size % Changed
27 14.89 MB → 14.89 MB (-1.15 kB) -0.01%
Changeset
File Δ Size
locale/pl.json 📈 +985 B (+1.09%) 88.37 kB → 89.33 kB
locale/en.json 📈 +88 B (+0.05%) 170.33 kB → 170.42 kB
locale/ca.json 📉 -185 B (-0.10%) 188.11 kB → 187.93 kB
locale/de.json 📉 -183 B (-0.10%) 180.07 kB → 179.89 kB
locale/nb-NO.json 📉 -166 B (-0.10%) 156.96 kB → 156.8 kB
locale/it.json 📉 -182 B (-0.10%) 171.16 kB → 170.98 kB
locale/es.json 📉 -186 B (-0.10%) 174.55 kB → 174.37 kB
locale/uk.json 📉 -232 B (-0.11%) 214.88 kB → 214.65 kB
locale/fr.json 📉 -194 B (-0.11%) 179.6 kB → 179.41 kB
locale/nl.json 📉 -156 B (-0.13%) 113.21 kB → 113.06 kB
locale/da.json 📉 -158 B (-0.15%) 106.35 kB → 106.2 kB
locale/th.json 📉 -303 B (-0.16%) 181.87 kB → 181.58 kB
locale/pt-BR.json 📉 -307 B (-0.16%) 183.19 kB → 182.89 kB
View detailed bundle breakdown

Added
No assets were added

Removed
No assets were removed

Bigger

Asset File Size % Changed
static/js/pl.js 88.37 kB → 89.33 kB (+985 B) +1.09%
static/js/en.js 170.33 kB → 170.42 kB (+88 B) +0.05%

Smaller

Asset File Size % Changed
static/js/pt-BR.js 183.19 kB → 182.89 kB (-307 B) -0.16%
static/js/th.js 181.87 kB → 181.58 kB (-303 B) -0.16%
static/js/uk.js 214.88 kB → 214.65 kB (-232 B) -0.11%
static/js/fr.js 179.6 kB → 179.41 kB (-194 B) -0.11%
static/js/es.js 174.55 kB → 174.37 kB (-186 B) -0.10%
static/js/ca.js 188.11 kB → 187.93 kB (-185 B) -0.10%
static/js/de.js 180.07 kB → 179.89 kB (-183 B) -0.10%
static/js/it.js 171.16 kB → 170.98 kB (-182 B) -0.10%
static/js/nb-NO.js 156.96 kB → 156.8 kB (-166 B) -0.10%
static/js/da.js 106.35 kB → 106.2 kB (-158 B) -0.15%
static/js/nl.js 113.21 kB → 113.06 kB (-156 B) -0.13%

Unchanged

Asset File Size % Changed
static/js/index.js 9.54 MB 0%
static/js/indexeddb-main-thread-worker-e59fee74.js 12.94 kB 0%
static/js/workbox-window.prod.es5.js 5.64 kB 0%
static/js/en-GB.js 7.18 kB 0%
static/js/resize-observer.js 18.37 kB 0%
static/js/BackgroundImage.js 120.54 kB 0%
static/js/ReportRouter.js 1.16 MB 0%
static/js/narrow.js 638.11 kB 0%
static/js/TransactionList.js 106.22 kB 0%
static/js/wide.js 164.15 kB 0%
static/js/AppliedFilters.js 9.71 kB 0%
static/js/usePayeeRuleCounts.js 10.04 kB 0%
static/js/useTransactionBatchActions.js 13.23 kB 0%
static/js/FormulaEditor.js 1.04 MB 0%

loot-core

Total

Files count Total bundle size % Changed
1 5.82 MB 0%
View detailed bundle breakdown

Added
No assets were added

Removed
No assets were removed

Bigger
No assets were bigger

Smaller
No assets were smaller

Unchanged

Asset File Size % Changed
kcab.worker.MNtpiHkH.js 5.82 MB 0%

api

Total

Files count Total bundle size % Changed
1 4.43 MB 0%
View detailed bundle breakdown

Added
No assets were added

Removed
No assets were removed

Bigger
No assets were bigger

Smaller
No assets were smaller

Unchanged

Asset File Size % Changed
bundle.api.js 4.43 MB 0%

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/actualbudget/actual/pull/7140 **Author:** [@dependabot[bot]](https://github.com/apps/dependabot) **Created:** 3/6/2026 **Status:** ✅ Merged **Merged:** 3/7/2026 **Merged by:** [@MatissJanis](https://github.com/MatissJanis) **Base:** `master` ← **Head:** `dependabot/npm_and_yarn/express-rate-limit-8.2.2` --- ### 📝 Commits (4) - [`fbcdf13`](https://github.com/actualbudget/actual/commit/fbcdf13627f93f33bef58968f340c5b98facbd99) Bump express-rate-limit from 8.2.1 to 8.2.2 - [`4a1f510`](https://github.com/actualbudget/actual/commit/4a1f5101ed997cf69f94553b000ca27a3c8d2b9c) [AI] Update express-rate-limit to 8.3.0 to fix GHSA-46wh-pxpv-q5gq vulnerability - [`d04dbd8`](https://github.com/actualbudget/actual/commit/d04dbd841629b83da9bf5b4c98717a5862c5bb06) Add release notes for PR #7140 - [`9839e70`](https://github.com/actualbudget/actual/commit/9839e70a87d14348d53bb3eca766792834c935fd) [AI] Update release notes to reflect version 8.3.0 ### 📊 Changes **3 files changed** (+21 additions, -8 deletions) <details> <summary>View changed files</summary> 📝 `packages/sync-server/package.json` (+1 -1) ➕ `upcoming-release-notes/7140.md` (+6 -0) 📝 `yarn.lock` (+14 -7) </details> ### 📄 Description Bumps [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) from 8.2.1 to 8.2.2. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/a009ad6488448515b219eb9f4203c725eb328c8e"><code>a009ad6</code></a> 8.2.2</li> <li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/72cd30e449615e50833ad92f88d8ae59faf9f467"><code>72cd30e</code></a> chore: update dependencies</li> <li><a href="https://github.com/express-rate-limit/express-rate-limit/commit/1ddb1cc8ba6a7774fae49fff0c45e2c2a9305d95"><code>1ddb1cc</code></a> fix: handle ipv4 mapped to ipv6 (ghsa-46wh-pxpv-q5gq)</li> <li>See full diff in <a href="https://github.com/express-rate-limit/express-rate-limit/compare/v8.2.1...v8.2.2">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~gamemaker1">gamemaker1</a>, a new releaser for express-rate-limit since your current version.</p> </details> <details> <summary>Attestation changes</summary> <p>This version has no provenance attestation, while the previous version (8.2.1) was attested. Review the <a href="https://www.npmjs.com/package/express-rate-limit?activeTab=versions">package versions</a> before updating.</p> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=express-rate-limit&package-manager=npm_and_yarn&previous-version=8.2.1&new-version=8.2.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/actualbudget/actual/network/alerts). </details> <!--- actual-bot-sections ---> <hr /> <!--- bundlestats-action-comment key:combined start ---> ### Bundle Stats Bundle | Files count | Total bundle size | % Changed ------ | ----------- | ----------------- | --------- desktop-client | 27 | 14.89 MB → 14.89 MB (-1.15 kB) | -0.01% loot-core | 1 | 5.82 MB | 0% api | 1 | 4.43 MB | 0% <details> <summary>View detailed bundle stats</summary> #### desktop-client **Total** Files count | Total bundle size | % Changed ----------- | ----------------- | --------- 27 | 14.89 MB → 14.89 MB (-1.15 kB) | -0.01% <details> <summary>Changeset</summary> File | Δ | Size ---- | - | ---- `locale/pl.json` | 📈 +985 B (+1.09%) | 88.37 kB → 89.33 kB `locale/en.json` | 📈 +88 B (+0.05%) | 170.33 kB → 170.42 kB `locale/ca.json` | 📉 -185 B (-0.10%) | 188.11 kB → 187.93 kB `locale/de.json` | 📉 -183 B (-0.10%) | 180.07 kB → 179.89 kB `locale/nb-NO.json` | 📉 -166 B (-0.10%) | 156.96 kB → 156.8 kB `locale/it.json` | 📉 -182 B (-0.10%) | 171.16 kB → 170.98 kB `locale/es.json` | 📉 -186 B (-0.10%) | 174.55 kB → 174.37 kB `locale/uk.json` | 📉 -232 B (-0.11%) | 214.88 kB → 214.65 kB `locale/fr.json` | 📉 -194 B (-0.11%) | 179.6 kB → 179.41 kB `locale/nl.json` | 📉 -156 B (-0.13%) | 113.21 kB → 113.06 kB `locale/da.json` | 📉 -158 B (-0.15%) | 106.35 kB → 106.2 kB `locale/th.json` | 📉 -303 B (-0.16%) | 181.87 kB → 181.58 kB `locale/pt-BR.json` | 📉 -307 B (-0.16%) | 183.19 kB → 182.89 kB </details> <details> <summary>View detailed bundle breakdown</summary> <div> **Added** No assets were added **Removed** No assets were removed **Bigger** Asset | File Size | % Changed ----- | --------- | --------- static/js/pl.js | 88.37 kB → 89.33 kB (+985 B) | +1.09% static/js/en.js | 170.33 kB → 170.42 kB (+88 B) | +0.05% **Smaller** Asset | File Size | % Changed ----- | --------- | --------- static/js/pt-BR.js | 183.19 kB → 182.89 kB (-307 B) | -0.16% static/js/th.js | 181.87 kB → 181.58 kB (-303 B) | -0.16% static/js/uk.js | 214.88 kB → 214.65 kB (-232 B) | -0.11% static/js/fr.js | 179.6 kB → 179.41 kB (-194 B) | -0.11% static/js/es.js | 174.55 kB → 174.37 kB (-186 B) | -0.10% static/js/ca.js | 188.11 kB → 187.93 kB (-185 B) | -0.10% static/js/de.js | 180.07 kB → 179.89 kB (-183 B) | -0.10% static/js/it.js | 171.16 kB → 170.98 kB (-182 B) | -0.10% static/js/nb-NO.js | 156.96 kB → 156.8 kB (-166 B) | -0.10% static/js/da.js | 106.35 kB → 106.2 kB (-158 B) | -0.15% static/js/nl.js | 113.21 kB → 113.06 kB (-156 B) | -0.13% **Unchanged** Asset | File Size | % Changed ----- | --------- | --------- static/js/index.js | 9.54 MB | 0% static/js/indexeddb-main-thread-worker-e59fee74.js | 12.94 kB | 0% static/js/workbox-window.prod.es5.js | 5.64 kB | 0% static/js/en-GB.js | 7.18 kB | 0% static/js/resize-observer.js | 18.37 kB | 0% static/js/BackgroundImage.js | 120.54 kB | 0% static/js/ReportRouter.js | 1.16 MB | 0% static/js/narrow.js | 638.11 kB | 0% static/js/TransactionList.js | 106.22 kB | 0% static/js/wide.js | 164.15 kB | 0% static/js/AppliedFilters.js | 9.71 kB | 0% static/js/usePayeeRuleCounts.js | 10.04 kB | 0% static/js/useTransactionBatchActions.js | 13.23 kB | 0% static/js/FormulaEditor.js | 1.04 MB | 0% </div> </details> --- #### loot-core **Total** Files count | Total bundle size | % Changed ----------- | ----------------- | --------- 1 | 5.82 MB | 0% <details> <summary>View detailed bundle breakdown</summary> <div> **Added** No assets were added **Removed** No assets were removed **Bigger** No assets were bigger **Smaller** No assets were smaller **Unchanged** Asset | File Size | % Changed ----- | --------- | --------- kcab.worker.MNtpiHkH.js | 5.82 MB | 0% </div> </details> --- #### api **Total** Files count | Total bundle size | % Changed ----------- | ----------------- | --------- 1 | 4.43 MB | 0% <details> <summary>View detailed bundle breakdown</summary> <div> **Added** No assets were added **Removed** No assets were removed **Bigger** No assets were bigger **Smaller** No assets were smaller **Unchanged** Asset | File Size | % Changed ----- | --------- | --------- bundle.api.js | 4.43 MB | 0% </div> </details> </details> <!--- bundlestats-action-comment key:combined end ---> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
GiteaMirror added the pull-request label 2026-05-01 03:57:16 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/actual#56263