Bump express-rate-limit from 5.3.0 to 7.5.0
            
              Closed
            
          
        
              Number: #1543
Type: Pull Request
State: Closed
            Type: Pull Request
State: Closed
              Author: 
              
              dependabot[bot]
Association: None
Comments: 1
          Association: None
Comments: 1
              Created: 
              
              May 05, 2025 at 06:30 AM UTC
(6 months ago)
            (6 months ago)
              Updated: 
              
              June 23, 2025 at 07:58 AM UTC
(4 months ago)
          (4 months ago)
                  Closed: 
                  
                  June 23, 2025 at 07:58 AM UTC
(4 months ago)
              
                (4 months ago)
                  Time to Close:
                  
                  about 2 months
                
            
              Labels:
triage dependencies javascript
            triage dependencies javascript
              Description:
                
                  
                
            
        Bumps express-rate-limit from 5.3.0 to 7.5.0.
Release notes
Sourced from express-rate-limit's releases.
v7.5.0
Added
- Implemented the combined
 RateLimitheader according to the eighth draft of the IETF RateLimit header specificiation. Enable by settingstandardHeaders: 'draft-8'.- Added a new
 identifieroption, used as the name for the quota policy in thedraft-8headers.- Added a new
 headersDraftVersionvalidation check to identifies cases where an unsupported version string is passed to thestandardHeadersoption.
You can view the full changelog here.
v7.4.1
Fixed
- Made the
 passOnStoreErrorreturn after callingnext()rather than continuing execution.
You can view the full changelog here.
v7.4.0
Added
- Added
 passOnStoreErroroption to allow a way to "fail open" in the event of a backend error.
You can view the full changelog here.
v7.3.1
Fixed
- Changed error displayed for the
 creationStackvalidation check when a store withlocalKeysset to false is used.- Improved documentation for the
 creationStackcheck.
You can view the full changelog here.
v7.3.0
Added
- Added a new
 unsharedStorevalidation check that identifies cases where a single store instance is shared across multiple limiters.
You can view the full changelog here.
... (truncated)
Commits
fe46b437.5.0919bb8adocs: add changelog forv7.5.069a1c20feat(headers): implement ietfdraft-8(#486)413995bbuild(deps): bump cookie, express and socket.io (#483)eaea95b7.4.13a2fdbafix: return after calling next() when passOnStoreError is used (#482)53f3aacbuild(deps): bump body-parser and express (#480)f18932cbuild(deps-dev): bump axios from 1.6.2 to 1.7.5 (#477)00458eabuild(deps-dev): bump webpack from 5.76.3 to 5.94.0 (#476)9d7c8cfbuild(deps): bump ws, engine.io and socket.io-adapter (#474)- Additional commits viewable in compare view
 
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
                  Commits:
1
              
                1
                  Files Changed:
2
              
                2
                  Additions:
+96
              
                +96
                  Deletions:
-32
            -32
Package Dependencies
Technical Details
| ID: | 2039551 | 
            
| UUID: | 2497917627 | 
            
| Node ID: | PR_kwDOFUBaBc6U4zK7 | 
            
| Host: | GitHub | 
| Repository: | Z-byte-prog/docs | 
| Mergeable: | Yes | 
| Merge State: | Unstable |