Bump helmet from 4.6.0 to 8.1.0
Closed
Number: #1573
Type: Pull Request
State: Closed
Type: Pull Request
State: Closed
Author:
dependabot[bot]
Association: None
Comments: 1
![dependabot[bot]](https://github.com/dependabot.png)
Association: None
Comments: 1
Created:
June 09, 2025 at 06:22 AM UTC
(4 months ago)
(4 months ago)
Updated:
August 16, 2025 at 05:35 PM UTC
(about 2 months ago)
(about 2 months ago)
Closed:
August 16, 2025 at 05:35 PM UTC
(about 2 months ago)
(about 2 months ago)
Time to Close:
2 months
Labels:
triage dependencies javascript no-pr-activity
triage dependencies javascript no-pr-activity
Description:
Bumps helmet from 4.6.0 to 8.1.0.
Changelog
Sourced from helmet's changelog.
8.1.0 - 2025-03-17
Changed
Content-Security-Policy
gives a better error when a directive value, likeself
, should be quoted. See #4828.0.0 - 2024-09-28
Changed
- Breaking:
Strict-Transport-Security
now has a max-age of 365 days, up from 180- Breaking:
Content-Security-Policy
middleware now throws an error if a directive should have quotes but does not, such asself
instead of'self'
. See #454- Breaking:
Content-Security-Policy
'sgetDefaultDirectives
now returns a deep copy. This only affects users who were mutating the result- Breaking:
Strict-Transport-Security
now throws an error when "includeSubDomains" option is misspelled. This was previously a warningRemoved
- Breaking: Drop support for Node 16 and 17. Node 18+ is now required
7.2.0 - 2024-09-28
Changed
Content-Security-Policy
middleware now warns if a directive should have quotes but does not, such asself
instead of'self'
. This will be an error in future versions. See #4547.1.0 - 2023-11-07
Added
helmet.crossOriginEmbedderPolicy
now supports theunsafe-none
directive. See #4777.0.0 - 2023-05-06
Changed
- Breaking:
Cross-Origin-Embedder-Policy
middleware is now disabled by default. See #411Removed
- Breaking: Drop support for Node 14 and 15. Node 16+ is now required
- Breaking:
Expect-CT
is no longer part of Helmet. If you still need it, you can use theexpect-ct
package. See #3786.2.0 - 2023-05-06
- Expose header names (e.g.,
strictTransportSecurity
for theStrict-Transport-Security
header, instead ofhsts
)- Rework documentation
6.1.5 - 2023-04-11
Fixed
... (truncated)
Commits
57e1b39
8.1.0c8efbe3
Update changelog for 8.1.0 release3396804
Add 8.0.0 release date to changelog52dd8eb
Content-Security-Policy: better error when value should be quoted4af4777
Use built-in test runner (instead of Jest)ba10272
Organize importse0f1387
Update devDependencies to latest versions842393c
Check types duringnpm test
, run in parallel77fbe3a
Strict-Transport-Security: fix documentation for default max-age632e629
Update license year for 2025- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
1
Files Changed:
2
2
Additions:
+87
+87
Deletions:
-33
-33
Package Dependencies
Technical Details
ID: | 1316876 |
UUID: | 2577489207 |
Node ID: | PR_kwDOFUBaBc6ZoV03 |
Host: | GitHub |
Repository: | Z-byte-prog/docs |
Mergeable: | Yes |
Merge State: | Unstable |