chore(deps): update @slack/bolt requirement from ^5.0.0 to ^5.1.0 in /examples/deploy-heroku #3079

Open
dependabot[bot] opened 7:53am on September 11, 2026 wants to merge 1 commit into slackapi/bolt main from
dependabot/npm_and_yarn/examples/deploy-heroku/slack/bolt-tw-5.1.0
Diff Delta:
0
About 0 Diff Delta/hour
Classified as:  General

dependabot-bot's Description of Work

Updates the requirements on @slack/bolt to permit the latest version.

Changelog

Sourced from @​slack/bolt's changelog.



5.1.0


Minor Changes




  • 6cf7b0c: Enforce a configurable request body size limit in HTTPReceiver and ExpressReceiver to prevent unauthenticated large-body denial-of-service attempts. Both receivers previously buffered the entire request body into memory before signature verification, so a flood of large invalid requests could exhaust memory and crash a publicly exposed app.


    Both receivers now reject request bodies larger than a new bodyLimit option with an HTTP 413 response before the whole body is buffered. The limit is enforced on the bytes actually received (not the Content-Length header, which a client controls) and applies even when signatureVerification is false. It defaults to 4194304 (4 MB); pass a different number of bytes, a bytes-style string like '4mb', or Infinity to disable it (not recommended in production).


    This is a security fix with a minor behavioral change: requests with bodies larger than 4 MB are now rejected with 413 by default (previously unbounded). Apps that legitimately receive larger payloads can raise bodyLimit on the receiver.




Patch Changes



  • b9acd4f: Fix AwsEventV1.multiValueQueryStringParameters to allow null, matching the actual AWS API Gateway payload and the @types/aws-lambda APIGatewayProxyEvent type. This resolves the type error when passing an APIGatewayProxyEvent directly to the handler returned by AwsLambdaReceiver.


5.0.0


Major Changes




  • d284e69: Drop Node.js 18 support. The minimum required runtime is now Node.js 20 (npm >=9.6.4).




  • d284e69: Remove deprecated WorkflowStep class and all associated types, middleware, and utilities. Use CustomFunction and app.function() instead.




  • d284e69: Replace axios with native fetch for response_url calls. Remove agent and clientTls options from AppOptions — use clientOptions.fetch to provide a custom fetch implementation for proxy/TLS needs. Add a dispatcher option to SocketModeReceiver for proxy/TLS configuration in socket mode.


    respond() now throws a RespondError when the response_url request returns a non-2xx status (restoring the throw-on-failure behavior that axios provided) and resolves to a Response on success rather than an axios response object.




Minor Changes



  • d284e69: Improve error handling by leveraging @slack/web-api v8 error classes. Authorization errors are now properly wrapped in an AuthorizationError, preserving the original thrown value (non-Error rejections are retained via the cause of the wrapped original). Default error handlers log richer details for web-api errors (API error codes, rate limit durations, HTTP status codes) alongside the full error object, so stack traces and causes remain available. The @slack/web-api error classes (SlackError, WebAPIPlatformError, WebAPIRequestError, WebAPIHTTPError, WebAPIRateLimitedError) can be imported from @slack/web-api for instanceof checks.


Patch Changes




  • 9839a50: Pass the App's named bolt-app ConsoleLogger to the default receivers when no logger option is provided. Previously the App constructor built a named logger on this.logger but threaded the raw (potentially undefined) constructor argument into initReceiver, so HTTPReceiver / SocketModeReceiver each built their own anonymous logger and receiver-side log lines (e.g. unhandled HTTP requests on custom routes) appeared without the bolt-app prefix.


    Behaviour change for the no-logger case: the default receiver now shares the same Logger instance as app.logger, so a downstream app.logger.setLevel(...) after construction will affect receiver-side logging too. This is consistent with the existing behaviour that already mutates this.logger's level via the logLevel constructor option. Apps that supplied their own logger are unaffected; apps that relied on the receiver's logger being independent of app.logger will need to pass a separate logger into the receiver explicitly.




  • e1c21d7: Fix AwsLambdaReceiver.toHandler() so Bolt apps on the AWS Lambda Node.js 24+ runtime no longer fail at startup with Runtime.CallbackHandlerDeprecated. The returned handler is now a 2-arg promise-based function; the unused trailing callback parameter has been removed from the AwsHandler type. The legacy AwsCallback export is retained and marked @deprecated.




  • f2de079: Add context_team_id and context_enterprise_id as optional fields on the EnvelopedEvent type. Slack's Events API delivers these on the envelope for Slack Connect channels and Enterprise Grid org-wide apps, where team_id may refer to a workspace different from the one the bot is installed in. Without the typed fields, downstream code had to reach for @ts-expect-error or unsafe casts to route by the correct workspace.




4.7.3


Patch Changes



  • 341b60e: Reject empty signingSecret at initialization to prevent accidental HMAC signature forgery.


4.7.2


Patch Changes



  • 4545150: Require exact ssl_check=1 value to bypass signature verification, preventing truthy but incorrect values from skipping authentication checks.


4.7.1


<!-- raw HTML omitted -->

... (truncated)

Commits



  • ffbe0b6 chore: release (#3020)


  • 6cf7b0c feat(receivers): add configurable bodyLimit to cap request body size (#3057)


  • 08d52ee chore(deps-dev): bump @​changesets/cli from 2.30.0 to 3.0.1 (#3067)


  • f7a7379 chore(deps-dev): update serverless requirement from ^4.41.0 to ^4.41.1 in /ex...


  • 0542410 chore(deps-dev): bump @​changesets/get-release-plan from 4.0.15 to 4.0.16 (#3066)


  • 278eb5b chore(deps-dev): bump @​changesets/config from 3.1.3 to 3.1.4 (#3063)


  • b4d97d8 chore(deps-dev): bump @​changesets/assemble-release-plan from 6.0.9 to 6.0.10 ...


  • d374244 chore(deps-dev): bump @​changesets/get-dependents-graph from 2.1.3 to 2.1.4 (#...


  • 9ae4bde ci: allow Dependabot to update the changesets toolchain (#3061)


  • e973b79 chore(deps): bump @​slack/web-api from 8.0.0 to 8.1.1 (#3059)

  • Additional commits viewable in compare view


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

1 total changed file
(1 file ignored)
You've reached the end of this PR review
Your attention span may now revert to "default human"