Pull Request Overview
- Opened on September 11, 2026
- Status Open
- Commit count 1 with first commit September 11, 2026
Total Delta
Open Days
Test Delta
How long has this pull request spent in each phase of its lifecycle?
| Fraction of total time | Business days | Phase |
|---|---|---|
|
|
0.0 days | Authoring 1 commit before pull request opened for review |
|
|
0.0 days | Awaiting first review |
|
|
7.7 days | Revising work with 0 commits in response to 1 review that left 2 comments |
Total time for pull request still awaiting merge (longer than repo's target): 7.7 business days
chore(deps): bump @slack/bolt from 5.0.0 to 5.1.0 in /examples/custom-receiver
Bumps @slack/bolt from 5.0.0 to 5.1.0.
Changelog
Sourced from @slack/bolt's changelog.
5.1.0
Minor Changes
6cf7b0c: Enforce a configurable request body size limit in
HTTPReceiverandExpressReceiverto prevent unauthenticated large-body denial-of-service attempts. Both receivers previously buffered the entire request body into memory before signature verification, so a flood of large invalid requests could exhaust memory and crash a publicly exposed app.Both receivers now reject request bodies larger than a new
bodyLimitoption with an HTTP413response before the whole body is buffered. The limit is enforced on the bytes actually received (not theContent-Lengthheader, which a client controls) and applies even whensignatureVerificationisfalse. It defaults to4194304(4 MB); pass a differentnumberof bytes, abytes-style string like'4mb', orInfinityto disable it (not recommended in production).This is a security fix with a minor behavioral change: requests with bodies larger than 4 MB are now rejected with
413by default (previously unbounded). Apps that legitimately receive larger payloads can raisebodyLimiton the receiver.Patch Changes
- b9acd4f: Fix
AwsEventV1.multiValueQueryStringParametersto allownull, matching the actual AWS API Gateway payload and the@types/aws-lambdaAPIGatewayProxyEventtype. This resolves the type error when passing anAPIGatewayProxyEventdirectly to the handler returned byAwsLambdaReceiver.
Commits
-
ffbe0b6chore: release (#3020) -
6cf7b0cfeat(receivers): add configurable bodyLimit to cap request body size (#3057) -
08d52eechore(deps-dev): bump@changesets/clifrom 2.30.0 to 3.0.1 (#3067) -
f7a7379chore(deps-dev): update serverless requirement from ^4.41.0 to ^4.41.1 in /ex... -
0542410chore(deps-dev): bump@changesets/get-release-planfrom 4.0.15 to 4.0.16 (#3066) -
278eb5bchore(deps-dev): bump@changesets/configfrom 3.1.3 to 3.1.4 (#3063) -
b4d97d8chore(deps-dev): bump@changesets/assemble-release-planfrom 6.0.9 to 6.0.10 ... -
d374244chore(deps-dev): bump@changesets/get-dependents-graphfrom 2.1.3 to 2.1.4 (#... -
9ae4bdeci: allow Dependabot to update the changesets toolchain (#3061) -
e973b79chore(deps): bump@slack/web-apifrom 8.0.0 to 8.1.1 (#3059) - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Comments Threads Pending Resolution
Resolved Comment Threads
No resolved comments have been left on this PR.