This pull request's diff hasn't been prepared yet. Log in with GitHub to have us prepare it for review.

chore(deps): bump @slack/bolt from 5.0.0 to 5.1.0 in /examples/custom-receiver #3075

Open
dependabot[bot] opened 7:53am on September 11, 2026 wants to merge 1 commit into slackapi/bolt main from
dependabot/npm_and_yarn/examples/custom-receiver/slack/bolt-5.1.0
Diff Delta:
0
Classified as:  General

dependabot-bot's Description of Work

Bumps @slack/bolt from 5.0.0 to 5.1.0.

Changelog

Sourced from @​slack/bolt's changelog.



5.1.0


Minor Changes




  • 6cf7b0c: Enforce a configurable request body size limit in HTTPReceiver and ExpressReceiver to prevent unauthenticated large-body denial-of-service attempts. Both receivers previously buffered the entire request body into memory before signature verification, so a flood of large invalid requests could exhaust memory and crash a publicly exposed app.


    Both receivers now reject request bodies larger than a new bodyLimit option with an HTTP 413 response before the whole body is buffered. The limit is enforced on the bytes actually received (not the Content-Length header, which a client controls) and applies even when signatureVerification is false. It defaults to 4194304 (4 MB); pass a different number of bytes, a bytes-style string like '4mb', or Infinity to disable it (not recommended in production).


    This is a security fix with a minor behavioral change: requests with bodies larger than 4 MB are now rejected with 413 by default (previously unbounded). Apps that legitimately receive larger payloads can raise bodyLimit on the receiver.




Patch Changes



  • b9acd4f: Fix AwsEventV1.multiValueQueryStringParameters to allow null, matching the actual AWS API Gateway payload and the @types/aws-lambda APIGatewayProxyEvent type. This resolves the type error when passing an APIGatewayProxyEvent directly to the handler returned by AwsLambdaReceiver.


Commits



  • ffbe0b6 chore: release (#3020)


  • 6cf7b0c feat(receivers): add configurable bodyLimit to cap request body size (#3057)


  • 08d52ee chore(deps-dev): bump @​changesets/cli from 2.30.0 to 3.0.1 (#3067)


  • f7a7379 chore(deps-dev): update serverless requirement from ^4.41.0 to ^4.41.1 in /ex...


  • 0542410 chore(deps-dev): bump @​changesets/get-release-plan from 4.0.15 to 4.0.16 (#3066)


  • 278eb5b chore(deps-dev): bump @​changesets/config from 3.1.3 to 3.1.4 (#3063)


  • b4d97d8 chore(deps-dev): bump @​changesets/assemble-release-plan from 6.0.9 to 6.0.10 ...


  • d374244 chore(deps-dev): bump @​changesets/get-dependents-graph from 2.1.3 to 2.1.4 (#...


  • 9ae4bde ci: allow Dependabot to update the changesets toolchain (#3061)


  • e973b79 chore(deps): bump @​slack/web-api from 8.0.0 to 8.1.1 (#3059)

  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

1 total changed file
(1 file ignored)
Congrats, you've cleared the final file
Approve, request changes, or stare into the void (reviewer's choice) 😅