dependabot-bot's Description of Work
Bumps @slack/bolt from 5.0.0 to 5.1.0.
Changelog
Sourced from @slack/bolt's changelog.
5.1.0
Minor Changes
6cf7b0c: Enforce a configurable request body size limit in
HTTPReceiverandExpressReceiverto prevent unauthenticated large-body denial-of-service attempts. Both receivers previously buffered the entire request body into memory before signature verification, so a flood of large invalid requests could exhaust memory and crash a publicly exposed app.Both receivers now reject request bodies larger than a new
bodyLimitoption with an HTTP413response before the whole body is buffered. The limit is enforced on the bytes actually received (not theContent-Lengthheader, which a client controls) and applies even whensignatureVerificationisfalse. It defaults to4194304(4 MB); pass a differentnumberof bytes, abytes-style string like'4mb', orInfinityto disable it (not recommended in production).This is a security fix with a minor behavioral change: requests with bodies larger than 4 MB are now rejected with
413by default (previously unbounded). Apps that legitimately receive larger payloads can raisebodyLimiton the receiver.Patch Changes
- b9acd4f: Fix
AwsEventV1.multiValueQueryStringParametersto allownull, matching the actual AWS API Gateway payload and the@types/aws-lambdaAPIGatewayProxyEventtype. This resolves the type error when passing anAPIGatewayProxyEventdirectly to the handler returned byAwsLambdaReceiver.
Commits
-
ffbe0b6chore: release (#3020) -
6cf7b0cfeat(receivers): add configurable bodyLimit to cap request body size (#3057) -
08d52eechore(deps-dev): bump@changesets/clifrom 2.30.0 to 3.0.1 (#3067) -
f7a7379chore(deps-dev): update serverless requirement from ^4.41.0 to ^4.41.1 in /ex... -
0542410chore(deps-dev): bump@changesets/get-release-planfrom 4.0.15 to 4.0.16 (#3066) -
278eb5bchore(deps-dev): bump@changesets/configfrom 3.1.3 to 3.1.4 (#3063) -
b4d97d8chore(deps-dev): bump@changesets/assemble-release-planfrom 6.0.9 to 6.0.10 ... -
d374244chore(deps-dev): bump@changesets/get-dependents-graphfrom 2.1.3 to 2.1.4 (#... -
9ae4bdeci: allow Dependabot to update the changesets toolchain (#3061) -
e973b79chore(deps): bump@slack/web-apifrom 8.0.0 to 8.1.1 (#3059) - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)