NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #262 most downloaded on npm
Fast, unopinionated, minimalist web framework
Last release 6 days ago
14 Sep 2026
Release timing varies
gaps range from 3 weeks to 1.4 years
Nearly every release is documented
notes for 60 of the last 60 stable releases
173 versions withdrawn
withdrawn after publishing
16 years old
289 releases · first in 2010
Deprecate leading : in name for app.param(name, fn)
res.append(field, val) to append headers: in name for app.param(name, fn)req.param() -- use req.params, req.body, or req.query insteadapp.param(fn)OPTIONS responses to include the HEAD method properlyres.sendFile not always detecting aborted connectionFix crash from error within OPTIONS response handler
OPTIONS response handlerOne column per quarter.
Fix Allow header for OPTIONS to not contain duplicate methods
Allow header for OPTIONS to not contain duplicate methodsres.sendFile when HEAD or 304Fix exception in req.fresh/req.stale without response headers
req.fresh/req.stale without response headersFix res.send double-calling res.end for HEAD requests
res.send double-calling res.end for HEAD requestsFix res.sendfile logging standard write errors
res.sendfile logging standard write errorsFix res.sendFile logging standard write errors
res.sendFile logging standard write errorsarrayLimit behaviorCorrectly invoke async router callback asynchronously
Fix handling of URLs containing :// in the path
:// in the pathAdd support for app.set('views', array)
app.set('views', array)
res.send(status) to mention res.sendStatus(status)content-disposition module for res.attachment/res.download
Content-Disposition headerpath.resolve in view lookupDEBUG_FD env variable supporton-finished to determine request statusFix res.redirect body when redirect status specified
res.redirect body when redirect status specifiedFix using same param name in array of paths
Fix redirect loop when index file serving disabled
- deps: etag@~1.4.0 - deps: proxy-addr@~1.0.3 - Use forwarded npm module - deps: send@0.9.3 - deps: etag@~1.4.0 - deps: serve-static@~1.6.3 - deps: se
forwarded npm moduleFix issue with object keys starting with numbers truncated
Fix a global leak when multiple subnets are trusted
Fix regression for empty string path in app.use
path in app.userouter.use to accept array of middleware without pathapp.use argumentsFix app.use to accept array of middleware without path
app.use to accept array of middleware without pathInvoke callback for sendfile when client aborts
res.sendStatusres.sendFile, res.sendfile, and res.downloaderr will be populated with request aborted errorreq.subdomainsetag to generate ETag headersmime-typesX-Content-Type-Options: nosniff headerlastModified optionetag to generate ETag headerlastModified optionhasbody to be true for content-length: 0Vary header string as fieldFix a path traversal issue when using root
root- deps: qs@2.2.2 - Remove unnecessary cloning
- deps: qs@2.2.0 - Array parsing fix - Performance improvements
- deps: send@0.8.3 - deps: destroy@1.0.3 - deps: on-finished@2.1.0 - deps: serve-static@~1.5.3 - deps: send@0.8.3
Work around fd leak in Node.js 0.10 for fs.ReadStream
fd leak in Node.js 0.10 for fs.ReadStreamFix parsing of weird req.originalUrl values
req.originalUrl values- deps: qs@1.2.0 - Fix parsing array of objects
fix incorrect deprecation warnings on res.download
res.downloaddeprecate res.sendfile -- use res.sendFile instead
res.sendFile
root option specifiedres.sendfile -- use res.sendFile insteadapp.use()extensions optionextensions optionfix res.sendfile regression for serving directory index files
res.sendfile regression for serving directory index filesFix incorrect 403 on Windows and Node.js 0.11
Work-around v8 generating empty stack traces
Fix exception when global Error.stackTraceLimit is too low
Error.stackTraceLimit is too lowdeprecate res.json(status, obj) -- use res.status(status).json(obj) instead
req.protocol for proxy-direct connectionsapp.set('query parser', parser)
app.set('query parser', 'extended') parse with "qs" moduleapp.set('query parser', 'simple') parse with "querystring" core moduleapp.set('query parser', false) disable query string parsingapp.set('query parser', true) enable simple parsingres.json(status, obj) -- use res.status(status).json(obj) insteadres.jsonp(status, obj) -- use res.status(status).jsonp(obj) insteadres.send(status, body) -- use res.status(status).send(body) insteadTRACE_DEPRECATION environment variable--no-deprecation argument--trace-deprecation argumentRegExpdotfiles optionmaxAge value to 1 yearBuffer creation in res.sendfix subapp.mountpath regression for app.use(subapp)
subapp.mountpath regression for app.use(subapp)previous versions are not vulnerable; this is just explicit protection
app.use()req.param(name, fn) handlersres.redirect(url, status) -- use res.redirect(status, url) insteadres.send(status, num) to send num as json (not error)res.jsonp returns JSON responsepath in app.use(path, fn)
RegExptry blocksapp.use(fn)CONNECTres methodsfix routing regression when altering req.method
req.methodadd deprecation message to non-plural req.accepts*
req.accepts*res.send(body, status)res.vary()headers option to res.sendfile
mergeParams option to Router
req.params from parent routesreq.hostname -- correct name for what req.host returnsdepd modulereq.host -- use req.hostname insteadroute.all is only routerouter.param() only when route matchesreq.params after invoking routerfinalhandler for final response handlingmedia-typer to alter content-type charsetmaxage (converted by ms)maxAge (converted by ms)setHeaders option- deps: cookie-signature@1.0.4 - fix for timing attacks
fix res.attachment Unicode filenames in Safari
res.attachment Unicode filenames in Safariexpress:routerfix persistence of modified req.params[name] from app.param()
req.params[name] from app.param()escape-html for HTML escapingfix catching errors from top-level handlers
vary module for res.varySend max-age in Cache-Control in correct format
max-age in Cache-Control in correct formatescape-html for escapingcustom etag control with app.set('etag', val)
app.set('etag', val)
app.set('etag', function(body, encoding){ return '"etag"' }) custom etag generationapp.set('etag', 'weak') weak tagapp.set('etag', 'strong') strong etagapp.set('etag', false) turn offapp.set('etag', true) standard etagres.send ETag as weak and reduce collisionsfix handling of errors from router.param() callbacks
router.param() callbacksrevert "fix behavior of multiple app.VERB for the same path"
app.VERB for the same path"
add req.baseUrl to access the path stripped from req.url in routes
req.baseUrl to access the path stripped from req.url in routesapp.VERB for the same pathrouter.param() only when necessary instead of every matchapp.set('trust proxy', trust)
app.set('trust proxy', 1) trust first hopapp.set('trust proxy', 'loopback') trust loopback addressesapp.set('trust proxy', '10.0.0.1') trust single IPapp.set('trust proxy', '10.0.0.1/16') trust subnetapp.set('trust proxy', '10.0.0.1, 10.0.0.2') trust listapp.set('trust proxy', false) turn offapp.set('trust proxy', true) trust everythingcharset in Content-Type for res.senddeprecate app.del() -- use app.delete() instead
app.del() -- use app.delete() insteadres.json(obj, status) -- use res.json(status, obj) instead
res.json(status, num) requires res.status(status).json(num)res.jsonp(obj, status) -- use res.jsonp(status, obj) instead
res.jsonp(status, num) requires res.status(status).jsonp(num)req.next when inside router instanceETag header in HEAD requestsContent-Type for res.jsonpapp.purgerouter.purgeapp.allenable() methodfix res.jsonp error if callback param is object
req.host for IPv6 literalsres.jsonp error if callback param is objectNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix setting empty header from empty field
field- deps: basic-auth@~1.0.3 - deps: connect@2.30.1 - deps: body-parser@~1.13.2 - deps: compression@~1.5.1 - deps: errorhandler@~1.4.1 - deps: morgan@~1.
perf: parse with regular expressions
ETag matching supportDate response headerContent-Location on 304 responsehttp-errors for standard emitted errorsstatuses instead of http module for status messages- deps: connect@2.29.2 - deps: body-parser@~1.12.4 - deps: compression@~1.4.4 - deps: connect-timeout@~1.6.2 - deps: debug@~2.2.0 - deps: depd@~1.0.1
Fix high intensity foreground color for bold
extensions or index optionsYour coding agent can read these notes before it upgrades. Set up the MCP server →