NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #262 most downloaded on npm
Fast, unopinionated, minimalist web framework
Last release 7 days ago
14 Sep 2026
Release timing varies
gaps range from 3 weeks to 1.4 years
Nearly every release is documented
notes for 60 of the last 60 stable releases
173 versions withdrawn
withdrawn after publishing
16 years old
289 releases · first in 2010
Fix req.host when using "trust proxy" hops count
req.host when using "trust proxy" hops countreq.protocol/req.secure when using "trust proxy" hops countFix "trust proxy" setting to inherit when app is mounted
"trust proxy" setting to inherit when app is mountedETags for all request responses
GET and HEAD requestscontent-type to parse Content-Type headerscontent-type to parse Content-Type headersoptionsOne column per quarter.
- deps: connect@2.28.3 - deps: compression@~1.3.1 - deps: csurf@~1.6.6 - deps: errorhandler@~1.3.3 - deps: express-session@~1.10.2 - deps: serve-index
- deps: connect@2.28.2 - deps: body-parser@~1.10.2 - deps: serve-static@~1.8.1 - deps: send@0.11.1 - Fix root path disclosure
Fix OPTIONS responses to include the HEAD method property
OPTIONS responses to include the HEAD method propertyreadline for prompt in express(1)Fix exception in req.fresh/req.stale without response headers
req.fresh/req.stale without response headers- deps: connect@2.27.6 - deps: compression@~1.2.2 - deps: express-session@~1.9.3 - deps: http-errors@~1.2.8 - deps: serve-index@~1.5.3 - deps: type-is
- deps: connect@2.27.4 - deps: body-parser@~1.9.3 - deps: compression@~1.2.1 - deps: errorhandler@~1.2.3 - deps: express-session@~1.9.2 - deps: qs@2.3
Correctly invoke async callback asynchronously
Fix handling of URLs containing :// in the path
:// in the pathFix internal utils.merge deprecation warnings
utils.merge deprecation warningsUse content-disposition module for res.attachment/res.download
content-disposition module for res.attachment/res.download
Content-Disposition headeretag module to generate ETag headershttp-errors module for creating errorsutils-merge module for merging objectsDEBUG_FD env variable support- deps: connect@2.26.6 - deps: compression@~1.1.2 - deps: csurf@~1.6.2 - deps: errorhandler@~1.2.2
Fix accepting non-object arguments to logger
logger- deps: connect@2.26.4 - deps: morgan@~1.3.2 - deps: type-is@~1.5.2
- deps: connect@2.26.3 - deps: body-parser@~1.8.4 - deps: serve-favicon@~2.1.5 - deps: serve-static@~1.6.3 - deps: proxy-addr@~1.0.3 - Use forwarded n
forwarded npm module- deps: connect@2.26.2 - deps: body-parser@~1.8.3 - deps: qs@2.2.4
Fix a global leak when multiple subnets are trusted
Use crc instead of buffer-crc32 for speed
crc instead of buffer-crc32 for speedFix error in req.subdomains on empty host
req.subdomains on empty hostSupport IP address host in req.subdomains
req.subdomainslastModified optionetag to generate ETag headerVary header string as fieldFix a path traversal issue when using root
root- deps: connect@2.25.9 - deps: body-parser@~1.6.7 - deps: qs@2.2.2
- deps: connect@2.25.8 - deps: body-parser@~1.6.6 - deps: csurf@~1.4.1 - deps: qs@2.2.0
- deps: connect@2.25.7 - deps: body-parser@~1.6.5 - deps: express-session@~1.7.6 - deps: morgan@~1.2.3 - deps: serve-static@~1.5.3 - deps: send@0.8.3
Work around fd leak in Node.js 0.10 for fs.ReadStream
fd leak in Node.js 0.10 for fs.ReadStreamFix backwards compatibility in logger
loggerFix original URL parsing in res.location
res.locationquery middleware breaking with argument- deps: connect@2.25.3 - deps: multiparty@3.3.2
- deps: connect@2.25.2 - deps: body-parser@~1.6.2 - deps: qs@1.2.0
- deps: connect@2.25.1 - deps: body-parser@~1.6.1 - deps: qs@1.1.0
- deps: connect@2.25.0 - deps: body-parser@~1.6.0 - deps: compression@~1.0.10 - deps: csurf@~1.4.0 - deps: express-session@~1.7.4 - deps: qs@1.0.2 - d
extensions optionfix res.sendfile regression for serving directory index files
res.sendfile regression for serving directory index filesWork-around v8 generating empty stack traces
Fix exception when global Error.stackTraceLimit is too low
Error.stackTraceLimit is too lowAdd TRACE_DEPRECATION environment variable
req.protocol for proxy-direct connectionsres.sendfile to sendTRACE_DEPRECATION environment variable--no-deprecation argument--trace-deprecation argumentRegExpdotfiles optionmaxAge value to 1 yearprevious versions are not vulnerable; this is just explicit protection
res.redirect(url, status) -- use res.redirect(status, url) insteadres.send(status, num) to send num as json (not error)res.jsonp returns JSON responseCONNECTadd deprecation message to app.configure
app.configurereq.authbasic-auth to parse Authorization headermaxage (converted by ms)- deps: connect@2.21.1 - deps: cookie-parser@1.3.2 - deps: cookie-signature@1.0.4 - deps: express-session@~1.5.2 - deps: type-is@~1.3.2 - deps: cookie
deprecate connect(middleware) -- use app.use(middleware) instead
media-typer to alter content-type charsetconnect(middleware) -- use app.use(middleware) insteadconnect.createServer() -- use connect() insteadres.setHeader() patch to work with with get -> append -> set patterndeprecate things with depd module
depd moduleverify option to json -- use body-parser module directlyverify option to urlencoded -- use body-parser module directlydepd modulefinalhandler for final response handlingmedia-typer to parse content-type for charsetDo not throw un-catchable error on file open race condition
escape-html for HTML escapingfix "event emitter leak" warnings
- use vary module for res.vary - deps: connect@2.19.4 - deps: errorhandler@1.0.2 - deps: method-override@2.0.2 - deps: serve-favicon@2.0.1 - deps: deb
vary module for res.vary- deps: connect@2.19.3 - deps: compression@1.0.6
- deps: connect@2.19.2 - deps: compression@1.0.4 - deps: proxy-addr@1.0.1
deprecate methodOverride() -- use method-override module directly
methodOverride() -- use method-override module directlymax-age in Cache-Control in correct formatcustom etag control with app.set('etag', val)
app.set('etag', val)
app.set('etag', function(body, encoding){ return '"etag"' }) custom etag generationapp.set('etag', 'weak') weak tagapp.set('etag', 'strong') strong etagapp.set('etag', false) turn offapp.set('etag', true) standard etagres.send ETag as weak and reduce collisions- update connect to 2.17.3 - deps: body-parser@1.2.2 - deps: express-session@1.2.1 - deps: method-override@1.0.2
keep previous Content-Type for res.jsonp
Content-Type for res.jsonpcharset in Content-Type for res.sendres.charset appending charset when content-type has onedeprecate res.headerSent -- use res.headersSent
app.set('trust proxy', trust)
app.set('trust proxy', 1) trust first hopapp.set('trust proxy', 'loopback') trust loopback addressesapp.set('trust proxy', '10.0.0.1') trust single IPapp.set('trust proxy', '10.0.0.1/16') trust subnetapp.set('trust proxy', '10.0.0.1, 10.0.0.2') trust listapp.set('trust proxy', false) turn offapp.set('trust proxy', true) trust everythingres.headerSent -- use res.headersSentres.on("header") -- use on-headers module insteadres.appendHeader that would append in wrong orderdeprecate app.del() -- use app.delete() instead
app.del() -- use app.delete() insteadres.json(obj, status) -- use res.json(status, obj) instead
res.json(status, num) requires res.status(status).json(num)res.jsonp(obj, status) -- use res.jsonp(status, obj) instead
res.jsonp(status, num) requires res.status(status).jsonp(num)app.purgerouter.purgeapp.allres.appendHeaderres.headerSent to return Booleanres.headersSent for node.js 0.8enable() methodfix res.jsonp error if callback param is object
req.host for IPv6 literalsres.jsonp error if callback param is objectNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →