NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2633 most downloaded on npm
help secure Express/Connect apps with various HTTP headers
Last release 2 months ago
12 Jul 2026
Release timing varies
gaps range from 4 weeks to 1.2 years
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
135 releases · first in 2012
Content-Security-Policy: improved performance by ~7% when there are no dynamic directives
Content-Security-Policy: improved performance by ~7% when there are no dynamic directivesContent-Security-Policy: improved error handling for invalid directive namesContent-Security-Policy: useDefaults: false with no directives is no longer valid, both at runtime and the type levelContent-Security-Policy: dynamically-computed directive values would throw, not call next, when invalidContent-Security-Policy: dynamically-computed directive value entries would throw, not call next, when function threwCross-Origin-Opener-Policy: support noopener-allow-popups. See #522
Cross-Origin-Opener-Policy: support noopener-allow-popups. See #522One column per quarter.
Content-Security-Policy gives a better error when a directive value, like self, should be quoted. See #482
Content-Security-Policy gives a better error when a directive value, like self, should be quoted. See #482Breaking: Strict-Transport-Security now has a max-age of 365 days, up from 180
Strict-Transport-Security now has a max-age of 365 days, up from 180Content-Security-Policy middleware now throws an error if a directive should have quotes but does not, such as self instead of 'self'. See #454Content-Security-Policy's getDefaultDirectives now returns a deep copy. This only affects users who were mutating the resultStrict-Transport-Security now throws an error when "includeSubDomains" option is misspelled. This was previously a warningContent-Security-Policy middleware now warns if a directive should have quotes but does not, such as self instead of 'self'. This will be an error in
Content-Security-Policy middleware now warns if a directive should have quotes but does not, such as self instead of 'self'. This will be an error in future versions. See #454helmet.crossOriginEmbedderPolicy now supports the unsafe-none directive. See #447
helmet.crossOriginEmbedderPolicy now supports the unsafe-none directive. See #447Breaking: Cross-Origin-Embedder-Policy middleware is now disabled by default. See #411
Cross-Origin-Embedder-Policy middleware is now disabled by default. See #411Expect-CT is no longer part of Helmet. If you still need it, you can use the expect-ct package. See #378Expose header names (e.g., strictTransportSecurity for the Strict-Transport-Security header, instead of hsts)
strictTransportSecurity for the Strict-Transport-Security header, instead of hsts)Fixed yet another issue with TypeScript exports. See #420
Fix another issue with TypeScript default exports. See #418
Fix issue with TypeScript default exports. See #417
Restored main to package to help with some build tools
main to package to help with some build tools### Fixed - Fixed missing package metadata
Improve support for various TypeScript setups, including "nodenext". See #405
crossOriginEmbedderPolicy did not accept options at the top level. See #390
crossOriginEmbedderPolicy did not accept options at the top level. See #390Breaking: helmet.contentSecurityPolicy no longer sets block-all-mixed-content directive by default
helmet.contentSecurityPolicy no longer sets block-all-mixed-content directive by defaulthelmet.expectCt is no longer set by default. It can, however, be explicitly enabled. It will be removed in Helmet 7. See #310helmet.frameguard no longer offers a specific error when trying to use ALLOW-FROM; it just says that it is unsupported. Only the error message has changedFix TypeScript bug with some TypeScript configurations. See #375 and #359
Cross-Origin-Embedder-Policy: support credentialless policy. See #365
Cross-Origin-Embedder-Policy: support credentialless policy. See #365Content-Security-Policy and Content-Security-Policy-Report-OnlyOrigin-Agent-ClusterImprove imports for CommonJS and ECMAScript modules. See #345
Removed some unused internal code
ECMAScript module imports (i.e., import helmet from "helmet" and import { frameguard } from "helmet"). See #320
import helmet from "helmet" and import { frameguard } from "helmet"). See #320helmet.contentSecurityPolicy: useDefaults option now defaults to truehelmet.contentSecurityPolicy: form-action directive is now set to 'self' by defaulthelmet.crossOriginEmbedderPolicy is enabled by defaulthelmet.crossOriginOpenerPolicy is enabled by defaulthelmet.crossOriginResourcePolicy is enabled by defaulthelmet.originAgentCluster is enabled by defaulthelmet.frameguard: add TypeScript editor autocomplete. See #322helmet() function is slightly fasterNothing published for this version
helmet.contentSecurityPolicy: the useDefaults option, defaulting to false, lets you selectively override defaults more easily
helmet.contentSecurityPolicy: the useDefaults option, defaulting to false, lets you selectively override defaults more easilypackage.json. See #303helmet.crossOriginEmbedderPolicy: a new middleware for the Cross-Origin-Embedder-Policy header, disabled by default
helmet.crossOriginEmbedderPolicy: a new middleware for the Cross-Origin-Embedder-Policy header, disabled by defaulthelmet.crossOriginOpenerPolicy: a new middleware for the Cross-Origin-Opener-Policy header, disabled by defaulthelmet.crossOriginResourcePolicy: a new middleware for the Cross-Origin-Resource-Policy header, disabled by defaulttrue enables a middleware with default options. Previously, this would fail with an error if the middleware was already enabled by default.originAgentCluster at the top levelNothing published for this version
Shrink the published package by about 2.5 kB
helmet.originAgentCluster: a new middleware for the Origin-Agent-Cluster header, disabled by default
helmet.originAgentCluster: a new middleware for the Origin-Agent-Cluster header, disabled by defaulthelmet.contentSecurityPolicy: broken TypeScript types. See #283
helmet.contentSecurityPolicy: broken TypeScript types. See #283helmet.contentSecurityPolicy: setting the default-src to helmet.contentSecurityPolicy.dangerouslyDisableDefaultSrc disables it
helmet.contentSecurityPolicy: setting the default-src to helmet.contentSecurityPolicy.dangerouslyDisableDefaultSrc disables ithelmet.frameguard: slightly improved error messages for non-stringshelmet.contentSecurityPolicy: get the default directives with contentSecurityPolicy.getDefaultDirectives()
helmet.contentSecurityPolicy: get the default directives with contentSecurityPolicy.getDefaultDirectives()helmet() now supports objects that don't have Object.prototype in their chain, such as Object.create(null), as optionshelmet.expectCt: max-age is now first. See #264Fixed a few errors in the README
Directive values can now include functions, as they could in Helmet 3. See #243
helmet.contentSecurityPolicy:
HelmetOptions interface is no longer exported. This only affects TypeScript users. If you need the functionality back, see this commentNothing published for this version
Nothing published for this version
See the Helmet 4 upgrade guide for help upgrading from Helmet 3.
See the Helmet 4 upgrade guide for help upgrading from Helmet 3.
helmet.contentSecurityPolicy:
default-src directive is supplied, an error is thrownhelmet.contentSecurityPolicy:
helmet.xssFilter now disables the buggy XSS filter by default. See #230helmet.featurePolicy. If you still need it, use the feature-policy package on npm.helmet.hpkp. If you still need it, use the hpkp package on npm.helmet.noCache. If you still need it, use the nocache package on npm.helmet.contentSecurityPolicy:
browserSniff and disableAndroid parameters). See helmetjs/csp#97reportOnly. Read this if you need help.setAllHeaders parameter). Read this if you need help.loose optionhelmet.frameguard:
ALLOW-FROM action. Read more here.helmet.hidePoweredBy no longer accepts arguments. See this article to see how to replicate the removed behavior. See #224.helmet.hsts:
includeSubdomains with a lowercase D. See #231setIf. Read this if you need help. See #232helmet.xssFilter no longer accepts options. Read "How to disable blocking with X-XSS-Protection" and "How to enable the report directive with X-XSS-Protection" if you need the legacy behavior.Nothing published for this version
Nothing published for this version
Nothing published for this version
helmet.expectCt is no longer a separate package. This should have no effect on end users.
helmet.expectCt is no longer a separate package. This should have no effect on end users.helmet.frameguard is no longer a separate package. This should have no effect on end users.helmet.dnsPrefetchControl is no longer a separate package. This should have no effect on end users.
helmet.dnsPrefetchControl is no longer a separate package. This should have no effect on end users.helmet.ieNoOpen is no longer a separate package. This should have no effect on end users.
helmet.ieNoOpen is no longer a separate package. This should have no effect on end users.helmet.featurePolicy is deprecated. Use the feature-policy module instead.
helmet.featurePolicy is deprecated. Use the feature-policy module instead.Rewrote internals in TypeScript. This should have no effect on end users.
helmet.noCache is deprecated. Use the nocache module instead. See #215
helmet-csp to v2.10.0
allow-downloads sandbox directive. See helmet-csp#103helmet.noCache is deprecated. Use the nocache module instead. See #215Updated bowser subdependency from 2.7.0 to 2.9.0
helmet-csp to v2.9.5
bowser subdependency from 2.7.0 to 2.9.0bowser subdependency. See helmet-csp#96 and #101Updated bowser subdependency from 2.6.1 to 2.7.0. See helmet-csp#94
helmet-csp to v2.9.4
bowser subdependency from 2.6.1 to 2.7.0. See helmet-csp#94Fixed a bug where a request from Firefox 4 could delete default-src from future responses
helmet-csp to v2.9.2
default-src from future responsesbowser subdependency to latest versionUpdated x-xss-protection to v1.3.0
x-xss-protection to v1.3.0
mode: null to disable mode=blockhelmet-csp to v2.9.1
bowser subdependency from 2.5.3 to 2.5.4. See helmet-csp#88### Changed - Updated helmet-csp to v2.9.0
helmet-csp to v2.9.0### Changed - Updated helmet-csp to v2.8.0
helmet-csp to v2.8.0Updated dns-prefetch-control to v0.2.0
dns-prefetch-control to v0.2.0dont-sniff-mimetype to v1.1.0helmet-crossdomain to v0.4.0hide-powered-by to v1.1.0x-xss-protection to v1.2.0featurePolicy has 19 new features: ambientLightSensor, documentDomain, documentWrite, encryptedMedia, fontDisplayLateSwap, layoutAnimations, legacyIma
featurePolicy has 19 new features: ambientLightSensor, documentDomain, documentWrite, encryptedMedia, fontDisplayLateSwap, layoutAnimations, legacyImageFormats, loadingFrameDefaultEager, oversizedImages, pictureInPicture, serial, syncScript, unoptimizedImages, unoptimizedLosslessImages, unoptimizedLossyImages, unsizedMedia, verticalScroll, wakeLock, and xrexpect-ct to v0.2.0feature-policy to v0.3.0frameguard to v3.1.0nocache to v2.1.0referrerPolicy now supports multiple values
referrerPolicy now supports multiple valuesreferrerPolicy to v1.2.0helmet.hsts's setIf option has been deprecated and will be removed in hsts@3. See helmetjs/hsts#22 for more
bugs field in package.jsonhsts to v2.2.0ienoopen to v1.1.0helmet.hsts's setIf option has been deprecated and will be removed in hsts@3. See helmetjs/hsts#22 for moreincludeSubdomains option (with a lowercase d) has been deprecated and will be removed in hsts@3. Use the uppercase-D includeSubDomains option instead. See helmetjs/hsts#21 for moreThe hpkp middleware has been deprecated. If you still need to use this module, install the standalone hpkp module from npm. See #180 for more.
hpkp middleware has been deprecated. If you still need to use this module, install the standalone hpkp module from npm. See #180 for more.helmet.featurePolicy now supports four new features
helmet.featurePolicy now supports four new featureshelmet.featurePolicy middleware
helmet.featurePolicy middlewarehelmet.permittedCrossDomainPolicies middleware
helmet.permittedCrossDomainPolicies middlewareRemoved lodash.reduce dependency from csp
lodash.reduce dependency from cspexpectCt should use comma instead of semicolon as delimiter
expectCt should use comma instead of semicolon as delimiterYour coding agent can read these notes before it upgrades. Set up the MCP server →