NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #2633 most downloaded on npm
help secure Express/Connect apps with various HTTP headers
Last release 2 months ago
12 Jul 2026
Release timing varies
gaps range from 4 weeks to 1.2 years
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
15 years old
135 releases · first in 2012
xssFilter now supports reportUri option
xssFilter now supports reportUri optionMain Helmet middleware is now named to help with debugging
One column per quarter.
csp now supports prefix-src directive
csp now supports prefix-src directivecsp no longer loads JSON files internally, helping some module bundlersfalse should be able to disable a CSP directivecsp now supports strict-dynamic value
csp now supports strict-dynamic valuecsp now supports require-sri-for directiveconnect dependencyUpdated connect dependency to latest
connect dependency to latestcsp does not automatically set report-to when setting report-uri
csp does not automatically set report-to when setting report-urihsts no longer cares whether it's HTTPS and always sets the header
hsts no longer cares whether it's HTTPS and always sets the headercsp now supports report-to directive
csp now supports report-to directivenpmignore### Changed - Bump connect version
connect versionexpectCt middleware for setting the Expect-CT header
expectCt middleware for setting the Expect-CT headercsp now supports the worker-src directive
csp now supports the worker-src directive### Changed - Bump connect version
connect versioncsp now supports more sandbox directives
csp now supports more sandbox directivesreferrerPolicy allows strict-origin and strict-origin-when-cross-origin directives
referrerPolicy allows strict-origin and strict-origin-when-cross-origin directivesconnect versioncsp now allows manifest-src directive
csp now allows manifest-src directivecsp now allows frame-src directive
csp now allows frame-src directivecsp will check your directives for common mistakes and throw errors if it finds them. This can be disabled with loose: true.
csp will check your directives for common mistakes and throw errors if it finds them. This can be disabled with loose: true.csp. For source lists (like script-src or object-src), use the standard scriptSrc: ["'none'"]. The sandbox directive can be sandbox: true to block everything.false can disable a CSP directive. For example, scriptSrc: false is the same as not specifying it.reportOnly: true no longer requires a report-uri to be set.hsts's maxAge now defaults to 180 days (instead of 1 day)hsts's maxAge parameter is seconds, not millisecondshsts includes subdomains by defaultdomain parameter in frameguard cannot be emptynoEtag option no longer present in noCacheconnect-src workaround in CSP modulehpkp middleware now supports the includeSubDomains property with a capital D
hpkp middleware now supports the includeSubDomains property with a capital Dhpkp was setting includeSubdomains instead of includeSubDomains### Added - referrerPolicy middleware
referrerPolicy middlewareTop-level aliases (like helmet.xssFilter) are no longer dynamically required
helmet.xssFilter) are no longer dynamically requirednocache's noEtag option is now deprecated
nocache's noEtag option is now deprecatedcsp now better handles Firefox on mobileRemove several dependencies from helmet-csp
helmet-cspframeguard had a documentation error about its default valueframeguard docs in main Helmet readme said frameguard, not helmet.frameguardcsp lets you dynamically set reportOnly
csp lets you dynamically set reportOnlyPass configuration to enable/disable default middlewares
dnsPrefetchControl middleware is now enabled by defaultframeguard can no longer be initialized with strings; you must use an objecthpkp lowercase in documentationhpkp spec URL in readmesframeguard header name in readmehpkp has a setIf option to conditionally set the header
hpkp has a setIf option to conditionally set the headercsp now has a browserSniff option to disable all user-agent sniffing
csp now has a browserSniff option to disable all user-agent sniffingframeguard can now be initialized with optionsnpmignore file to speed up installs slightly### Added - Code of conduct - dnsPrefetchControl middleware ### Fixed - csp readme had syntax errors
dnsPrefetchControl middlewarecsp readme had syntax errorscsp wouldn't recognize IE Mobile browsers
csp wouldn't recognize IE Mobile browserscsp had some errors in its readmecsp with no User Agent would cause errors
csp with no User Agent would cause errorscsp module supports dynamically-generated values
csp module supports dynamically-generated valuescsp directives are now under the directives keyhpkp's Report-Only header is now opt-in, not opt-outcrossdomain middlewarecsp no longer throws errors when some directives aren't quoted ('self', for example)maxage option in the hpkp middlewaresafari5 option from csp moduleunsafe-inline and unsafe-evalcsp policies is no longer recursivehpkp allows a report-uri without the Report-Only header
hpkp allows a report-uri without the Report-Only headernocache now sends the Surrogate-Control header
nocache now sends the Surrogate-Control headernocache no longer contains the private directive in the Cache-Control headerxssFilter now has a function name
xssFilter now has a function nameincludeSubdomains to includeSubDomainsNothing published for this version
csp now supports Microsoft Edge
csp now supports Microsoft Edgeconnect to 3.4.0depd to 1.1.0license key to csp's package.jsoncsp directives now support every directive, not just sandboxAdd "Handling CSP violations" to csp readme
csp readmepackage.jsonhpkp had a link to the wrong place in its readmehpkp requires 2 or more pinshpkp might have miscalculated maxAge slightly wrongNothing published for this version
nocache adds private to its Cache-Control directive
nocache adds private to its Cache-Control directivepackage.jsonDeprecated crossdomain middleware
crossdomain middlewarecrossdomain is no longer a default middlewareUpdated all outdated dependencies (insofar as possible)
Travis CI should test 0.10 and 0.12
hpkp middleware### Changed - Improved xssFilter performance - Updated Lodash versions
xssFilter performance"Other recommended modules" in README
frameguard middleware exported a function called xframeYou can disable csp for Android
csp for Androidcsp on Chrome Mobile on Android and iOSnocache should force revalidation
nocache should force revalidationplatform version in CSP and X-XSS-Protection
platform version in CSP and X-XSS-Protection### Changed - Updated Connect version ### Fixed - Fixed minor csp bugfixes
csp bugfixesUpdated URLs in package.json for new URL
package.json for new URLMost middlewares have some aliases now
xframe now called frameguard (though xframe still works)frameguard chooses sameorigin by defaultframeguard understands "SAME-ORIGIN" in addition to "SAMEORIGIN"nocache removed from default middleware stack### Added - Support preload in HSTS header
Use helmet-crossdomain to test the waters
nocache now sets the Expires and Pragma headers
nocache now sets the Expires and Pragma headersnocache now allows you to crush ETagsAll middleware functions are named
helmet() was having issuesThis changelog was created after the release of 0.3.1.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →