What's Changed
Fixed
- Smoke test regression: Upgraded
expressto v5 intest-app-node-express— thepath-to-regexp >=8.4.0security override broke express 4.x, which calls thepathRegexpnamed export removed in 8.4.0. Express 5 uses path-to-regexp 8.4+ natively.
Changed
- Security hardening: Patched all 54 Dependabot security alerts via
pnpm.overridesin the rootpackage.json. Affected packages include:tar,esbuild,webpack,cookie,minimatch,rollup,ajv,qs,devalue,hono,@angular/core,@angular/compiler,@sveltejs/kit,svelte,nanotar,simple-git,@hono/node-server,defu,elysia,h3,immutable,lodash,node-forge,path-to-regexp,picomatch,serialize-javascript,svgo,undici,vite,brace-expansion,fastify,file-type,next,srvx,unhead, andyaml.pnpm auditreports no known vulnerabilities.
Full Changelog: https://github.com/logtide-dev/logtide-javascript/blob/main/CHANGELOG.md#072---2026-04-07