Skip to content

Bump multer and multer-gridfs-storage - #190

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-0f401cb448
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-0f401cb448

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 10, 2026 •

Copy link
Copy Markdown

PR 190 Large dependabot[bot] Test plan 36784 Completed Powered by Pull Request Badge

Bumps multer and multer-gridfs-storage. These dependencies needed to be updated together.
Updates multer from 1.4.4 to 2.3.0

Release notes

Sourced from multer's releases.

v2.3.0

Important

What's Changed

New Contributors

... (truncated)

Changelog

Sourced from multer's changelog.

2.3.0

2.2.0

2.1.1

2.1.0

2.0.2

2.0.1

2.0.0

1.4.5-lts.2

... (truncated)

Commits
  • 4e8edf5 2.3.0 (#1455)
  • 87a584e fix: reject invalid field names instead of crashing on append-field errors
  • ab6aeae fix: enforce file size limit with async fileFilter
  • eef7444 fix: destroy disk write stream on aborted uploads to prevent fd leak
  • 25ec9bb docs: refresh all README translations (#1462)
  • 73c1759 feat: add an opt-in fieldArrayIndexLimit (#1438)
  • ece6735 Update 'README-zh-cn.md' up to now (#1264)
  • 3278e1b docs: add Japanese translation to README (#1354)
  • 3c0bc5e test: accept files exactly at fileSize limit (#1382)
  • b6d84b0 docs: add Indonesian translation for README (#1431)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for multer since your current version.


Updates multer-gridfs-storage from 5.0.2 to 6.2.1

Release notes

Sourced from multer-gridfs-storage's releases.

v6.2.0

  • Fixed: An upload that failed mid-stream could leave orphaned chunks in GridFS. Failed writes now call abort() on the GridFS write stream so any chunks already written are cleaned up.
  • Fixed: An upload no longer hangs forever if the client aborts the request mid-stream. pump's premature-close callback is now handled, and settling the upload (resolving or rejecting) is guarded against firing twice.

Full Changelog: devconcept/multer-gridfs-storage@v6.1.0...v6.2.0

v6.1.0

Some of the changes below are driven by the mongodb Node.js driver dropping GridFS fields it no longer persists. If you relied on contentType or aliases, see the migration notes in each entry.

  • Removed: The contentType file option and the contentType property on the uploaded file (req.file.contentType). Recent versions of the mongodb driver no longer persist a native contentType field on the GridFS file document — it was deprecated from the GridFS specification — so the value was never actually stored. Use the file's metadata for a per-file content type that is saved and queryable; the content type sent by the client is still available as Multer's req.file.mimetype.
  • Removed: The aliases file option. As with contentType, the mongodb driver no longer stores the GridFS aliases field, so the option was silently ignored and never appeared on the uploaded file.
  • Removed: The NodeCallback type export. The storage engine's _handleFile and _removeFile callbacks now derive their signatures directly from Multer's StorageEngine interface.
  • Added: A GridFsStorageInstance type export so a storage instance can be annotated directly (for example let storage: GridFsStorageInstance). The GridFsStorage export remains the callable value used to create engines.
  • Changed: Improved the TypeScript types. The file option and the object it returns are now fully typed (FileOption / FileConfig) instead of any, the uploaded file's metadata is typed Document | null to match the value the engine emits, and the storage's error property is now Error | null instead of unknown.
  • Changed: The README examples now use ESM import syntax; require still works for CommonJS projects.

Full Changelog: devconcept/multer-gridfs-storage@v6.0.0...v6.1.0

v6.0.0

This is a major release. Upgrading requires Node.js 22 or newer, installing mongodb yourself, and Multer 2. See the breaking changes below.

  • Breaking: Raised the minimum supported Node.js version to 22.
  • Breaking: mongodb is now a peer dependency (^7.5.0) instead of a bundled dependency. Install it alongside this package. The bundled @types/mongodb and @types/express type packages were removed because the mongodb driver now ships its own types, which also resolves the type conflicts reported in #529, #554 and #502.
  • Breaking: Raised the Multer peer dependency to ^2.2.0, and @types/multer is now a peer dependency (^2.2.0). This clears the install conflicts reported in #517 and #490.
  • Breaking: Removed the client option. The MongoClient is now inferred from the provided db, so it no longer needs to be passed separately.
  • Added: The file option can return a transforms array of transform streams, piped in order between the incoming file and GridFS before it is stored (for example to encrypt or compress uploads). Resolves #405.
  • Removed: Dropped the md5 file property and the disableMD5 file option. MongoDB removed automatic md5 hashing from GridFS in the mongodb Node.js driver 4.0.0 (disableMD5 has had no effect since), so stored files no longer expose an md5 hash.
  • Changed: Replaced the mongodb-uri dependency with mongodb-connection-string-url (the parser used by the mongodb driver itself) for connection string comparison. The database name is now resolved by the driver via client.db() instead of being parsed manually.
  • Changed: The package is now a dual ESM/CommonJS module, built with tshy. It exposes an exports map with both import and require entry points (output moved from lib/ to dist/).
  • Changed: Modernized the test toolchain to run TypeScript through tsx (replacing ts-node), and switched coverage from nyc to c8.
  • Changed: Updated development dependencies to their latest versions (including Express 5, supertest 7 and sinon 22 in the test suite) and migrated ESLint to v10 with a flat eslint.config.js (replacing .eslintrc.json/.eslintignore).
  • Changed: Replaced the unmaintained coveralls package (which pulled in the deprecated request dependency and its security advisories) with Codecov coverage uploads from CI.
  • Removed: Dropped the is-promise dependency; the trivial promise check is now inlined.
  • Fixed: Uploads no longer throw TypeError: Cannot read properties of undefined (reading '_id') with recent MongoDB driver versions (#560). The stored file's id and metadata are read from the write stream's gridFSFile property, and a finish event without a stored file now rejects with an error instead of leaving the request hanging.
Changelog

Sourced from multer-gridfs-storage's changelog.

6.2.1

  • Changed: Dropped the has-own-prop dependency; the test suite now uses the native Object.hasOwn (available since the package's minimum supported Node.js version). It was a runtime dependency used only in tests.
  • Changed: Moved @types/pump from dependencies to devDependencies — it is a compile-time type declaration only and never appears in the public API.
  • Changed: Updated development dependencies to their latest compatible versions.

6.1.0

  • Added: A close() method that detaches a storage from its database connection, removing the dbError listeners it registered on the underlying MongoClient (and its own listeners). Call it for short-lived storages — for example per-request engines — so they no longer accumulate listeners on a shared or cached connection. Previously those listeners were never removed, leaking the storage and eventually triggering a MaxListenersExceeded warning.
  • Changed: Switched the test runner to Vitest.
  • Fixed: The connection cache could assign a new entry the wrong index and overwrite an existing one after an earlier entry for the same url was removed (for example when a cached connection with different options failed). New cache entries now take a fresh index past the highest existing one.
  • Fixed: Connection strings that differ only in a repeated query parameter (for example readPreferenceTags) are no longer treated as the same connection by the cache; duplicate parameters are compared instead of being collapsed.
  • Changed: Passing a database connection whose db is not available yet (an unopened connection) now throws a clear error instead of failing later with a confusing message.
  • Removed: The contentType file option and the contentType property on the uploaded file (req.file.contentType). Recent versions of the mongodb driver no longer persist a native contentType field on the GridFS file document — it was deprecated from the GridFS specification — so the value was never actually stored. Use the file's metadata for a per-file content type that is saved and queryable; the content type sent by the client is still available as Multer's req.file.mimetype.
  • Removed: The aliases file option. As with contentType, the mongodb driver no longer stores the GridFS aliases field, so the option was silently ignored and never appeared on the uploaded file.
  • Removed: The NodeCallback type export. The storage engine's _handleFile and _removeFile callbacks now derive their signatures directly from Multer's StorageEngine interface.
  • Added: A GridFsStorageInstance type export so a storage instance can be annotated directly (for example let storage: GridFsStorageInstance). The GridFsStorage export remains the callable value used to create engines.
  • Changed: Improved the TypeScript types. The file option and the object it returns are now fully typed (FileOption / FileConfig) instead of any, the uploaded file's metadata is typed Document | null to match the value the engine emits, and the storage's error property is now Error | null instead of unknown.
  • Changed: The README examples now use ESM import syntax; require still works for CommonJS projects.

6.0.0

This is a major release. Upgrading requires Node.js 22 or newer, installing mongodb yourself, and Multer 2. See the breaking changes below.

  • Breaking: Raised the minimum supported Node.js version to 22.
  • Breaking: mongodb is now a peer dependency (^7.5.0) instead of a bundled dependency. Install it alongside this package. The bundled @types/mongodb and @types/express type packages were removed because the mongodb driver now ships its own types, which also resolves the type conflicts reported in #529, #554 and #502.
  • Breaking: Raised the Multer peer dependency to ^2.2.0, and @types/multer is now a peer dependency (^2.2.0). This clears the install conflicts reported in #517 and #490.
  • Breaking: Removed the client option. The MongoClient is now inferred from the provided db, so it no longer needs to be passed separately.
  • Added: The file option can return a transforms array of transform streams, piped in order between the incoming file and GridFS before it is stored (for example to encrypt or compress uploads). Resolves #405.
  • Removed: Dropped the md5 file property and the disableMD5 file option. MongoDB removed automatic md5 hashing from GridFS in the mongodb Node.js driver 4.0.0 (disableMD5 has had no effect since), so stored files no longer expose an md5 hash.
  • Changed: Replaced the mongodb-uri dependency with mongodb-connection-string-url (the parser used by the mongodb driver itself) for connection string comparison. The database name is now resolved by the driver via client.db() instead of being parsed manually.
  • Changed: The package is now a dual ESM/CommonJS module, built with tshy. It exposes an exports map with both import and require entry points (output moved from lib/ to dist/).
  • Changed: Modernized the test toolchain to run TypeScript through tsx (replacing ts-node), and switched coverage from nyc to c8.
  • Changed: Updated development dependencies to their latest versions (including Express 5, supertest 7 and sinon 22 in the test suite) and migrated ESLint to v10 with a flat eslint.config.js (replacing .eslintrc.json/.eslintignore).
  • Changed: Replaced the unmaintained coveralls package (which pulled in the deprecated request dependency and its security advisories) with Codecov coverage uploads from CI.
  • Removed: Dropped the is-promise dependency; the trivial promise check is now inlined.
  • Fixed: Uploads no longer throw TypeError: Cannot read properties of undefined (reading '_id') with recent MongoDB driver versions (#560). The stored file's id and metadata are read from the write stream's gridFSFile property, and a finish event without a stored file now rejects with an error instead of leaving the request hanging.
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [multer](https://github.com/expressjs/multer) and [multer-gridfs-storage](https://github.com/devconcept/multer-gridfs-storage). These dependencies needed to be updated together.

Updates `multer` from 1.4.4 to 2.3.0
- [Release notes](https://github.com/expressjs/multer/releases)
- [Changelog](https://github.com/expressjs/multer/blob/main/CHANGELOG.md)
- [Commits](expressjs/multer@v1.4.4...v2.3.0)

Updates `multer-gridfs-storage` from 5.0.2 to 6.2.1
- [Release notes](https://github.com/devconcept/multer-gridfs-storage/releases)
- [Changelog](https://github.com/devconcept/multer-gridfs-storage/blob/master/CHANGELOG.md)
- [Commits](devconcept/multer-gridfs-storage@v5.0.2...v6.2.1)

---
updated-dependencies:
- dependency-name: multer
  dependency-version: 2.3.0
  dependency-type: direct:production
- dependency-name: multer-gridfs-storage
  dependency-version: 6.2.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 10, 2026
@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: a79cf902-44e4-4ef1-8739-5827ddbeb463

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants