update proxy-addr dependency (CVE noise prevention)
Author: hoerupCreated Sep 15, 2026Updated Sep 15, 2026
Labels4.x5.xdepsgood first contribution
current express depends on proxy-addr 2.0.7 which is vulnerable to https://www.cve.org/CVERecord?id=CVE-2026-90711
please update to 2.0.8
Source: expressjs/express