Skip to content

chore(deps): update dependency @types/content-type to v2 - #8377

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/content-type-2.x
Closed

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/content-type-2.x

Conversation

@renovate

@renovate renovate Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@​types/content-type ^1.1.9 → ^2.0.0 age confidence

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Jul 27, 2026
@renovate
renovate Bot requested a review from a team as a code owner July 27, 2026 17:40
@renovate renovate Bot added javascript Pull requests that update Javascript code dependencies Pull requests that update a dependency file labels Jul 27, 2026
kodiakhq[bot]
kodiakhq Bot previously approved these changes Jul 27, 2026
@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch from 5b858fa to c457b2b Compare July 30, 2026 15:24
@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch from c457b2b to 79b0053 Compare August 12, 2026 03:36
@github-actions

github-actions Bot commented Aug 12, 2026 •

Copy link
Copy Markdown

📊 Benchmark results

Comparing with 9fa2967

  • Dependency count: 1,018 (no change)
  • Package size: 381 MB (no change)
  • Number of ts-expect-error directives: 331 (no change)

kodiakhq[bot]
kodiakhq Bot previously approved these changes Aug 14, 2026
kodiakhq[bot]
kodiakhq Bot previously approved these changes Aug 17, 2026
kodiakhq[bot]
kodiakhq Bot previously approved these changes Aug 19, 2026
kodiakhq[bot]
kodiakhq Bot previously approved these changes Aug 19, 2026
@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch from 492c18e to 49a0437 Compare August 23, 2026 23:35
@renovate renovate Bot changed the title fix(deps): update dependency content-type to v2 chore(deps): update dependency @types/content-type to v2 Aug 23, 2026
@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch from 49a0437 to f02b254 Compare August 26, 2026 12:07
@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch 4 times, most recently from da18e2b to a7305ed Compare September 3, 2026 15:50
@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch 3 times, most recently from f660d02 to cb1b1d4 Compare September 10, 2026 15:18
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8b80a180-482c-4210-a5ff-e9eb37957306

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch from cb1b1d4 to 50a92e7 Compare September 15, 2026 09:17
@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch 2 times, most recently from 5a061e2 to f615ad1 Compare October 1, 2026 07:41
@renovate
renovate Bot force-pushed the renovate/content-type-2.x branch from f615ad1 to 0875666 Compare October 5, 2026 16:03
sarahetter pushed a commit that referenced this pull request Oct 6, 2026
…tly (#8572)

Opened by Netliloop run [#392](https://netliloop.netlify.app/#/runs/392)
(security-scan), asked in
[Slack](https://slack.com/archives/C095D1JL480/p1791299459766719?thread_ts=1791298825.895999&cid=C095D1JL480)

### Why

- Renovate's [#8472](#8472)
(`content-type` v1 → v3) fails every build job: v3 is ESM-only, has no
default export, and `parse()` takes a header string instead of a request
object, so `src/utils/proxy.ts` and
`src/lib/functions/form-submissions-handler.ts` no longer compile. Its
sibling [#8377](#8377)
(`@types/content-type` v2) fails lint on its own because v2 is a stub
pointing at the package's bundled types.
- Both PRs have re-run and failed on every weekly rebase since July;
together they account for 64 + 40 failed integration jobs in the last
four weeks.

### What changed

- `content-type` goes to `^3.1.1` and `@types/content-type` is removed
(v3 ships its own types).
- The three call sites import `parse` by name and pass
`req.headers['content-type']`. The proxy already guarded on the header
being present; the form handler now defaults a missing header to `''`,
which parses to an empty type and falls through to neither form branch,
matching the proxy's guard.
- Behaviour change to know about: v3 `parse()` never throws on a string,
where v1 threw `TypeError` on a missing or malformed header. In
`src/utils/proxy.ts` that TypeError was an unhandled rejection that
crashed `netlify dev` on any POST with a malformed `Content-Type`; now
such a request proxies normally and gets the static server's 405 (the
new test covers this). The proxy only forwards form content types to the
form handler, so the handler's own `?? ''` is reached only when the
functions server is called directly; there a missing header now takes
the existing `Invalid Content-Type` warn-and-continue branch instead of
throwing.
- A `charset` parameter is passed through to `raw-body` exactly as
before: v1 also accepted any token value there, so `charset=bogus` still
ends in `raw-body`'s 415.
- All three call sites use the same `req.headers['content-type'] ?? ''`
idiom.
- Root `node_modules/content-type` is now the ESM-only v3; `npm ls
content-type` shows `express`, `body-parser`, `type-is` and verdaccio
each keep a nested v1/v2 copy, so no CommonJS `require('content-type')`
resolves to v3.
- Supersedes #8472 and #8377, which can be closed when this merges.

### How we verified

- `npm run build`, `npm run typecheck`, `npm run lint`: all exit 0 (on
#8472 the build fails with TS1192 and TS2345).
- `CI=true npm run test:unit`: 80 files passed.
- New integration test `should keep serving when a form submission
carries a malformed content type`: a POST with `Content-Type: not/a
valid; ;;` and a POST with no `Content-Type` at all (sent as a Buffer
body, since node-fetch adds `text/plain` to a string body) must each get
a 405 and the next GET a 200. On `main` it fails with `request to
http://localhost:33773/ failed, reason: socket hang up` because the
unhandled TypeError from `content-type@1` kills the dev server; on this
branch it passes (5.5 s).
- `CI=true npx vitest run --retry=3
tests/integration/commands/dev/dev-forms-and-redirects.test.ts` with the
new test included: 14 passed (14).
- End to end with the built CLI (`node bin/run.js dev --offline`)
against a fixture with a `submission-created` function, [commands and
output
here](https://netliloop.netlify.app/api/files/eyJrZXkiOiJldmlkZW5jZS8zOTIvZWZjYTE0YzgtYTFiMy00MzFjLWJmNjUtNzkzODA2ZGRlOTFiIiwibmFtZSI6ImNvbnRlbnQtdHlwZS12My1kZXYtZm9ybS1yZWNlaXB0cy50eHQiLCJ0eXBlIjoidGV4dC9wbGFpbiIsImV4cCI6MTgyMjgzNjk3OTIwNX0.f3ULpDp40grpAemeOoh55S3xXaZNBT5HVHJOjsr7JuE):
a urlencoded POST and a multipart POST with a file attachment both
reached the function with the parsed fields (200, function log shows the
fields); POSTs with no `Content-Type`, a malformed one, and
`application/json` were not treated as forms (405) and a GET afterwards
returned 200; `application/x-www-form-urlencoded; charset=UTF-8` still
matched.

### What is left to test

- Nothing. CI ran the full matrix on the final commit: 35 checks, all
green (unit on ubuntu/macOS/Windows, 8 integration shards, e2e, lint,
format, typecheck, verify-docs, package-size).

### Risk

`low`: one narrow code path in `netlify dev` (form-submission routing),
covered by the integration test and the end-to-end check above; a wrong
result shows immediately as a form POST not reaching the handler. No
Linear issue: a self-contained dependency fix the CLI team can merge
from this description.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Netliloop <netliloop@netlify.com>
@sarahetter

Copy link
Copy Markdown
Contributor

Obsolete: @types/content-type was removed in #8572 (content-type v3 ships its own types).

@sarahetter sarahetter closed this Oct 6, 2026
@renovate
renovate Bot deleted the renovate/content-type-2.x branch October 6, 2026 16:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant