Repository navigation
fix(deps): update dependency content-type to v3 - #8472
Closed
renovate[bot] wants to merge 1 commit into
Closed
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Member
|
needs a fix here: |
renovate
Bot
force-pushed
the
renovate/content-type-3.x
branch
from
September 4, 2026 15:05
bcc0143 to
55b5c69
Compare
renovate
Bot
force-pushed
the
renovate/content-type-3.x
branch
3 times, most recently
from
September 10, 2026 15:19
ddf04ec to
f7debec
Compare
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
renovate
Bot
force-pushed
the
renovate/content-type-3.x
branch
4 times, most recently
from
September 20, 2026 20:00
f885d67 to
534b6ba
Compare
renovate
Bot
force-pushed
the
renovate/content-type-3.x
branch
2 times, most recently
from
October 1, 2026 07:41
f98886f to
b5eeed8
Compare
renovate
Bot
force-pushed
the
renovate/content-type-3.x
branch
from
October 5, 2026 16:04
b5eeed8 to
9cd3b64
Compare
sarahetter
pushed a commit
that referenced
this pull request
Oct 6, 2026
…tly (#8572) Opened by Netliloop run [#392](https://netliloop.netlify.app/#/runs/392) (security-scan), asked in [Slack](https://slack.com/archives/C095D1JL480/p1791299459766719?thread_ts=1791298825.895999&cid=C095D1JL480) ### Why - Renovate's [#8472](#8472) (`content-type` v1 → v3) fails every build job: v3 is ESM-only, has no default export, and `parse()` takes a header string instead of a request object, so `src/utils/proxy.ts` and `src/lib/functions/form-submissions-handler.ts` no longer compile. Its sibling [#8377](#8377) (`@types/content-type` v2) fails lint on its own because v2 is a stub pointing at the package's bundled types. - Both PRs have re-run and failed on every weekly rebase since July; together they account for 64 + 40 failed integration jobs in the last four weeks. ### What changed - `content-type` goes to `^3.1.1` and `@types/content-type` is removed (v3 ships its own types). - The three call sites import `parse` by name and pass `req.headers['content-type']`. The proxy already guarded on the header being present; the form handler now defaults a missing header to `''`, which parses to an empty type and falls through to neither form branch, matching the proxy's guard. - Behaviour change to know about: v3 `parse()` never throws on a string, where v1 threw `TypeError` on a missing or malformed header. In `src/utils/proxy.ts` that TypeError was an unhandled rejection that crashed `netlify dev` on any POST with a malformed `Content-Type`; now such a request proxies normally and gets the static server's 405 (the new test covers this). The proxy only forwards form content types to the form handler, so the handler's own `?? ''` is reached only when the functions server is called directly; there a missing header now takes the existing `Invalid Content-Type` warn-and-continue branch instead of throwing. - A `charset` parameter is passed through to `raw-body` exactly as before: v1 also accepted any token value there, so `charset=bogus` still ends in `raw-body`'s 415. - All three call sites use the same `req.headers['content-type'] ?? ''` idiom. - Root `node_modules/content-type` is now the ESM-only v3; `npm ls content-type` shows `express`, `body-parser`, `type-is` and verdaccio each keep a nested v1/v2 copy, so no CommonJS `require('content-type')` resolves to v3. - Supersedes #8472 and #8377, which can be closed when this merges. ### How we verified - `npm run build`, `npm run typecheck`, `npm run lint`: all exit 0 (on #8472 the build fails with TS1192 and TS2345). - `CI=true npm run test:unit`: 80 files passed. - New integration test `should keep serving when a form submission carries a malformed content type`: a POST with `Content-Type: not/a valid; ;;` and a POST with no `Content-Type` at all (sent as a Buffer body, since node-fetch adds `text/plain` to a string body) must each get a 405 and the next GET a 200. On `main` it fails with `request to http://localhost:33773/ failed, reason: socket hang up` because the unhandled TypeError from `content-type@1` kills the dev server; on this branch it passes (5.5 s). - `CI=true npx vitest run --retry=3 tests/integration/commands/dev/dev-forms-and-redirects.test.ts` with the new test included: 14 passed (14). - End to end with the built CLI (`node bin/run.js dev --offline`) against a fixture with a `submission-created` function, [commands and output here](https://netliloop.netlify.app/api/files/eyJrZXkiOiJldmlkZW5jZS8zOTIvZWZjYTE0YzgtYTFiMy00MzFjLWJmNjUtNzkzODA2ZGRlOTFiIiwibmFtZSI6ImNvbnRlbnQtdHlwZS12My1kZXYtZm9ybS1yZWNlaXB0cy50eHQiLCJ0eXBlIjoidGV4dC9wbGFpbiIsImV4cCI6MTgyMjgzNjk3OTIwNX0.f3ULpDp40grpAemeOoh55S3xXaZNBT5HVHJOjsr7JuE): a urlencoded POST and a multipart POST with a file attachment both reached the function with the parsed fields (200, function log shows the fields); POSTs with no `Content-Type`, a malformed one, and `application/json` were not treated as forms (405) and a GET afterwards returned 200; `application/x-www-form-urlencoded; charset=UTF-8` still matched. ### What is left to test - Nothing. CI ran the full matrix on the final commit: 35 checks, all green (unit on ubuntu/macOS/Windows, 8 integration shards, e2e, lint, format, typecheck, verify-docs, package-size). ### Risk `low`: one narrow code path in `netlify dev` (form-submission routing), covered by the integration test and the end-to-end check above; a wrong result shows immediately as a form POST not reaching the handler. No Linear issue: a self-contained dependency fix the CLI team can merge from this description. 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: Netliloop <netliloop@netlify.com>
Contributor
|
Obsolete: content-type v3 landed in #8572. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^1.0.5→^3.0.0Release Notes
jshttp/content-type (content-type)
v3.1.1Compare Source
Added
v3.1.0Compare Source
Improved
isTypeValidandisTokenValidutilitiesparseperf using bitwise flags (#76)parameters: falsev3.0.0Compare Source
This is an ESM only release. The API is unchanged since the latest
2.xrelease.Changed
v2.1.0Compare Source
Added
comma: true(#72)181e947v2.0.0Compare Source
Rewrite package to be 3x faster and support lenient parsing. No longer errors during
parse, so you must validate things liketypeafter parsing before using it blindly.Changed
ac5ba17427eb1bAdded
5f65f1cparameters: falseto only extracttypewhen parsingConfiguration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.