Skip to content

chore(deps): Bump express-rate-limit from 8.5.2 to 8.6.0#217

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/express-rate-limit-8.6.0
Closed

chore(deps): Bump express-rate-limit from 8.5.2 to 8.6.0#217
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/express-rate-limit-8.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps express-rate-limit from 8.5.2 to 8.6.0.

Release notes

Sourced from express-rate-limit's releases.

v8.6.0

You can view the changelog here.

Commits
  • fffb3c4 8.6.0
  • f366b2d docs: debugging guide, time constants, & v8.6.0 changelog (#652)
  • 593ddd2 fix: make debug output easier to read (#653)
  • ef8c129 fix: Pin safe version of @​asyncapi/specs dev dep (#659)
  • 7b05e0d feat: add time constants to support more readable values for windowMs (#655)
  • 863e730 chore(deps-dev): bump the development-dependencies group with 3 updates (#657)
  • e0e711e fix: correct wording in usage documentation for express-rate-limit (#656)
  • fcd3aa7 chore(deps-dev): bump the development-dependencies group with 3 updates (#651)
  • 99d4298 feat: use debug for debug logging (#641)
  • 23e4dde feat: Run validations once each (#650)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [express-rate-limit](https://github.com/express-rate-limit/express-rate-limit) from 8.5.2 to 8.6.0.
- [Release notes](https://github.com/express-rate-limit/express-rate-limit/releases)
- [Commits](express-rate-limit/express-rate-limit@v8.5.2...v8.6.0)

---
updated-dependencies:
- dependency-name: express-rate-limit
  dependency-version: 8.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 20, 2026
@elnora-automation-bot

Copy link
Copy Markdown
Contributor

Automated Dependency Review

Verdict: SAFE
Ecosystem: pnpm · Bump: minor
Package: express-rate-limit (8.5.2 → 8.6.0)

Rationale

  • Non-breaking per upstream notes
  • CI: build ✓ · test ✓

Recommendation

Merge in the next batch PR.

@elnora-automation-bot elnora-automation-bot Bot added the auto-review: safe Automated review: safe to merge label Jul 21, 2026
rjamul-elnora-ai pushed a commit that referenced this pull request Jul 21, 2026
## Included Bumps

| PR | Ecosystem | Package | Old → New | Type |
|----|-----------|---------|-----------|------|
| #216 | pnpm | @biomejs/biome | 2.5.3 → 2.5.4 | patch |
| #217 | pnpm | express-rate-limit | 8.5.2 → 8.6.0 | minor |

## Skipped — Needs Review

_None._

## Recommended to Close — Major

| PR | Package | Old → New |
|----|---------|-----------|
| #215 | actions/setup-node | 6 → 7 |

## Verification

**pnpm ecosystem**: build ✓ · test ✓

## How to Merge

Merging closes the individual Dependabot PRs above whose changes are now
in main.

Co-authored-by: elnora-automation-bot[bot] <294956319+elnora-automation-bot[bot]@users.noreply.github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

Looks like express-rate-limit is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 21, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/express-rate-limit-8.6.0 branch July 21, 2026 12:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-review: safe Automated review: safe to merge dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants