Express v5
expressjs.com
expressjs.com
This footgun can be easily avoided without ripping out regex support altogether. Just switch to a regex engine that is actually regular, like re2.
See also "Regular Expression Matching Can Be Simple And Fast" by rsc [1].
> Before going into the changes in this release, let’s address why it was released v5 on the next dist-tag. As part of reviving the project, we started a Security working group and security triage team to address the growing needs around open source supply chain security. We undertook a security audit (more details to come on that) and uncovered some problems that needed to be addressed. Thus, in addition to the “normal” work done in public issues, we also did a lot of security work in private forks. This security work required orchestration when releasing, to ensure the code and CVE reports went out together. You can find a summary of the most recent vulnerabilities patched in our security release notes.
>
> While we weren’t able to simultaneously release v5, this blog post, the changelog, and documentation, we felt it was most important to have a secure and stable release.
>
> As soon as possible, we’ll provide more details on our long-term support (LTS) plans, including when the release will move from next to latest. For now, if you are uncomfortable being on the bleeding edge (even if it is a rather dull edge) then you should wait to upgrade until the release is tagged latest. That said, we look forward to working with you to address any bugs you encounter as you upgrade.Kudos to the team for pushing express forward!
Nearly everything else these days has a route that takes a request and returns a response. This matches HTTP more closely.
All that was old will be new again.
Personally I like to strip all the excess data as soon as possible and expose the raw response as a plain “transfer-encoding: chunked” stream. That way the client can decide if they want to accept each chunk as they come or simply await the whole response with limited code change.
Either way, being able to easily pass the response writer around and set headers, write, close, as needed without being tied to a single function’s control flow is nice. It can be done in the more modern frameworks ofc, but ends up being a bit more machinery required at each endpoint.
I haven't done it though, I used to really like SSE (it's a little more REST-y) but the world seems to have decided on websockets.
https://fastify.dev/docs/latest/Guides/Getting-Started/#your...
Maybe there are more API changes planned for v6 and v5 is the stepping stone?
Many thanks to the Express devs! It's been a reliable part of the stack for a long time.
For personal projects, I've been loving https://hono.dev/ The DX is fantastic and it runs in bun and CloudFlare workers. Shoutout to the hono developers!
For larger team projects, I end up using Fastify and NextJS. No real reason other than it's what's already running or other devs on the projects prefer it. But Express is always a great option.
I am really confused by this. Is it really that stable ? For any software that was released this back, I would have thought its abandoned. Are there no features that the community had demanded in this time
I switched from classic .NET Framework because they deprecated WinForms and WPF was not usable and they churned the entire damn platform and replaced it with alpha-quality software. How many UI frameworks, and how much other churn happened in the past 11 years there? Way too much, everybody is so fed up that the past decade of my career consisted of rewriting desktop apps to this stack.
NPM makes it quite easy to publish anything and for others to start using it. Just don't, stick with the proven solutions. There's - adjusted for user base - the same or worse amount of churn on Pypi and Nuget. If you wouldn't choose a random library nobody uses in the C# land, don't do it in the Node land. At least the Node libs continue to grow, while the Nuget stuff continues to die.
Read this line on Wiki: "In Perl 6, we decided it would be better to fix the language than fix the user - Larry wall"
Looks like a very good philosophical statement. Maybe there's a lesson here for other programming language
( The other Perl slogan: "Easy things should be easy and hard things should be possible" is also really good )
From what I read, it's a living, breathing language with innovative features, core developers, regular releases and a healthy community of users. What more do you want?