expressjs/multer
66.7
Adequate · 2 October 2026
930
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a Node.js middleware library designed to handle multipart/form-data file uploads. It provides configurable storage engines for saving files to disk or keeping them in memory, along with robust validation and error handling for upload limits and malformed requests. The library also supports dynamic configuration and integration with modern frontend APIs for sending blobs and images.
Features
Add FormData upload examples for blobs and images
Added two new example projects, FormDataBlob and FormDataImage, to demonstrate how to send file data to a server using the FormData API. The FormDataBlob example shows how to construct a Blob from text and upload it, while the FormDataImage example demonstrates uploading a file selected via an input element. Both examples include a Node.js/Express backend using multer for handling the uploads and a frontend HTML/JS client.
examples · high confidence
New disk and memory storage engines
The library now includes dedicated storage engines for saving uploaded files to disk or keeping them in memory. The disk storage engine writes files to a specified destination (defaulting to the system temp directory) with configurable filename generation and an optional fsync flush to ensure data durability before the upload callback completes. The memory storage engine buffers the entire file content in RAM, allowing access via the file object's buffer property, which is useful for small files but requires monitoring memory usage via limits.
storage · high confidence
Behavioural changes
Multer 2.4.0 release with security fixes and API enhancements
This release introduces Multer 2.4.0, which addresses [CVE redacted] and adds several functional improvements. Users can now pass a function to the \limits\ option to set limits dynamically per request, and the \DiskStorage\ engine supports an opt-in \flush\ option to fsync files before completion. The library now exposes busboy's \defCharset\, \highWaterMark\, and \fileHwm\ options, and includes a \streamHandler\ option to support pre-consumed bodies (e.g., for Google Cloud Functions). Error handling is improved with \filename\ included in \LIMIT\_FILE\_SIZE\ and \LIMIT\_UNEXPECTED\_FILE\ errors, and field names are now decoded to match \file.originalname\. Additionally, files skipped by \fileFilter\ no longer count towards \maxCount\, and the library rejects non-integer limit values at construction time.
(repo-wide) · high confidence
Multer library refactored with new internal modules and improved error handling
The lib directory has been restructured into distinct modules: counter.js tracks pending operations, file-appender.js manages how uploaded files are attached to the request object, multer-error.js defines a custom error class with specific codes (like LIMIT\_FILE\_SIZE and MISSING\_FIELD\_NAME), remove-uploaded-files.js handles cleanup, and validate-limits.js ensures limit configurations are valid integers. The main make-middleware.js now uses these components to handle multipart uploads, including decoding WHATWG-escaped filenames, preserving async context, and managing busboy limits more precisely.
lib · high confidence
Test coverage
1 commit adding/updating tests in test/files; Expanded test coverage for upload aborts, storage flush, and field limits.
Dependencies
Multer 2.4.0 release with updated dependencies
This release updates the multer package to version 2.4.0 and refreshes its dependency tree, notably upgrading busboy to ^1.6.0 and type-is to ^1.6.18. It also adds funding information via OpenCollective and sets the minimum Node.js engine requirement to 10.16.0. Additionally, new example projects (FormDataBlob and FormDataImage) are introduced, demonstrating usage with Express 5.1.0 and multer 2.3.0.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 66 → 67 (+0.3)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 65 → 65 (+0.6)
- Architecture 69 → 69 (+0.0)
- Maturity 65 → 65 (-0.1)
- Readiness 67 → 67 (+0.0)
- Security 86 → 89 (+2.7)
Findings
- No change — the same findings as the prior survey.
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
expressjs/multer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 35979e5afbb814bdb4b750ce028b125eb84c53af — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.