Skip to content

Releases: fastify/fastify-static

v10.1.5

Choose a tag to compare

@Eomm Eomm released this 26 Sep 07:37
2f0953a

What's Changed

  • fix: use registered root for relative downloads by @lprnmns in #610

New Contributors

Full Changelog: v10.1.4...v10.1.5

v10.1.4

Choose a tag to compare

@mcollina mcollina released this 17 Sep 07:47
a39a464

This is a security release for GHSA-r799-r9gc-m956 (CVE-2026-90982).

It fixes a route guard and allowedPath bypass on case-insensitive filesystems. Users should upgrade to @fastify/static 10.1.4.

Full Changelog: v10.1.3...v10.1.4

v10.1.3

Choose a tag to compare

@Tony133 Tony133 released this 19 Aug 15:17

What's Changed

  • chore: bump c8 from 11.0.0 to 12.0.0 by @dependabot[bot] in #602
  • chore(.npmrc): add min-release-age by @Fdawgs in #603
  • chore: bump fastify/workflows/.github/workflows/lock-threads.yml from 6.0.0 to 7.0.0 by @dependabot[bot] in #605

Full Changelog: v10.1.2...v10.1.3

v10.1.2

Choose a tag to compare

@mcollina mcollina released this 22 Jul 09:44
7a9d1c6

⚠️ Security Release

What's Changed

Full Changelog: v10.1.1...v10.1.2

v10.1.1

Choose a tag to compare

@mcollina mcollina released this 22 Jul 07:54
3733059

⚠️ Security Release

What's Changed

Full Changelog: v10.1.0...v10.1.1

v10.1.0

Choose a tag to compare

@climba03003 climba03003 released this 11 Jul 13:51
36c939d

What's Changed

  • fix: set Vary: Accept-Encoding for preCompressed responses by @LeSingh1 in #586
  • feat: use @fastify/error for errors and add option suppressWarning by @climba03003 in #599

New Contributors

Full Changelog: v10.0.0...v10.1.0

v10.0.0

Choose a tag to compare

@climba03003 climba03003 released this 11 Jul 10:44
babf6df

Breaking Changes

  • setHeaders now using FastifyReply instead of Response.

You should refactor your code to use the reply helpers.
For example,

// Before
const fastify = require('fastify')({logger: true})
const path = require('node:path')

fastify.register(require('@fastify/static'), {
  root: path.join(__dirname, 'public'),
  prefix: '/public/', // optional: default '/',
  setHeaders(res) {
    res.setHeader('X-Test', 'Foo')
  }
})
// After
const fastify = require('fastify')({logger: true})
const path = require('node:path')

fastify.register(require('@fastify/static'), {
  root: path.join(__dirname, 'public'),
  prefix: '/public/', // optional: default '/',
  setHeaders(reply) {
    reply.header('X-Test', 'Foo')
  }
})

What's Changed

New Contributors

Full Changelog: v9.3.0...v10.0.0

v9.3.0

Choose a tag to compare

@Eomm Eomm released this 08 Jul 16:09
ad05a27

What's Changed

  • chore: update fastify-plugin dependency to version 6.0.0 by @Puppo in #594

New Contributors

Full Changelog: v9.2.0...v9.3.0

v9.2.0

Choose a tag to compare

@Eomm Eomm released this 08 Jul 15:39
a343813

What's Changed

  • chore(.gitattributes): retain binary file eol style by @Fdawgs in #577
  • refactor(types): migrate from tsd to tstyche by @Tony133 in #579
  • fix: propagate return value from fastify.errorHandler by @abdulmunimjemal in #582
  • chore: update depedabot setting by @climba03003 in #583
  • chore: bump @fastify/compress from 8.3.1 to 9.0.0 by @dependabot[bot] in #590
  • chore: bump @types/node from 25.9.4 to 26.0.0 in the dev-dependencies-typescript group by @dependabot[bot] in #592
  • docs: fix broken links by @Fdawgs in #591
  • docs: clarify precompressed allowedPath behavior by @mcollina in #593

New Contributors

Full Changelog: v9.1.3...v9.2.0

v9.1.3

Choose a tag to compare

@mcollina mcollina released this 21 Apr 07:42
880c1a6

What's Changed

  • fix: support wildcard prefixes with route params by @mcollina in #576

Full Changelog: v9.1.2...v9.1.3