Releases: fastify/fastify-static
Releases · fastify/fastify-static
Release list
v10.1.5
v10.1.4
This is a security release for GHSA-r799-r9gc-m956 (CVE-2026-90982).
It fixes a route guard and allowedPath bypass on case-insensitive filesystems. Users should upgrade to @fastify/static 10.1.4.
Full Changelog: v10.1.3...v10.1.4
v10.1.3
What's Changed
- chore: bump c8 from 11.0.0 to 12.0.0 by @dependabot[bot] in #602
- chore(.npmrc): add min-release-age by @Fdawgs in #603
- chore: bump fastify/workflows/.github/workflows/lock-threads.yml from 6.0.0 to 7.0.0 by @dependabot[bot] in #605
Full Changelog: v10.1.2...v10.1.3
v10.1.2
v10.1.1
v10.1.0
What's Changed
- fix: set Vary: Accept-Encoding for preCompressed responses by @LeSingh1 in #586
- feat: use
@fastify/errorfor errors and add optionsuppressWarningby @climba03003 in #599
New Contributors
Full Changelog: v10.0.0...v10.1.0
v10.0.0
Breaking Changes
setHeadersnow usingFastifyReplyinstead ofResponse.
You should refactor your code to use the reply helpers.
For example,
// Before
const fastify = require('fastify')({logger: true})
const path = require('node:path')
fastify.register(require('@fastify/static'), {
root: path.join(__dirname, 'public'),
prefix: '/public/', // optional: default '/',
setHeaders(res) {
res.setHeader('X-Test', 'Foo')
}
})
// After
const fastify = require('fastify')({logger: true})
const path = require('node:path')
fastify.register(require('@fastify/static'), {
root: path.join(__dirname, 'public'),
prefix: '/public/', // optional: default '/',
setHeaders(reply) {
reply.header('X-Test', 'Foo')
}
})What's Changed
- chore!: bump content-disposition fom 1.0.1 to 2.0.1 by @climba03003 in #597
- fix: ignore unsupported deflate for precompressed assets by @jibin7jose in #596
- fix!: allow setHeaders to override send headers by @climba03003 in #598
New Contributors
- @jibin7jose made their first contribution in #596
Full Changelog: v9.3.0...v10.0.0
v9.3.0
v9.2.0
What's Changed
- chore(.gitattributes): retain binary file eol style by @Fdawgs in #577
- refactor(types): migrate from tsd to tstyche by @Tony133 in #579
- fix: propagate return value from fastify.errorHandler by @abdulmunimjemal in #582
- chore: update depedabot setting by @climba03003 in #583
- chore: bump @fastify/compress from 8.3.1 to 9.0.0 by @dependabot[bot] in #590
- chore: bump @types/node from 25.9.4 to 26.0.0 in the dev-dependencies-typescript group by @dependabot[bot] in #592
- docs: fix broken links by @Fdawgs in #591
- docs: clarify precompressed allowedPath behavior by @mcollina in #593
New Contributors
- @abdulmunimjemal made their first contribution in #582
Full Changelog: v9.1.3...v9.2.0