Skip to content

Conversation

dolevmiz1
Copy link

snyk-top-banner

Snyk has created this PR to upgrade fastify from 4.21.0 to 4.29.1.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 21 versions ahead of your current version.

  • The recommended version was released 22 days ago.

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Improper Validation of Specified Type of Input
SNYK-JS-FASTIFY-9788069
44 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
44 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-FINDMYWAY-8055229
44 No Known Exploit
Release notes
Package name: fastify
  • 4.29.1 - 2025-04-28

    ⚠️ Security Release ⚠️

    Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442.

    Full Changelog: v4.29.0...v4.29.1

  • 4.29.0 - 2024-12-04

    What's Changed

    • fix(backport v4.x): config type in RouteShorthandOptions by @ bastienmenis in #5527
    • feat(backport 4.x): add body parsing on copy move mkcol methods by @ johaven in #5549
    • [Backport 4.x] fix: res serializer not given reply (#5556) by @ github-actions in #5563
    • chore(backport 4.x): allow ! in PR title by @ github-actions in #5572
    • [Backport 4.x] feat: support different body schema per content type by @ github-actions in #5559
    • [Backport 4.x] chore(sponsor): add valtown by @ github-actions in #5593
    • [Backport 4.x] fix: nullish host by @ github-actions in #5594
    • refactor(4.x): add deprecate warning of json shorthand by @ climba03003 in #5587
    • [Backport 4.x] chore(sponsor): add handsontable by @ github-actions in #5595
    • [Backport 4.x] fix: throwing "FST_ERR_DUPLICATED_ROUTE" error instead of raw error by @ github-actions in #5624
    • fix(backport 4.x): reorder handling of Response replies by @ github-actions in #5629
    • [Backport 4.x] docs: add default value for maxParamLength by @ github-actions in #5631
    • [Backport 4.x] chore: fix sponsor link by @ github-actions in #5641
    • [Backport 4.x] feat: add fastify v4 codemods by @ github-actions in #5654
    • [Backport 4.x] feat: bind this to instance in onclose by @ github-actions in #5679
    • [Backport 4.x] docs: update v4 codemods by @ github-actions in #5686

    New Contributors

    Full Changelog: v4.28.1...v4.29.0

  • 4.28.1 - 2024-06-29
  • 4.28.0 - 2024-06-14
  • 4.27.0 - 2024-05-07
  • 4.26.2 - 2024-03-03
  • 4.26.1 - 2024-02-12
  • 4.26.0 - 2024-01-29
  • 4.25.2 - 2023-12-24
  • 4.25.1 - 2023-12-15
  • 4.25.0 - 2023-12-13
  • 4.24.3 - 2023-10-19
  • 4.24.2 - 2023-10-15
  • 4.24.1 - 2023-10-13
  • 4.24.0 - 2023-10-11
  • 4.23.2 - 2023-09-14
  • 4.23.1 - 2023-09-13
  • 4.23.0 - 2023-09-11
  • 4.22.2 - 2023-09-01
  • 4.22.1 - 2023-08-31
  • 4.22.0 - 2023-08-27
  • 4.21.0 - 2023-07-27
from fastify GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade fastify from 4.21.0 to 4.29.1.

See this package in npm:
fastify

See this project in Snyk:
https://app.snyk.io/org/ori-fvw/project/128814a0-c8d3-4d24-9597-563dba4c379f?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants