chore(dependencies): update dependency fastify to v3.29.4 [security] #307
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.9.2->3.29.4GitHub Vulnerability Alerts
CVE-2022-41919
Impact
The attacker can use the incorrect
Content-Typeto bypass thePre-Flightchecking offetch.fetch()requests with Content-Type’s essence as "application/x-www-form-urlencoded", "multipart/form-data", or "text/plain", could potentially be used to invoke routes that only acceptsapplication/jsoncontent type, thus bypassing any CORS protection, and therefore they could lead to a Cross-Site Request Forgery attack.Patches
For
4.xusers, please update to at least4.10.2For
3.xusers, please update to at least3.29.4Workarounds
Implement Cross-Site Request Forgery protection using
@fastify/csrf.References
Check out the HackerOne report: https://hackerone.com/reports/1763832.
For more information
Fastify security policy
Release Notes
fastify/fastify (fastify)
v3.29.4Compare Source
and CVE-2022-41919
Full Changelog: fastify/fastify@v3.29.3...v3.29.4
v3.29.3Compare Source
Security ReleaseThis release backport the fixes of GHSA-455w-c45v-86rg for the v3.x line.
While not being a vulnerability for this line, a backport is still welcome due to the problems highlighted in the report.
Full Changelog: fastify/fastify@v3.29.2...v3.29.3
v3.29.2Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.29.1...v3.29.2
v3.29.1Compare Source
What's Changed
@fastify/*modules by @Fdawgs in #3860New Contributors
Full Changelog: fastify/fastify@v3.29.0...v3.29.1
v3.29.0Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.28.0...v3.29.0
v3.28.0Compare Source
What's Changed
requestproperties by @sumbad in #3787Full Changelog: fastify/fastify@v3.27.4...v3.28.0
v3.27.4Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.27.3...v3.27.4
v3.27.3Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.27.2...v3.27.3
v3.27.2Compare Source
What's Changed
standardlinting by @Divlo in #3682test:ciinstead oftestby @Divlo in #3692New Contributors
Full Changelog: fastify/fastify@v3.27.1...v3.27.2
v3.27.1Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.27.0...v3.27.1
v3.27.0Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.26.0...v3.27.0
v3.26.0Compare Source
What's Changed
fastify.decoratearrow functions with function expressions by @onosendi in #3577custom-parser.test.jsflaky test by @darkgl0w in #3627thisisFastifyInstanceby @darkgl0w in #3622New Contributors
Full Changelog: fastify/fastify@v3.25.3...v3.26.0
v3.25.3Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.25.2...v3.25.3
v3.25.2Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.25.1...v3.25.2
v3.25.1Compare Source
What's Changed
fastify-split-validatorto Ecosystem by @MetCoder95 in #3535/docs/index.mdby @nooreldeensalah in #3557New Contributors
Full Changelog: fastify/fastify@v3.25.0...v3.25.1
v3.25.0Compare Source
What's Changed
middieto core section by @Fdawgs in #3501New Contributors
Full Changelog: fastify/fastify@v3.24.1...v3.25.0
v3.24.1Compare Source
What's Changed
set-cookiesection by @Fdawgs in #3477serializerCompilerby @mm1995tk in #3490New Contributors
Full Changelog: fastify/fastify@v3.24.0...v3.24.1
v3.24.0Compare Source
What's Changed
request.bodycontent and usage by @Fdawgs in #3436New Contributors
Full Changelog: fastify/fastify@v3.23.1...v3.24.0
v3.23.1Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.23.0...v3.23.1
v3.23.0Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.22.1...v3.23.0
v3.22.1Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.22.0...v3.22.1
v3.22.0Compare Source
What's Changed
fastify-supabaseto fastify ecosystem by @darkgl0w in #3348New Contributors
Full Changelog: fastify/fastify@v3.21.6...v3.22.0
v3.21.6Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.21.5...v3.21.6
v3.21.5Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.21.4...v3.21.5
v3.21.4Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.21.3...v3.21.4
v3.21.3Compare Source
What's Changed
Full Changelog: fastify/fastify@v3.21.2...v3.21.3
v3.21.2Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.21.1...v3.21.2
v3.21.1Compare Source
What's Changed
FastifyInstance#setErrorHandlersupports async handlers by @AnnikaCodes in #3309New Contributors
Full Changelog: fastify/fastify@v3.21.0...v3.21.1
v3.21.0Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.20.2...v3.21.0
v3.20.2Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.20.1...v3.20.2
v3.20.1Compare Source
What's Changed
serializerOptsto server option interface by @ddadaal in #3231New Contributors
Full Changelog: fastify/fastify@v3.20.0...v3.20.1
v3.20.0Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v3.19.2...v3.20.0
v3.19.2Compare Source
PR:
Configuration
📅 Schedule: Branch creation - "" in timezone UTC, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.