Skip to content

Releases: fastify/fastify-reply-from

v12.5.0

01 Dec 22:03
e740e22

Choose a tag to compare

⚠️ Security Release ⚠️

By crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from.

Read more at GHSA-2q7r-29rg-6m5h. This is catalogued as CVE-2025-66415.

What's Changed

  • Add test for text/event-stream proxying with custom parser by @mcollina in #438

Full Changelog: v12.4.0...v12.5.0

v12.4.0

03 Nov 10:13
bb232f5

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v12.3.1...v12.4.0

v12.3.1

17 Aug 09:35

Choose a tag to compare

What's Changed

  • Improve typing and usage of getDefaultDelay by @Antiavanti in #432
  • test: migrated utils-filter-pseudo-headers.test.js from tap to node:test by @Tony133 in #427
  • Use isHttp2 check to detect we are canceling an HTTP2 request by @mcollina in #433

New Contributors

Full Changelog: v12.3.0...v12.3.1

v12.3.0

12 Aug 11:48

Choose a tag to compare

What's Changed

  • fix: handle closed HTTP/2 sessions after GOAWAY by @mcollina in #431

Full Changelog: v12.2.0...v12.3.0

v12.2.0

12 Aug 11:48
cd2ba08

Choose a tag to compare

What's Changed

New Contributors

Full Changelog: v12.1.0...v12.2.0

v12.1.0

29 Mar 06:50

Choose a tag to compare

What's Changed

  • ci(ci): set job permissions by @Fdawgs in #411
  • perf: use node: prefix to bypass require.cache call for builtins by @Fdawgs in #412
  • feat: add specific timeout for request by @leonied7 in #414

New Contributors

Full Changelog: v12.0.2...v12.1.0

v12.0.2

04 Feb 09:09
7cec1df

Choose a tag to compare

What's Changed

  • build(dependabot): reduce npm updates to monthly by @Fdawgs in #403
  • build(deps-dev): Bump nock from 13.5.6 to 14.0.0 by @dependabot in #407
  • chore: rename master to main by @Fdawgs in #406
  • types: Allow to pass any requestable undici instance by @g12i in #405

New Contributors

  • @g12i made their first contribution in #405

Full Changelog: v12.0.1...v12.0.2

v12.0.1

11 Jan 12:04
v12.0.1
df1c344

Choose a tag to compare

What's Changed

  • docs(readme): update ci badge syntax by @Fdawgs in #388
  • build(deps-dev): Bump @types/tap from 15.0.12 to 18.0.0 by @dependabot in #390
  • types: use node: prefix for builtins by @Fdawgs in #391
  • build(deps-dev): replace standard with neostandard by @Fdawgs in #389
  • build(deps-dev): add eslint, peer dep of neostandard by @Fdawgs in #393
  • chore(package): add funding and contribs by @Fdawgs in #394
  • chore: remove semver by @Uzlopak in #395
  • build(deps-dev): Bump @sinonjs/fake-timers from 13.0.5 to 14.0.0 by @dependabot in #392
  • chore: remove msgpack5 by @Uzlopak in #397
  • chore: try to fix ci issue by @Uzlopak in #396
  • perf: use optional chaining by @Fdawgs in #398
  • refactor: prefix unused params with underscores by @Fdawgs in #399
  • refactor(index): return directly in arrow function by @Fdawgs in #400
  • docs(readme): spelling and grammar fixes by @Fdawgs in #401

Full Changelog: v12.0.0...v12.0.1

v12.0.0

28 Nov 11:40
9a315f2

Choose a tag to compare

What's Changed

Full Changelog: v11.0.2...v12.0.0

v11.0.2

18 Nov 16:49
13dc7ed

Choose a tag to compare

What's Changed

  • build(deps): Bump fastify-plugin from 4.5.1 to 5.0.1 by @dependabot in #382
  • fix: return 502 on invalid upstream status code by @simosho in #386

New Contributors

Full Changelog: v11.0.1...v11.0.2