Skip to content

Bump @fastify/reply-from from 9.7.0 to 12.6.2#83

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/fastify/reply-from-12.6.2
Open

Bump @fastify/reply-from from 9.7.0 to 12.6.2#83
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/fastify/reply-from-12.6.2

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 16, 2026

Bumps @fastify/reply-from from 9.7.0 to 12.6.2.

Release notes

Sourced from @​fastify/reply-from's releases.

v12.6.2

⚠️ Security Release

This fixes CVE CVE-2026-33805 GHSA-gwhp-pf74-vj37.

What's Changed

New Contributors

Full Changelog: fastify/fastify-reply-from@v12.6.1...v12.6.2

v12.6.1

What's Changed

New Contributors

Full Changelog: fastify/fastify-reply-from@v12.5.0...v12.6.1

v12.5.0

⚠️ Security Release ⚠️

By crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @​fastify/reply-from.

Read more at GHSA-2q7r-29rg-6m5h. This is catalogued as CVE-2025-66415.

What's Changed

Full Changelog: fastify/fastify-reply-from@v12.4.0...v12.5.0

v12.4.0

What's Changed

... (truncated)

Commits
  • 457ac75 Bumped v12.6.2
  • c815dc4 Merge commit from fork
  • 1b8a45d ci: add lock-threads workflow (#466)
  • a71839c build(deps-dev): Bump proxy from 2.2.0 to 4.0.0 (#464)
  • f8aa76f build(deps-dev): Bump neostandard from 0.12.2 to 0.13.0 (#463)
  • e697b5e build(deps): Bump fastify/workflows/.github/workflows/plugins-ci.yml (#462)
  • 456a7e3 fix: correct path traversal check to allow '...' in URL path segments (#461)
  • e61ac4d Bumped v12.6.1
  • 4b87813 fix: avoid trailing ? when queryString option resolves to empty string (#459)
  • f883886 build(deps-dev): Bump c8 from 10.1.3 to 11.0.0 (#456)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by climba03003, a new releaser for @​fastify/reply-from since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 16, 2026
Bumps [@fastify/reply-from](https://github.com/fastify/fastify-reply-from) from 9.7.0 to 12.6.2.
- [Release notes](https://github.com/fastify/fastify-reply-from/releases)
- [Commits](fastify/fastify-reply-from@v9.7.0...v12.6.2)

---
updated-dependencies:
- dependency-name: "@fastify/reply-from"
  dependency-version: 12.6.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/fastify/reply-from-12.6.2 branch from ba29a04 to a926ff5 Compare April 23, 2026 15:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Development

Successfully merging this pull request may close these issues.

0 participants