Skip to content

fix(deps): update dependency fastify to v4.10.2 [security]#1126

Merged
Skn0tt merged 1 commit intomainfrom
renovate/npm-fastify-vulnerability
Jun 20, 2023
Merged

fix(deps): update dependency fastify to v4.10.2 [security]#1126
Skn0tt merged 1 commit intomainfrom
renovate/npm-fastify-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Mar 22, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
fastify (source) 4.9.2 -> 4.10.2 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-41919

Impact

The attacker can use the incorrect Content-Type to bypass the Pre-Flight checking of fetch. fetch() requests with Content-Type’s essence as "application/x-www-form-urlencoded", "multipart/form-data", or "text/plain", could potentially be used to invoke routes that only accepts application/json content type, thus bypassing any CORS protection, and therefore they could lead to a Cross-Site Request Forgery attack.

Patches

For 4.x users, please update to at least 4.10.2
For 3.x users, please update to at least 3.29.4

Workarounds

Implement Cross-Site Request Forgery protection using @fastify/csrf.

References

Check out the HackerOne report: https://hackerone.com/reports/1763832.

For more information

Fastify security policy


Release Notes

fastify/fastify

v4.10.2

Compare Source

⚠️ Security Release ⚠️

Full Changelog: fastify/fastify@v4.10.1...v4.10.2

v4.10.1

Compare Source

What's Changed

New Contributors

Full Changelog: fastify/fastify@v4.10.0...v4.10.1

v4.10.0

Compare Source

What's Changed

New Contributors

Full Changelog: fastify/fastify@v4.9.2...v4.10.0


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Mar 22, 2023
@netlify
Copy link
Copy Markdown

netlify bot commented Mar 22, 2023

Deploy Preview for quirrel-docs canceled.

Name Link
🔨 Latest commit 59ffc89
🔍 Latest deploy log https://app.netlify.com/sites/quirrel-docs/deploys/642aeaa207a45400081a6c89

@netlify
Copy link
Copy Markdown

netlify bot commented Mar 22, 2023

Deploy Preview for quirrel-development-ui canceled.

Name Link
🔨 Latest commit 59ffc89
🔍 Latest deploy log https://app.netlify.com/sites/quirrel-development-ui/deploys/642aeaa2d036630007524bfe

@coveralls
Copy link
Copy Markdown

coveralls commented Mar 22, 2023

Coverage Status

Coverage: 82.464%. Remained the same when pulling 59ffc89 on renovate/npm-fastify-vulnerability into 9344abf on main.

@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 22, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 22, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 23, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 24, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 25, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 25, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 25, 2023
@renovate renovate bot changed the title fix(deps): update dependency fastify to v4.10.2 [security] chore(deps): update dependency fastify to 4.10.2 [security] Mar 25, 2023
@renovate renovate bot changed the title chore(deps): update dependency fastify to 4.10.2 [security] fix(deps): update dependency fastify to v4.10.2 [security] Mar 27, 2023
@renovate renovate bot force-pushed the renovate/npm-fastify-vulnerability branch 2 times, most recently from dbb7799 to ef119ba Compare April 3, 2023 14:40
@renovate renovate bot force-pushed the renovate/npm-fastify-vulnerability branch from ef119ba to 59ffc89 Compare April 3, 2023 15:02
@Skn0tt Skn0tt merged commit f9d4494 into main Jun 20, 2023
Skn0tt added a commit that referenced this pull request Jun 20, 2023
🤖 I have created a release *beep* *boop*
---


##
[1.14.0](v1.13.4...v1.14.0)
(2023-06-20)


### Features

* added nextjs 13 app router native support & docs improvements
([91a3d93](91a3d93))


### Bug Fixes

* **deps:** update dependency @fastify/basic-auth to v5
([#1107](#1107))
([c3cc7cf](c3cc7cf))
* **deps:** update dependency fastify to v4.10.2 [security]
([#1126](#1126))
([f9d4494](f9d4494))
* **deps:** update dependency jsonwebtoken to v9 [security]
([#1112](#1112))
([55188c7](55188c7))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants