Skip to content

chore(deps): update compression to v1.8.1#824

Merged
AndyBitz merged 1 commit intovercel:mainfrom
dargmuesli:chore/deps/compression
Sep 4, 2025
Merged

chore(deps): update compression to v1.8.1#824
AndyBitz merged 1 commit intovercel:mainfrom
dargmuesli:chore/deps/compression

Conversation

@dargmuesli
Copy link
Copy Markdown
Contributor

@dargmuesli dargmuesli commented Jul 20, 2025

Resolves GHSA-76c9-3jph-rj3q

Closes #825

@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcompression@​1.7.4 ⏵ 1.8.199 +1100100 +189100

View full report

@MikeMcC399

This comment was marked as resolved.

@dargmuesli

This comment was marked as resolved.

@shlomisas
Copy link
Copy Markdown

Hi guys any idea when it'll be released?

@MikeMcC399
Copy link
Copy Markdown

@shlomisas

Hi guys any idea when it'll be released?

That would depend on actions from a maintainer and so far there has been no response to this PR or to the related issue #825

@PieterT2000
Copy link
Copy Markdown

See #825 (comment) for a temporary workaround

@jimthedev
Copy link
Copy Markdown

I sent vercel a message on social media to see if they will send someone over to hit the button.

@MikeMcC399
Copy link
Copy Markdown

@jimthedev

I sent vercel a message on social media to see if they will send someone over to hit the button.

... and did you succeed in getting any response?

@jimthedev
Copy link
Copy Markdown

Sadly no.

@MikeMcC399
Copy link
Copy Markdown

@jimthedev

Thanks for trying!

@MikeMcC399

This comment was marked as resolved.

@AndyBitz
Copy link
Copy Markdown
Contributor

AndyBitz commented Sep 4, 2025

@dargmuesli Thanks for the PR! I'll create a new release shortly

@AndyBitz AndyBitz merged commit cfaff36 into vercel:main Sep 4, 2025
1 check passed
@MikeMcC399
Copy link
Copy Markdown

MikeMcC399 commented Sep 4, 2025

@AndyBitz

Thanks for merging the PR! Unfortunately it seems that CI is failing due to some outdated usage.

Do you need any assistance in updating the GitHub Action workflows to get them to work?

@AndyBitz
Copy link
Copy Markdown
Contributor

AndyBitz commented Sep 4, 2025

@MikeMcC399 I'm already on it, no worries

@AndyBitz
Copy link
Copy Markdown
Contributor

AndyBitz commented Sep 4, 2025

We've just published serve@14.2.5 which includes those changes. Thanks again!

@dargmuesli dargmuesli deleted the chore/deps/compression branch November 24, 2025 20:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Low severity vulnerability in on-headers@1.0.2 CVE-2025-7339

6 participants