Skip to content

chore(deps): [security] bump fastify from 2.10.0 to 2.15.1#5

Open
dependabot-preview[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/fastify-2.15.1
Open

chore(deps): [security] bump fastify from 2.10.0 to 2.15.1#5
dependabot-preview[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/fastify-2.15.1

Conversation

@dependabot-preview
Copy link
Copy Markdown

Bumps fastify from 2.10.0 to 2.15.1. This update includes a security fix.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

Denial of service in fastify A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.

Affected versions: < 2.15.1

Release notes

Sourced from fastify's releases.

v2.15.1

Breaking Change

For security reasons we changed the default in the ajvconfiguration. Unfortunately allErrors: true is a DoS attack vector for certain schemas. So this changed to allErrors: false.

See: ajv-validator/ajv@334071a Ref: https://hackerone.com/reports/903521

📚 PR:

  • Add PATCH to body validation (#2351)

v2.15.0

📚 PR:

  • Bind error handler to instance (v2) (#2305)
  • Fix custom JSON support (#2309)
  • On ready backport (#2296)

v2.14.1

  • Tweak haproxy config for issue #2036 (#2270) (#2271)
  • Fix: call preHandler on reply.callNotFound (#2256) (#2264)
  • doc: doc example to use ajv-errors (#2254)
  • Log clientError as trace to avoid dev confusion (#2241) (#2242)

v2.14.0

📚 PR:

v2.13.1

📚 PR:

  • Ignore pino@6.
  • ignore fast-json-stringify in dependabot
  • Fix link to Fastify Create (#2146)
  • test for issue #2148 where typedefs for query params object were wrong (#2149)
  • Replace greenkeeper with dependabot (#2162)
  • add fastify-method-override to ecosystem (#2165)
  • Update Logging.md (#2171)
  • Add to fastify-qrcode into Ecosystem (#2170)
  • docs: errors in async hook (#2176)
  • docs: use direct references in the "Schema Resolver" example (#2155)
  • fix: typo in routes doc (#2182)
  • Add google cloud trace API plugin (#2185)
  • Fixes crash when using a non-standard error code (#2184)
  • Fix package-manager CI (#2189)
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [fastify](https://github.com/fastify/fastify) from 2.10.0 to 2.15.1. **This update includes a security fix.**
- [Release notes](https://github.com/fastify/fastify/releases)
- [Commits](fastify/fastify@v2.10.0...v2.15.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview Bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Aug 5, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants