fix(deps): update dependency @nestjs/platform-fastify to v11 [security]#71
Open
renovate[bot] wants to merge 1 commit intomainfrom
Open
fix(deps): update dependency @nestjs/platform-fastify to v11 [security]#71renovate[bot] wants to merge 1 commit intomainfrom
renovate[bot] wants to merge 1 commit intomainfrom
Conversation
448d01b to
8f1af64
Compare
8f1af64 to
c50cf4b
Compare
ca620ec to
65c8c8b
Compare
bd7eb00 to
fd3ff3d
Compare
958b163 to
b34e8fe
Compare
b34e8fe to
3d1963c
Compare
f0fa7ab to
71c8860
Compare
5ec9142 to
6e02c7a
Compare
6e02c7a to
cac5fb0
Compare
cac5fb0 to
6a3b916
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
10.4.20→11.1.11GitHub Vulnerability Alerts
CVE-2025-69211
A NestJS application is vulnerable if it meets all of the following criteria:
@nestjs/platform-fastify.NestMiddleware(viaMiddlewareConsumer) for security checks (authentication, authorization, etc.), or throughapp.use().forRoutes('admin')).Example Vulnerable Config:
Attack Vector:
/adminadminGET /%61dmin%61dmin), but controller for/adminis executed.Consequences:
Patches
Patched in
@nestjs/platform-fastify@11.1.11Resources
Credit goes to Hacktron AI for reporting this issue.
Release Notes
nestjs/nest (@nestjs/platform-fastify)
v11.1.11Compare Source
v11.1.11 (2025-12-29)
Bug fixes
platform-fastifycoreDependencies
platform-socket.ioplatform-fastifycommonCommitters: 3
v11.1.10Compare Source
v11.1.10 (2025-12-22)
Bug fixes
coremicroservicescommonEnhancements
commoncoremicroservicescommon,coreDependencies
platform-fastifyplatform-expresscommonCommitters: 11
v11.1.9Compare Source
v11.1.9 (2025-11-14)
Bug fixes
coreEnhancements
commonDependencies
platform-fastifyCommitters: 4
v11.1.8Compare Source
v11.1.8 (2025-10-27)
Bug fixes
coreplatform-fastifyCommitters: 2
v11.1.7Compare Source
v11.1.7 (2025-10-21)
Bug fixes
microservicesplatform-fastifycorecommonEnhancements
common,platform-socket.io,websocketscommoncommon,corecoremicroservicesDependencies
platform-fastifycore,platform-express,platform-fastifycommonCommitters: 9
v11.1.6Compare Source
v11.1.6 (2025-08-07)
Bug fixes
coremicroservicesDependencies
platform-fastifyCommitters: 6
v11.1.5Compare Source
v11.1.5 (2025-07-18)
Dependencies
platform-expressv11.1.4Compare Source
v11.1.4 (2025-07-16)
Bug fixes
platform-fastifycore,testingcoremicroservicesEnhancements
platform-fastifycommon,core,microservices,platform-express,platform-fastify,websocketscoreDependencies
platform-wsplatform-fastifyCommitters: 11
v11.1.3Compare Source
v11.1.3 (2025-06-06)
Bug fixes
coreEnhancements
commoncommon,coreDependencies
platform-expressCommitters: 3
v11.1.2Compare Source
v11.1.2 (2025-05-26)
Bug fixes
microservicesDependencies
commonplatform-expressCommitters: 2
v11.1.1Compare Source
v11.1.1 (2025-05-14)
Bug fixes
coremicroservicescore,platform-fastifygetHeaderandappendHeadermethods fromAbstractHttpAdapter(@micalevisk)platform-expressEnhancements
microservicesDependencies
platform-fastifyplatform-wscommonCommitters: 7
v11.1.0Compare Source
v11.1.0 (2025-04-23)
Enhancements
microservicesCommitters: 1
v11.0.21Compare Source
v11.0.21 (2025-04-23)
Enhancements
commonDependencies
platform-fastifyCommitters: 1
v11.0.20Compare Source
What's Changed
evalby @Borewit in #14974New Contributors
Full Changelog: nestjs/nest@v11.0.19...v11.0.20
v11.0.19Compare Source
v11.0.18Compare Source
What's Changed
d9a69a3Full Changelog: nestjs/nest@v11.0.17...v11.0.18
v11.0.17Compare Source
v11.0.16Compare Source
v11.0.16 (2025-04-11)
file-typeto validate file mimetypes by @Chathula in #14881v11.0.15Compare Source
v11.0.15 (2025-04-10)
Bug fixes
platform-fastifyCommitters: 1
v11.0.14Compare Source
v11.0.14 (2025-04-09)
Bug fixes
platform-fastifyCommitters: 1
v11.0.13Compare Source
v11.0.13 (2025-04-03)
Bug fixes
platform-fastifymicroservicesDependencies
platform-expressplatform-fastifyCommitters: 2
v11.0.12Compare Source
v11.0.12 (2025-03-19)
Bug fixes
coreEnhancements
corev11.0.11Compare Source
v11.0.11 (2025-02-28)
Enhancements
platform-fastifyDependencies
platform-fastifyplatform-wsCommitters: 1
v11.0.10Compare Source
v11.0.10 (2025-02-17)
Bug fixes
microservicesplatform-expressv11.0.9Compare Source
v11.0.9 (2025-02-10)
Bug fixes
corecommonCommitters: 2
v11.0.8Compare Source
v11.0.8 (2025-02-06)
Bug fixes
commonplatform-expressCommitters: 4
v11.0.7Compare Source
v11.0.7 (2025-01-31)
Bug fixes
coreCommitters: 1
v11.0.6Compare Source
v11.0.6 (2025-01-27)
Bug fixes
coreCommitters: 1
v11.0.5Compare Source
v11.0.5 (2025-01-23)
Bug fixes
coreCommitters: 1
v11.0.4Compare Source
v11.0.3Compare Source
v11.0.2Compare Source
v11.0.1Compare Source
v11.0.0Compare Source
v11.0.0 (2025-01-16)
Article: https://trilon.io/blog/announcing-nestjs-11-whats-new
Migration guide: https://docs.nestjs.com/migration-guide 👈 👈 👈
Features
common,core,microservicescommon,corecommon,core,microservices,platform-express,platform-fastify,platform-socket.io,platform-ws,testing,websocketsEnhancements
common@Inject()(@micalevisk)microserviceswebsocketscommon,core,microservices,websocketscommon,core,platform-fastifyplatform-expressplatform-wsplatform-fastifycommon,coreBug fixes
coreReflectortypes (@AlexRMU)platform-fastifymicroservicescommonexportsof modules (@micalevisk)Other packages in the ecosystem
config(breaking changes)clicache-manager(breaking changes)cqrsDependencies
platform-fastifyCommitters: 22
v10.4.22Compare Source
What's Changed
Full Changelog: nestjs/nest@v10.4.21...v10.4.22
v10.4.21Compare Source
What's Changed
New Contributors
Full Changelog: nestjs/nest@v10.4.20...v10.4.21
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.