Skip to content

v1.4.9

Choose a tag to compare

@Fripix Fripix released this 03 Sep 09:25
· 47 commits to main since this release

A security release: one dependency update, nothing else.

🔒 Security

  • qs updated to 6.16.0, clearing two moderate advisories in the library Express uses to parse URL parameters: an array-limit bypass via bracket-key comma parsing (GHSA-x5fp-wj9c-mxmx) and a denial of service via an attacker-controlled isBuffer (GHSA-4mjr-xmp4-gh2g). Note that 6.15.3 was still affected — only 6.16.0 clears both. This was the sole vulnerability the published image carried; everything else npm audit reports lives in development dependencies, which are pruned out of the image at build time.

Nothing to do on upgrade, and no behaviour changes.

Full detail in the CHANGELOG. Image: ghcr.io/fripix/frirss:1.4.9.