⚠️ Security Release
This release fixes a critical path-scoped middleware bypass via absolute-form request targets:
- GHSA-hx87-8wv7-pjv8 / CVE-2026-85184
Versions >= 9.1.0, < 9.3.4 are affected. Users should upgrade to 9.3.4 or later.
What's Changed
- chore: bump @types/node from 25.9.4 to 26.0.0 in the dev-dependencies-typescript group by @dependabot[bot] in #268
- docs: fix broken links by @Fdawgs in #267
- ci: pin actions to commit-hash by @Fdawgs in #269
- chore: bump c8 from 11.0.0 to 12.0.0 by @dependabot[bot] in #270
- chore: bump fastify/workflows/.github/workflows/lock-threads.yml from 6.0.0 to 7.0.0 by @dependabot[bot] in #272
- chore: bump fastify/workflows/.github/workflows/plugins-ci.yml from 6.0.0 to 7.0.0 by @dependabot[bot] in #273
- chore(.npmrc): add min-release-age by @Fdawgs in #271
Full Changelog: v9.3.3...v9.3.4