Skip to content

1.2.5

Choose a tag to compare

@github-actions github-actions released this 03 Aug 20:43

Maintenance release clearing two build-time dependency advisories that were
open when 1.2.4 was tagged. Nothing here reaches a vault — no plugin behavior
changes.

Security

  • fast-uri bumped to 3.1.5 (host confusion via backslash authority
    introducer; dev-only, via the ajv/eslint toolchain).
  • brace-expansion ranges bumped past the CVE-2026-14257 mitigation-bypass
    DoS advisory (dev-only, via eslint/glob/test tooling; not yet flagged by
    Dependabot, caught by npm audit).
  • The release checklist now includes a dependency-advisory check before
    tagging, so future releases don't ship with a known-open alert.