1.2.5
Maintenance release clearing two build-time dependency advisories that were
open when 1.2.4 was tagged. Nothing here reaches a vault — no plugin behavior
changes.
Security
fast-uribumped to 3.1.5 (host confusion via backslash authority
introducer; dev-only, via the ajv/eslint toolchain).brace-expansionranges bumped past the CVE-2026-14257 mitigation-bypass
DoS advisory (dev-only, via eslint/glob/test tooling; not yet flagged by
Dependabot, caught bynpm audit).- The release checklist now includes a dependency-advisory check before
tagging, so future releases don't ship with a known-open alert.