@quasar/app-vite-v3.4.1
Changes
- Security: bumped
@fastify/staticfrom^9.1.1to^10.1.2in the SSR Fastify template — fixes a route-guard bypass via path traversal (high severity) and an authorization bypass via non-canonical URL paths. - This only affects newly generated SSR projects using the Fastify variant. Existing projects should manually bump
@fastify/staticto^10.1.2insrc-ssr/package.json. The only breaking change in v10 is thesetHeaderscallback signature (now receives aFastifyReplyinstead of a rawResponse) — the template doesn't use it, so no code changes are needed unless you added it yourself. - Upgraded more template spawned deps
Donations
Quasar Framework is an open-source MIT-licensed project made possible due to the generous contributions by sponsors and backers. If Quasar is useful in your workflow and you want to support ongoing maintenance, please consider the following: