Skip to content

chore(deps-dev): Bump @fastify/static from 10.1.3 to 10.1.4 in the minor-and-patch group - #1618

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/bun/minor-and-patch-39a45bcc09
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/bun/minor-and-patch-39a45bcc09

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 1 update: @fastify/static.

Updates @fastify/static from 10.1.3 to 10.1.4

Release notes

Sourced from @​fastify/static's releases.

v10.1.4

This is a security release for GHSA-r799-r9gc-m956 (CVE-2026-90982).

It fixes a route guard and allowedPath bypass on case-insensitive filesystems. Users should upgrade to @fastify/static 10.1.4.

Full Changelog: fastify/fastify-static@v10.1.3...v10.1.4

Commits
  • a39a464 Bumped v10.1.4
  • ac46015 Ignore .pi
  • 6288466 test: consume compressed response bodies
  • 04134a4 test: cover rootless path validation on Windows
  • d9a8c0a test: make case-folding fallback portable
  • dbe65e8 Merge commit from fork
  • 48b821f chore: bump content-disposition in the dependencies group (#607)
  • ee3f89d chore: bump fastify/workflows/.github/workflows/plugins-ci.yml (#604)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 1 update: [@fastify/static](https://github.com/fastify/fastify-static).


Updates `@fastify/static` from 10.1.3 to 10.1.4
- [Release notes](https://github.com/fastify/fastify-static/releases)
- [Commits](fastify/fastify-static@v10.1.3...v10.1.4)

---
updated-dependencies:
- dependency-name: "@fastify/static"
  dependency-version: 10.1.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 21, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Looks like @fastify/static is updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 21, 2026
@dependabot
dependabot Bot deleted the dependabot/bun/minor-and-patch-39a45bcc09 branch September 21, 2026 22:09
pathosDev added a commit that referenced this pull request Sep 21, 2026
… the fastest runner

`CompressionLiveness.test.ts` asserts, before it counts a single tick,
that the call under test took at least 50 ms — below that a 1 ms interval
proves nothing — and its one 48 MiB fixture cleared that floor by 135 ms
for gzip level 9 on the machine it was sized on.  On the Linux runners the
same leg reads 123–128 ms in two `develop` runs and 49.5 ms on the run for
#1618, where every leg was ~2.5× quicker: a faster runner class, and the
floor inside the spread of the fastest leg.  The precondition tripped
exactly as its message says it would ("grow the fixture, never lower the
floor"), on a bump to `@fastify/static` that touches nothing near zlib.

Growing everything is not possible: zstd at level 22 has a cliff, not a
slope — 48 MiB in 0.26–0.38 s here, 96 MiB in 3.7–5.4 s, 128 MiB in
5.2–5.4 s, the ultra levels running a 128 MiB window — and 5 s is the
per-test cap.  So the gzip compress leg and both decompress legs now work
on 160 MiB (gzip level 9: 139–186 ms at 48 MiB, 557–616 ms at 160 MiB here,
which puts the fastest runner near 165 ms, over three times the floor),
and the zstd level-22 leg keeps its 48 MiB as a `subarray` prefix of the
same buffer — the same data, no second allocation.  The decode legs
produce their frame at the default level, where zstd has no cliff, and
measure only the bytes coming back out.  Heaviest test 0.9 s here, RSS
~520 MiB for the file; three local runs green.  The header carries the
measurements and the reason a local number is not the margin.

Closes #1621

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants