Releases: fastify/fastify
Releases Β· fastify/fastify
Release list
v5.11.3
What's Changed
- fix: clear trailer state when removing all trailers by @Ram-blip in #6845
- docs: document percent-decoded route params as untrusted input by @mcollina in #6903
- docs(errors): document what the default error handler sends by @basteez in #6894
- docs(readme): fix grammar and cjs capitalization by @minirang in #6899
- fix: pass null instead of undefined to requestCompleted on success by @lazerg in #6837
- docs(encapsulation): clarify nested plugin scopes by @jean-michelet in #6893
- chore: Bump fastify/workflows/.github/workflows/lock-threads.yml from 6.0.0 to 7.0.0 by @dependabot[bot] in #6916
- chore: Bump fastify/workflows/.github/workflows/nested-quality.yml from 6.0.0 to 7.0.0 by @dependabot[bot] in #6917
- fix: recognize constructor-assigned built-in properties as decorator β¦ by @aquie00t in #6892
- fix: reset lastIndex before testing global/sticky content-type RegExp parsers by @zelinewang in #6846
New Contributors
- @minirang made their first contribution in #6899
- @lazerg made their first contribution in #6837
- @zelinewang made their first contribution in #6846
Full Changelog: v5.11.2...v5.11.3
v5.11.2
v5.11.1
What's Changed
- fix: add http method override warning by @jean-michelet in #6879
- fix(types): allow explicit http2: false in server options by @Tony133 in #6888
- docs: clarify what attachValidation exposes on request.validationError by @basteez in #6891
- fix: do not force close in-flight connections when forceCloseConnections is 'idle' by @aquie00t in #6889
New Contributors
Full Changelog: v5.11.0...v5.11.1
v5.11.0
What's Changed
- chore: Bump markdownlint-cli2 from 0.22.1 to 0.23.0 by @dependabot[bot] in #6839
- fix: normalize method in findRoute by @Ram-blip in #6838
- docs: fix incorrect description for validateInput in Request.md by @thePranav-kpk in #6823
- feat: rfc10008 http query method by @climba03003 in #6832
- perf: reuse cached content types for response serialization by @gurgunday in #6854
- chore(sponsor): add n-ix by @Eomm in #6852
- ci: pin actions to commit-hash by @Fdawgs in #6853
- ci(dependabot): temporarily ignore typescript updates by @Tony133 in #6869
- style(types): enforce max line length by @jean-michelet in #6864
- docs(ecosystem): update fastify-prisma repo URL by @zrosenbauer in #6724
- docs(getting-started): align import with exported routes by @Solaris-star in #6859
- docs(server): fix contradictory requestIdHeader default by @sobol-sudo in #6872
- fix(validation): correctly update falsy values from validator by @jackjin1997 in #6483
- docs: specific warning suppression by @jean-michelet in #6871
- ci(links-check): pin linkinator server root to the workspace by @aquie00t in #6877
- docs: update TypeScript docs to reference Fastify 5.x by @Sasireddy001 in #6880
- docs: use async trailer handlers in Reply examples by @Ram-blip in #6856
- docs: fix logController migration example and links by @aquie00t in #6876
- fix: uncatchable throws in writeHead when using async hook by @climba03003 in #6881
- fix: honor quoted-string in
Content-Typeparameter values by @aquie00t in #6865 - chore(.npmrc): add min-release-age by @Fdawgs in #6873
- chore: Bump actions/setup-node from 6.4.0 to 7.0.0 by @dependabot[bot] in #6866
- chore: Bump actions/labeler from 6.2.0 to 7.0.0 by @dependabot[bot] in #6867
New Contributors
- @Ram-blip made their first contribution in #6838
- @Solaris-star made their first contribution in #6859
- @sobol-sudo made their first contribution in #6872
- @jackjin1997 made their first contribution in #6483
- @Sasireddy001 made their first contribution in #6880
Full Changelog: v5.10.0...v5.11.0
v5.10.0
What's Changed
- docs(type-providers): clarify as const usage by @smith558 in #6772
- docs: fix broken and redirected links by @Eomm in #6817
- docs: remove marko from @fastify/view engines (support dropped) by @EduardF1 in #6821
- fix: clear socket._meta on reply.hijack() when onTimeout is registered by @nerkoux in #6810
- docs: fix duplicate routeOptions entries in Request.md example by @thePranav-kpk in #6824
- chore: Bump @types/node from 25.9.4 to 26.0.1 in the dev-dependencies-typescript group by @dependabot[bot] in #6829
- docs(ecosystem): add @stitchapi/fastify to Community plugins by @rejifald in #6820
- feat: introduce log controller layer by @Eomm in #6580
- fix: use ContentType to detect
jsonandcharsetin reply.send by @climba03003 in #6830 - docs: fix incorrect defaults and code examples in Server.md by @Adit-Jain-srm in #6805
- docs: fix incorrect hook count in Hooks.md by @thePranav-kpk in #6825
- chore: Bump fast-json-stringify from 6.4.0 to 7.0.0 in the dependencies group across 1 directory by @dependabot[bot] in #6800
- perf: reduce per-request overhead in the request lifecycle by @mcollina in #6831
- fix: derive request.port from request.host by @mcollina in #6680
- docs: update Logging.md with per-route log level info by @asppsa in #6627
- docs(type-providers): update import for article consistency by @smith558 in #6771
New Contributors
- @EduardF1 made their first contribution in #6821
- @thePranav-kpk made their first contribution in #6824
- @rejifald made their first contribution in #6820
- @Adit-Jain-srm made their first contribution in #6805
- @asppsa made their first contribution in #6627
Full Changelog: v5.9.0...v5.10.0
v5.9.0
What's Changed
- feat: add request.mediaType by @climba03003 in #6653
- docs: remove deprecated leveldb plugin and update ecosystem by @Tony133 in #6661
- chore(sponsor): add bestforandroid by @Eomm in #6659
- ci: drop Node.js 20 from yarn matrix in package-manager-ci.yml by @Tony133 in #6662
- fix: prevent duplicate res.end in sendTrailer with sync callbacks by @climba03003 in #6676
- fix: avoid duplicate closeIdleConnections call on native servers by @trivikr in #6669
- fix: error.code not present on some routing errors by @mcollina in #6678
- fix: correct isCustomSerializerCompiler flag check by @eddieran in #6657
- fix: validate invalid route logLevel at registration by @maxpetrusenko in #6523
- docs: update contribution rules by @Tony133 in #6670
- fix: use ContentType parser for response schema lookup by @UlisesGascon in #6685
- ci(ci): use shared quality workflow by @Fdawgs in #6688
- fix(types): allow request.getValidationFunction() to return undefined by @trivikr in #6665
- fix: do not trust forwarded host/proto when socket is missing by @mcollina in #6684
- perf: defer ContentType parsing in getSchemaSerializer until needed by @aquie00t in #6692
- perf: cache parsed ContentType objects in ContentTypeParser by @aquie00t in #6694
- perf: add typeof guard before toString.call in send and onSendEnd by @aquie00t in #6693
- chore: Bump pnpm/action-setup from 5.0.0 to 6.0.4 by @dependabot[bot] in #6704
- chore: Bump actions/github-script from 8 to 9 by @dependabot[bot] in #6705
- chore: Bump JustinBeckwith/linkinator-action from 2.4.0 to 2.4.2 by @dependabot[bot] in #6706
- docs: correct return503OnClosing comment in route.js by @mcollina in #6712
- fix: enable diagnostics tracking for async error handlers by @irzix in #6458
- fix: ignore duplicate trailer completions by @mcollina in #6714
- feat: add support of onMaxParamLength by @climba03003 in #6716
- chore: introduce TSTyche for type testing by @mrazauskas in #6532
- docs(reference): grammar and readability fixes by @Fdawgs in #6710
- chore: update depedabot setting by @climba03003 in #6715
- fix: include hint and docs URL in FSTWRN004 warning message by @aquie00t in #6723
- ci(ci): do not pass secrets to reusable workflow by @Fdawgs in #6744
- docs: add fastify-intlayer to ecosystem documentation by @aymericzip in #6594
- chore: Bump concurrently from 9.2.1 to 10.0.0 by @dependabot[bot] in #6752
- docs(Errors): fix incorrect usage of root fastify inside plugin scope by @Rpaudel379 in #6731
- ci: add node 26 to test matrices by @Fdawgs in #6728
- docs(Warnings): remove retired FSTWRN002 warning code by @leestana01 in #6754
- fix: chunk large HTTP/2 buffer replies by @mcollina in #6746
- chore: migrate type tests to TSTyche assertions (part one) by @mrazauskas in #6726
- chore: migrate type tests to TSTyche assertions (part two) by @mrazauskas in #6727
- docs: fix doubled braces in serializerCompiler signature by @DucMinhNe in #6747
- docs: remove HackerOne reporting link by @jhcpeixoto in #6735
- refactor(decorate): replace
findwithsomeinhasKeyfor correct boolean semantics by @aquie00t in #6759 - fix: replace
AssertionErrorwithFST_ERR_PLUGIN_DEPENDENCY_NOT_REGISTEREDincheckDependenciesby @aquie00t in #6774 - docs(ecosystem): add @inferdi/fastify by @maxrendel in #6742
- docs(typo): Write-Plugin.md by @zakirimadullahprogrammer-tech in #6776
- docs: fix duplicate anchor IDs causing broken TOC links by @AliMahmoudDev in #6770
- docs: add fastify-ata as a JSON Schema validator option by @mertcanaltin in #6733
- chore: rename type test files by @mrazauskas in #6762
- docs: update ajv-errors guidance by @Herrtian in #6741
- chore(warnings): correct duplicate 'not' typos in inline comments by @mixelburg in #6713
- docs: add fastify-param-schema-validation to ecosystem by @Player1205 in #6760
- docs(ecosystem): add @thecodepace/fastify-http-query by @Puppo in #6785
- chore: Bump esbuild from 0.25.12 to 0.28.1 in /test/bundler/esbuild in the npm_and_yarn group across 1 directory by @dependabot[bot] in #6788
- fix: clear socket._meta after response to prevent keep-alive leaks by @nerkoux in #6799
- fix: avoid double slash when joining nested prefixes by @rohithvegesna in #6803
- docs(sponsors): Update sponsors list by removing two entries by @Eomm in #6792
- chore: Bump fastify-plugin from 5.1.0 to 6.0.0 by @dependabot[bot] in #6801
- chore(package.json): fix delvedor's personal url by @Fdawgs in #6808
- chore: replace http with https in urls by @Fdawgs in #6809
- chore: add new sponsor by @Eomm in #6813
- chore: Bump actions/checkout from 6 to 7 by @dependabot[bot] in #6812
- fix: hasRequestDecorator/hasReplyDecorator misses constructor-assigned built-in properties by @LeSingh1 in #6753
- docs: migrate Zod type provider to official @fastify package by @Tony133 in #6686
- docs: add warning about empty string coercion with nullable types by @ritambh888 in #6452
- docs: fix incorrect code examples in Hooks and Server reference by @rrodj in #6622
- docs: update Serverless guide Dockerfile to a supported Node.js version by @harish885 in #6789
- docs(types): mark request metadata accessors as untrusted input by @mcollina in #6572
- Bumped v5.9.0 by @Eomm in #6816
New Contributors
- @eddieran made their first contribution in #6657
- @irzix made their first contribution in #6458
- @aymericzip made their first contribution in #6594
- @Rpaudel379 made their first contribution in #6731
- @leestana01 made their first contribution in #6754
- @DucMinhNe made their first contribution in #6747
- @jhcpeixoto made their first contribution in #6735
- @maxrendel made their first contribution in #6742
- @zakirimadullahprogrammer-tech made their first contribution in #6776
- @AliMahmoudDev made their first contribution in #6770
- @mertcanaltin made their first contribution in #6733
- @Herrtian made their first contribution in #6741
- @mixelburg made their first contribution in #6713
- @Player1205 made their first contribution in #6760
- @Puppo made their first contribution in #6785
- @nerkoux made their first contribution in #6799
- @rohithvegesna made their first contribution in #6803
- @LeSingh1 made their first contribution in #6753
- @ritambh888 made their first contribution in #6452
- @rrodj made their first contribution in #6622
- @harish885 made their first contribution in #6789
Full Changelog: v5.8.5...v5.9.0
v5.8.5
β οΈ Security Release
This fixes CVE CVE-2026-33806 GHSA-247c-9743-5963.
What's Changed
- chore: Fix port parsing by @jsumners in #6603
- chore: upgrade to typescript v6.0.2 by @Tony133 in #6605
- fix: restore trustProxy function for number and string types, add null check for socketAddr by @mcollina in #6613
- ci: reduce cron scheduled workflows from daily/weekly to monthly by @Fdawgs in #6623
- chore: Bump pnpm/action-setup from 4.2.0 to 5.0.0 by @dependabot[bot] in #6629
- chore: Bump markdownlint-cli2 from 0.21.0 to 0.22.0 by @dependabot[bot] in #6632
- chore: Bump borp from 0.21.0 to 1.0.0 by @dependabot[bot] in #6633
- chore: Bump actions/dependency-review-action from 4.8.3 to 4.9.0 by @dependabot[bot] in #6630
- docs(ecosystem): add @pompelmi/fastify-plugin by @SonoTommy in #6610
New Contributors
- @SonoTommy made their first contribution in #6610
Full Changelog: v5.8.4...v5.8.5
v5.8.4
v5.8.3
β οΈ Security Release
This fixes CVE CVE-2026-3635 GHSA-444r-cwp2-x5xf.
What's Changed
- docs(readme): add @Tony133 to plugin team by @Tony133 in #6565
- Updated Plugins-Guide.md; Changed "fastify" to "instance" during plugin registration to showcase that it's added as a child by @kyrylchenko in #6566
- test: use fastify.test in test case by @climba03003 in #6568
- docs: use fastify.example in documentation by @climba03003 in #6567
- docs: add common performance degradation guidance by @maxpetrusenko in #6520
- docs(server): fix camelCase anchor links in TOC by @Deepvamja in #6530
- ci(link-checker): fix root-relative links resolution by @barba-rossa in #6535
- docs: update syntax markdown, absolute paths and links by @Tony133 in #6569
- docs: clarify content-type parser/schema mismatch is outside threat model by @mcollina in #6537
- docs: fix incorrect code examples in Reply and Request reference by @mahmoodhamdi in #6582
- docs: replace redirected npm.im http-errors link by @mcollina in #6588
- types: Allow port to be null in request type definition by @TristanBarlow in #6589
- docs: update links by @Tony133 in #6593
- ci(lock-threads): use shared lock-threads workflow by @Fdawgs in #6592
New Contributors
- @kyrylchenko made their first contribution in #6566
- @maxpetrusenko made their first contribution in #6520
- @Deepvamja made their first contribution in #6530
- @barba-rossa made their first contribution in #6535
- @mahmoodhamdi made their first contribution in #6582
- @TristanBarlow made their first contribution in #6589
Full Changelog: v5.8.2...v5.8.3
v5.8.2
What's Changed
- docs(ecosystem): add @yeliex/fastify-problem-details by @yeliex in #6546
- Revert "chore: upgrade borp to v1.0.0" by @climba03003 in #6564
- docs: document body validation with custom content type parsers by @mcollina in #6556
- docs(ecosystem): add fastify-file-router by @bhouston in #6441
- docs: add fastify-svelte-view to Ecosystem list by @matths in #6453
- fix: anchor keyValuePairsReg to prevent quadratic backtracking by @mcollina in #6558
- docs: added note on handling of invalid URLs in setNotFoundHandler by @leftieFriele in #5661
- docs(guides): update codemod links by @OluchiEzeifedikwa in #6479
- docs: add @glidemq/fastify to community plugins by @avifenesh in #6560
New Contributors
- @yeliex made their first contribution in #6546
- @matths made their first contribution in #6453
- @leftieFriele made their first contribution in #5661
- @OluchiEzeifedikwa made their first contribution in #6479
- @avifenesh made their first contribution in #6560
Full Changelog: v5.8.1...v5.8.2