Skip to content

build(deps): Bump @fastify/static from 9.1.3 to 10.1.2 - #5

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fastify/static-10.1.2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/fastify/static-10.1.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026 •

Copy link
Copy Markdown

Bumps @fastify/static from 9.1.3 to 10.1.2.

Release notes

Sourced from @​fastify/static's releases.

v10.1.2

⚠️ Security Release

What's Changed

Full Changelog: fastify/fastify-static@v10.1.1...v10.1.2

v10.1.1

⚠️ Security Release

What's Changed

Full Changelog: fastify/fastify-static@v10.1.0...v10.1.1

v10.1.0

What's Changed

New Contributors

Full Changelog: fastify/fastify-static@v10.0.0...v10.1.0

v10.0.0

Breaking Changes

  • setHeaders now using FastifyReply instead of Response.

You should refactor your code to use the reply helpers. For example,

// Before
const fastify = require('fastify')({logger: true})
const path = require('node:path')
fastify.register(require('@​fastify/static'), {
root: path.join(__dirname, 'public'),
prefix: '/public/', // optional: default '/',
setHeaders(res) {
res.setHeader('X-Test', 'Foo')
}
})
</tr></table>

... (truncated)

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [@fastify/static](https://github.com/fastify/fastify-static) from 9.1.3 to 10.1.2.
- [Release notes](https://github.com/fastify/fastify-static/releases)
- [Commits](fastify/fastify-static@v9.1.3...v10.1.2)

---
updated-dependencies:
- dependency-name: "@fastify/static"
  dependency-version: 10.1.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 28, 2026
yves-chevallier pushed a commit that referenced this pull request Sep 19, 2026
All three are security releases: fastify closes GHSA-w2qp-rph6-63g4 and
GHSA-3m5p-2c4r-xxw2, @fastify/static closes GHSA-83w8-p2f5-377r and
GHSA-8pvw-jcv7-9cmj.

Redone by hand on main's lockfile instead of taking the three Dependabot
branches (#5, #6, #8), all of which fail CI the same way: regenerating
the lockfile drops the integrity of the xlsx entry, which resolves to the
SheetJS CDN rather than the registry, and pnpm then refuses to install an
unverified tarball. Starting from a correct lockfile and running a real
pnpm install leaves that entry untouched. docs/development/dependencies.md
records the trap and the repair, because it will arrive again with every
npm bump Dependabot proposes.

@fastify/static 10 breaks one thing, setHeaders receiving a FastifyReply
instead of the raw response. app.ts registers the plugin with a root and
nothing else, so it is not concerned — and the commit before this one put
that path under test.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
yves-chevallier added a commit that referenced this pull request Sep 19, 2026
* test(server): the SPA fallback was never exercised

STATIC_DIR defaults to empty, so @fastify/static was never registered in
a test and the not-found handler that falls back to index.html was never
reached — while production sets it on every boot. A deep link answering
404 for every student is a break the suite would have reported green.

Four cases on a temporary static root: an asset is served, a deep link
gets index.html so a reload keeps the page, the API prefixes keep their
JSON 404, and a non-GET never receives the SPA.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* build(deps): fastify 5.12.1, @fastify/static 10.1.2, vitest 4.1.11

All three are security releases: fastify closes GHSA-w2qp-rph6-63g4 and
GHSA-3m5p-2c4r-xxw2, @fastify/static closes GHSA-83w8-p2f5-377r and
GHSA-8pvw-jcv7-9cmj.

Redone by hand on main's lockfile instead of taking the three Dependabot
branches (#5, #6, #8), all of which fail CI the same way: regenerating
the lockfile drops the integrity of the xlsx entry, which resolves to the
SheetJS CDN rather than the registry, and pnpm then refuses to install an
unverified tarball. Starting from a correct lockfile and running a real
pnpm install leaves that entry untouched. docs/development/dependencies.md
records the trap and the repair, because it will arrive again with every
npm bump Dependabot proposes.

@fastify/static 10 breaks one thing, setHeaders receiving a FastifyReply
instead of the raw response. app.ts registers the plugin with a root and
nothing else, so it is not concerned — and the commit before this one put
that path under test.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Yves Chevallier <nowox@x0x.ch>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@yves-chevallier

Copy link
Copy Markdown
Contributor

Superseded by #28, merged as b0385fd, which carries this bump with a working lockfile.

This PR could not be merged: regenerating the lockfile drops the integrity of the xlsx entry, which resolves to the SheetJS CDN rather than the npm registry, and pnpm then refuses to install an unverified tarball. That is not a bug in the bumped package — all three open Dependabot PRs failed the same way. See docs/development/dependencies.md for the cause and the repair recipe.

@dependabot @github

dependabot Bot commented on behalf of github Sep 19, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/fastify/static-10.1.2 branch September 19, 2026 20:52
yves-chevallier added a commit that referenced this pull request Sep 19, 2026
* test(web): give the async queries a budget that survives a loaded machine

TeacherHome's first findByRole failed about two runs in three under
`pnpm -r test`, which runs four workspaces at once. The page had rendered
its header but not yet its cards: a React Query round trip through a
stubbed fetch had simply not finished inside Testing Library's one-second
default, which assumes a machine running this suite and nothing else.

Nothing is slow on purpose and no query fails to land, so the fix is the
budget, not the tests. The fragility predates the command palette suites
— they only grew the dom project by seventy tests and made it visible,
verified by running the workspace with those three files removed, which
came back clean three times out of three.

Five seconds leaves room for a loaded CI runner while keeping a genuinely
broken expectation failing promptly. Five consecutive `pnpm -r test` runs
are green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* ci: configure Dependabot so one repair covers every security bump

The repository had no Dependabot configuration, which means only security
updates ran and each opened its own pull request. All three that piled up
(#5, #6, #8) failed identically on the xlsx lockfile integrity, and all
three needed the same manual repair.

The trap is that adding a configuration file at all ENABLES version
updates for the ecosystem it names, so the obvious fix would have made
things worse: a weekly batch of version bumps is a weekly batch of broken
lockfiles. `open-pull-requests-limit: 0` switches version updates off
while leaving security pull requests untouched — they are explicitly not
subject to that limit — and a group then collapses them into one pull
request instead of one per package.

That group carries `applies-to: security-updates`. Without it a group
defaults to version updates, so it would have grouped nothing at all,
silently.

GitHub Actions and the Docker base image go the other way, with version
updates on: neither touches the pnpm lockfile, so their pull requests
merge as they arrive, and there is drift to close — actions/setup-node is
pinned at v5 in one workflow and v6 in another. Majors of the node base
image are ignored, because moving production to a new Node major is a
decision taken with `engines` and the CI matrix; `ignore` never applies
to security updates, so that costs nothing.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Yves Chevallier <nowox@x0x.ch>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant