Skip to content

Update dependency koa to v2.16.1#31

Open
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/koa-2.x-lockfile
Open

Update dependency koa to v2.16.1#31
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/koa-2.x-lockfile

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented Jun 9, 2025

This PR contains the following updates:

Package Type Update Change
koa (source) dependencies minor 2.11.02.16.1

By merging this PR, the issue #23 will be automatically resolved and closed:

Severity CVSS Score Vulnerability
High High 8.6 CVE-2025-25200
Medium Medium 5.0 CVE-2025-32379

Release Notes

koajs/koa (koa)

v2.16.1

Compare Source

fix: don't render redirect values in anchor ref

v2.16.0

Compare Source

This is a backported release to fix core underlying issue with HEAD requests when using http2.createSecureServer. See discussion at #​1593 and #​1547.

  • fix missing cleanup, if response socket is no longer writeable (issue 1547) (#​1593) 399cb6b

v2.15.4

Compare Source

Full Changelog: koajs/koa@2.15.3...2.15.4

Fix: avoid redos on host and protocol getter, see GHSA-593f-38f6-jp5m

v2.15.3

Compare Source

v2.15.2

Compare Source

v2.15.1

Compare Source

v2.15.0

Compare Source

v2.14.2

Compare Source

v2.14.1

Compare Source

v2.14.0

Compare Source

v2.13.4

Compare Source

v2.13.3

Compare Source

v2.13.2

Compare Source

v2.13.1

Compare Source

==================

fixes

others

v2.13.0

Compare Source

==================

features

others

v2.12.1

Compare Source

==================

fixes

others

v2.12.0

Compare Source

==================

features

others


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Jun 9, 2025
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/koa-2.x-lockfile branch from 332213b to 390c4bd Compare September 14, 2025 13:22
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/koa-2.x-lockfile branch from 390c4bd to 2c968e8 Compare September 30, 2025 08:55
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/koa-2.x-lockfile branch from 2c968e8 to 66d054a Compare October 1, 2025 09:46
@mend-for-github-com
Copy link
Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants