Skip to content

Conversation

dominikg
Copy link
Member

@dominikg dominikg commented Sep 8, 2025

sirv 3.0.2 fixed a theoretical security vulnerability where a sibling file that starts with the name of the root directory could be requested through a path that contains ..

sveltekit applications using adapter-node do not have this kind of file by default and users would have had to go out of their way to create one which is very unlikely.


Please don't delete this checklist! Before submitting the PR, please make sure you do the following:

  • It's really useful if your PR references an issue where it is discussed ahead of time. In many cases, features are absent for a reason. For large changes, please create an RFC: https://github.com/sveltejs/rfcs
  • This message body should clearly illustrate what problems it solves.
  • Ideally, include a test that fails without this PR but passes with it.

Tests

  • Run the tests with pnpm test and lint the project with pnpm lint and pnpm check

Changesets

  • If your PR makes a change that should be noted in one or more packages' changelogs, generate a changeset by running pnpm changeset and following the prompts. Changesets that add features should be minor and those that fix bugs should be patch. Please prefix changeset messages with feat:, fix:, or chore:.

Edits

  • Please ensure that 'Allow edits from maintainers' is checked. PRs without this option may be closed.

Copy link

changeset-bot bot commented Sep 8, 2025

🦋 Changeset detected

Latest commit: 93c0d16

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/adapter-node Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@dominikg
Copy link
Member Author

dominikg commented Sep 8, 2025

@benmccann benmccann changed the title fix(adapter-node): bump sirv to 3.0.2 fix: bump sirv to 3.0.2 Sep 9, 2025
@benmccann benmccann merged commit 5139c4e into main Sep 9, 2025
22 checks passed
@benmccann benmccann deleted the fix/bump-sirv branch September 9, 2025 17:26
@github-actions github-actions bot mentioned this pull request Sep 9, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants