Catalog / Backend

Fastify changelog

Node.js web framework that compiles JSON schemas into validation and serialization functions and builds an application from an encapsulated plugin tree.

SubscribeFastify as markdown, for pasting into a model
Latest
5.12.4
Shipped
11 Sep 2026today
Collected
60 releasesback to 2 Jul 2023
Source
fastify/fastify
Project
fastify.dev
Advisories
14 publishednewest 2026
Feed
RSS

Every release of a major line in one list, which is the one view the publisher never writes: 4 to 5. Only the lines whose first release the archive holds are listed, because a partial major would read as the whole of one.

Read today, the first day on record. Collection status

Version history

5.x35 releases
5.12.4

Fixed the fastify.js version mismatch.

fixed
5.12.2

⚠️ Security release Fix for https://github.com/fastify/fastify/security/advisories/GHSA-9q9j-q6p8-xq58 Fix for https://github.com/fastify/fastify/security/advisories/GHSA-hwr6-493r-vm6h Fix for https://github.com/fastify/fastify/security/ad

securitychanged
5.12.1

⚠️ Security release Fix for https://github.com/fastify/fastify/security/advisories/GHSA-w2qp-rph6-63g4 Fix for https://github.com/fastify/fastify/security/advisories/GHSA-3m5p-2c4r-xxw2 What's Changed [Backport 5.x] test: fix reply.mediaTyp

securitychanged
5.12.0

chore(sponsor): add testmu ai by @Eomm in https://github.com/fastify/fastify/pull/6922 docs: add per-route logging for Google Cloud Functions by @slegarraga in https://github.com/fastify/fastify/pull/6907 test: remove @sinonjs/fake-timers b

addedchanged
5.11.3

fix: clear trailer state when removing all trailers by @Ram-blip in https://github.com/fastify/fastify/pull/6845 docs: document percent-decoded route params as untrusted input by @mcollina in https://github.com/fastify/fastify/pull/6903 doc

changed
5.11.2

fix fastify version in fastify.js

changed
5.11.1

fix: add http method override warning by @jean-michelet in https://github.com/fastify/fastify/pull/6879 fix(types): allow explicit http2: false in server options by @Tony133 in https://github.com/fastify/fastify/pull/6888 docs: clarify what

addedchanged
5.11.0

chore: Bump markdownlint-cli2 from 0.22.1 to 0.23.0 by @dependabot[bot] in https://github.com/fastify/fastify/pull/6839 fix: normalize method in findRoute by @Ram-blip in https://github.com/fastify/fastify/pull/6838 docs: fix incorrect desc

addedchanged
5.10.0

docs(type-providers): clarify as const usage by @smith558 in https://github.com/fastify/fastify/pull/6772 docs: fix broken and redirected links by @Eomm in https://github.com/fastify/fastify/pull/6817 docs: remove marko from @fastify/view e

addedchanged
5.9.0

feat: add request.mediaType by @climba03003 in https://github.com/fastify/fastify/pull/6653 docs: remove deprecated leveldb plugin and update ecosystem by @Tony133 in https://github.com/fastify/fastify/pull/6661 chore(sponsor): add bestfora

addedfixedchanged
5.8.5

⚠️ Security Release This fixes CVE CVE-2026-33806 https://github.com/fastify/fastify/security/advisories/GHSA-247c-9743-5963. What's Changed chore: Fix port parsing by @jsumners in https://github.com/fastify/fastify/pull/6603 chore: upgrade

securityaddedfixed
5.8.3

⚠️ Security Release This fixes CVE CVE-2026-3635 https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf. What's Changed docs(readme): add @Tony133 to plugin team by @Tony133 in https://github.com/fastify/fastify/pull/656

securityaddedfixed
5.8.2

docs(ecosystem): add @yeliex/fastify-problem-details by @yeliex in https://github.com/fastify/fastify/pull/6546 Revert "chore: upgrade borp to v1.0.0" by @climba03003 in https://github.com/fastify/fastify/pull/6564 docs: document body valid

addedchanged
5.8.1

⚠️ Security Release Fixes "Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation": https://github.com/fastify/fastify/security/advisories/GHSA-573f-x89g-hqp9. CVE-2026-3419

securityfixed
5.8.0

docs(request): add host security warning references by @mcollina in https://github.com/fastify/fastify/pull/6476 docs: fix note style by @Fdawgs in https://github.com/fastify/fastify/pull/6487 chore: rename deploy website ci by @Eomm in htt

securityaddedchanged
5.7.3

⚠️ Security Release Fix https://github.com/fastify/fastify/security/advisories/GHSA-mrq3-vjjr-p77c CVE-2026-25224. What's Changed docs: update Reply.send() documentation for string serialization by @mcollina in https://github.com/fastify/fa

securitychanged
5.7.2

⚠️ Notice ⚠️ Parsing of the content-type header has been improved to a strict parser in PR #6414. This means only header values in the form described in RFC 9110 are accepted. What's Changed chore: npm ignore AI related files by @climba0300

addedchanged
5.7.1

chore: Bump actions/checkout from 5 to 6 by @dependabot[bot] in https://github.com/fastify/fastify/pull/6434 chore: updated version in the fastify.js by @Tony133 in https://github.com/fastify/fastify/pull/6446

changed
5.7.0

docs: Improved firebase serverless guide about process remaining stuck by @alexandercerutti in https://github.com/fastify/fastify/pull/6380 docs: update migration guide with date-time breaking change by @craftsman01 in https://github.com/fa

breakingsecurityadded
5.6.2

refactor: rename source file names with kebab-case by @jean-michelet in https://github.com/fastify/fastify/pull/6331 ci(ci): check dependabot prs originate from repo by @Fdawgs in https://github.com/fastify/fastify/pull/6330 fix: accept hta

addedchanged
5.6.1

fix: fix typo of deprecation warning FSTDEP022 by @Uzlopak in https://github.com/fastify/fastify/pull/6313 docs(decorators): fix TypeScript inconsistency by @emicovi in https://github.com/fastify/fastify/pull/6224 chore: fix typos by @deini

securityaddedchanged
5.6.0

fix: update typescript pino type to pick by @dancastillo in https://github.com/fastify/fastify/pull/6287 feat(types): router option types by @dancastillo in https://github.com/fastify/fastify/pull/6282 fix(types): Fix use of "esModuleIntero

changed
5.5.0

docs: fix markdown linting issue by @Uzlopak in https://github.com/fastify/fastify/pull/6175 chore: removed simple-get from mkcalendar tests by @ilteoood in https://github.com/fastify/fastify/pull/6199 chore: removed simple-get from version

securityaddedchanged
5.4.0

test: mv routes-* from tap by @jean-michelet in https://github.com/fastify/fastify/pull/6092 test: mv skip-reply-send from tap by @jean-michelet in https://github.com/fastify/fastify/pull/6094 test: mv plugins from tap by @jean-michelet in

addedchangedremoved
5.3.3

docs: update Vercel section by @leerob in https://github.com/fastify/fastify/pull/6046 docs(ecosystem): add fastify-papr plugin by @inaiat in https://github.com/fastify/fastify/pull/6051 test: migrated helper and input validation to node te

addedchangedremoved
5.3.2

⚠️ Security Release ⚠️ Unfortunately, v5.3.1 did not include a complete fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442. This is a follow-up patch to cover an edge case. What's Changed docs: fix arc

securityfixedchanged
5.3.1

⚠️ Security Release ⚠️ Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442 What's Changed test: migrate logger options to node test runner by @ilteoood in https://github.com/fastify/fastify/pull/6059 te

securitychanged
5.3.0

fix: wrong reply return type by @dangkyokhoang in https://github.com/fastify/fastify/pull/6026 feat: allow to access decorators by @jean-michelet in https://github.com/fastify/fastify/pull/5768 ci: continue-on-error on alternative runtime b

addedchanged
5.2.2

build: use static path instead of __filename by @climba03003 in https://github.com/fastify/fastify/pull/5922 fix(linting): fix linting error in error-handler.js by @Uzlopak in https://github.com/fastify/fastify/pull/5926 chore: Bump the dev

addedfixedchanged
5.2.1

chore: org members reorder by @Eomm in https://github.com/fastify/fastify/pull/5898 docs(request): clarify request host functionality by @Fdawgs in https://github.com/fastify/fastify/pull/5904 chore(package): add fdawgs to contributors arra

addedchanged
5.2.0

docs: add HeroDevs mentions to README and LTS docs by @AndreAngelantoni in https://github.com/fastify/fastify/pull/5730 test: migrated reply-early-hints.test.js from tap to node:test by @Tony133 in https://github.com/fastify/fastify/pull/58

addedfixedchanged
5.1.0

chore: Update Migration-Guide-V5.md by @jsumners in https://github.com/fastify/fastify/pull/5688 fix(guide-v5): wrong link for diagnostics channel by @corradopetrelli in https://github.com/fastify/fastify/pull/5693 chore: fix typo in reply-

addedchangedremoved
5.0.0

add missing route shorthands by @Uzlopak in https://github.com/fastify/fastify/pull/4409 lib: drop setDefaultRoute and getDefaultRoute methods by @RafaelGSS in https://github.com/fastify/fastify/pull/4485 Sync next-branch by @github-actions

addedchangeddeprecated
4.x25 releases
4.29.1

⚠️ Security Release ⚠️ Fix for "Invalid content-type parsing could lead to validation bypass" and CVE-2025-32442.

security
4.29.0

fix(backport v4.x): config type in RouteShorthandOptions by @bastienmenis in https://github.com/fastify/fastify/pull/5527 feat(backport 4.x): add body parsing on copy move mkcol methods by @johaven in https://github.com/fastify/fastify/pull

addedchangeddeprecated
4.28.1

[Backport 4.x] fix: server.listen listener is not cleanup properly by @github-actions in https://github.com/fastify/fastify/pull/5523 [Backport 4.x] test: fix test finished earlier than expected by @github-actions in https://github.com/fast

changed
4.28.0

test: fix closing - pipelining by @climba03003 in https://github.com/fastify/fastify/pull/5486 refactor(backport v4.x): change reply.redirect() signature (#5483) by @gurgunday in https://github.com/fastify/fastify/pull/5484 refactor(backpor

changed
4.27.0

docs(request): update request page by @Tony133 in https://github.com/fastify/fastify/pull/5343 ci: Add Nsolid runtime to CI and Integration tests by @riosje in https://github.com/fastify/fastify/pull/5332 docs(Ecosystem): add fastify-i18n,

addedchanged
4.26.2

fix: typo in module exports by @lirantal in https://github.com/fastify/fastify/pull/5316 docs(ts): Fix links by @rozzilla in https://github.com/fastify/fastify/pull/5308 fix: cb is not a function at fallbackErrorHandler by @Uzlopak in https

addedchanged
4.26.1

docs(ecosystem): adds fastify-hana to the community plugins list by @yoav0gal in https://github.com/fastify/fastify/pull/5289 docs: fix misattributed property parent in deprecation warning: request.elapsedTime by @mscottnelson in https://gi

addedchangeddeprecated
4.26.0

docs(ecosystem): add missing plugins to core list by @Fdawgs in https://github.com/fastify/fastify/pull/5234 ci: CITGM github workflow by @Uzlopak in https://github.com/fastify/fastify/pull/5233 chore: bump find-may-way to v8.0.0 by @mcolli

addedchangeddeprecated
4.25.2

fix: npm run test:watch by @domdomegg in https://github.com/fastify/fastify/pull/5221 fix: always consume stream payloads when responding to 204 with no body by @mcollina in https://github.com/fastify/fastify/pull/5231 docs: update setError

changed
4.25.1

fix: route constraints by @climba03003 in https://github.com/fastify/fastify/pull/5207 fix: Better plugin name detection for FSTWRN002 by @mcollina in https://github.com/fastify/fastify/pull/5209 chore: at-large project by @Eomm in https://

changed
4.25.0

feat: Improve RouteShorthandOptions['constraints'] type by @Fcmam5 in https://github.com/fastify/fastify/pull/5097 fix: add @eomm and @jsumners as lead maintainers by @mcollina in https://github.com/fastify/fastify/pull/5115 fix: reply.send

securityaddedchanged
4.24.3

fix: timeout on citgm tests by @simone-sanfratello in https://github.com/fastify/fastify/pull/5101 chore: add missing use strict directives by @Fdawgs in https://github.com/fastify/fastify/pull/5106

addedchanged
4.24.2

fix: build problems when Symbol.asyncDispose type is not available. by @arthurfiorette in https://github.com/fastify/fastify/pull/5096

changed
4.24.1

fix: citgm by @simone-sanfratello in https://github.com/fastify/fastify/pull/5075 fix: HEAD route reseting by @ivan-tymoshenko in https://github.com/fastify/fastify/pull/5090

changed
4.24.0

docs: Add blank line before onclose hook heading by @kadoshita in https://github.com/fastify/fastify/pull/5042 build(dependabot): ignore tap major updates by @Fdawgs in https://github.com/fastify/fastify/pull/5047 chore: Bump actions/checko

addedfixedchanged
4.23.2

fix: add routeOptions.schema to types by @Uzlopak in https://github.com/fastify/fastify/pull/5035

addedchanged
4.23.1

fix: correct warnings for request.routerPath and request.routerMethod by @Uzlopak in https://github.com/fastify/fastify/pull/5032 fix: add routeOptions.config to types by @mcollina in https://github.com/fastify/fastify/pull/5034

addedchanged
4.23.0

test: reduce output of reqIdGenFactory.test.js by @Uzlopak in https://github.com/fastify/fastify/pull/5012 feat: Add onListen Hook by @BrendenInhelder in https://github.com/fastify/fastify/pull/4899 docs(readme): avoid line breaks in docume

addedchanged
4.22.2

A spurious file (a test run result) was added to the package, which was now removed.

removed
4.22.1

chore: Bump the dev-dependencies group with 1 update by @dependabot in https://github.com/fastify/fastify/pull/5002 docs(ecosystem): add fastify-rabbitmq to ecosystem.md by @Bugs5382 in https://github.com/fastify/fastify/pull/5000 docs(ecos

addedchanged
4.22.0

make FastifySchemaValidationError.params wider by @cm-ayf in https://github.com/fastify/fastify/pull/4476 docs(ecosystem): add fastify-hashids by @andersonjoseph in https://github.com/fastify/fastify/pull/4934 fix: hasPlugin does not track

addedchanged
4.21.0

chore: remove license-checker package by @Uzlopak in https://github.com/fastify/fastify/pull/4914 chore: remove pump devDependency by @Uzlopak in https://github.com/fastify/fastify/pull/4913 ci: create artifacts in coverage workflows by @Uz

addedfixedchanged
4.20.0

build(deps-dev): Bump @sinclair/typebox from 0.28.20 to 0.29.1 by @dependabot in https://github.com/fastify/fastify/pull/4877 Update Prototype-Poisoning.md by @ed-henrique in https://github.com/fastify/fastify/pull/4879 docs: adjust line fo

securityaddedfixed
4.19.2

fix(typescript): route config should not pass url and method by @climba03003 in https://github.com/fastify/fastify/pull/4872 Overload DecorationMethod to fix #4870 by @voxpelli in https://github.com/fastify/fastify/pull/4874 fix: Type infer

changed
4.19.1

docs(typescript): fix typo by @jon-codes in https://github.com/fastify/fastify/pull/4861 docs(testing): add plugin testing guide by @Ekott2006 in https://github.com/fastify/fastify/pull/4849 docs: fix platformatic-cloud anchor id by @sher i

addedchanged