Repository navigation
chore(deps): update dependency verdaccio to v6.10.5 - #8590
Merged
Merged
Conversation
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
commit: |
sarahetter
approved these changes
Oct 7, 2026
sarahetter
left a comment
Contributor
There was a problem hiding this comment.
Lockfile-only verdaccio 6.9.0 → 6.10.5 (dev, e2e registry). Fixes qs (GHSA-4mjr-xmp4-gh2g, GHSA-x5fp-wj9c-mxmx, GHSA-q8mj-m7cp-5q26) and js-yaml 5 (GHSA-r3ph-w7gj-g6xm). Verified undici stays at 7.30.0 after merging main.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.9.0→6.10.5Release Notes
verdaccio/verdaccio (verdaccio)
v6.10.5Compare Source
Patch Changes
2ccbacf: Migrate the 6.x release workflow to Changesets action v2 and CLI v3.c159460: Improve validation of Search v1 query parameters.sizeandfromnow accept only plain string values; anything else falls back to the default page size and offset, as other non-numeric values already did. Only plain string parameters are forwarded to uplinks. An uplink search response that cannot be read now ends that uplink's results, and local results are still returned. Unexpected errors in the search endpoint are reported through the regular error handler. Registry configuration does not need to change.ec341ee: Validate Search v1 query text before starting a search.Search requests must provide a single, non-blank
textstring. Missing or invalid search text now receives HTTP 400 with the JSON error codeERR_TEXT_MISSING, before searching local packages or uplinks.Earlier 6.x releases could accept searches without text. Clients that call the search API directly must now supply a non-blank query. Valid query text is preserved, and searches with no matching packages continue to return HTTP 200 with an empty results array.
35e8373: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/auth:8.1.4→8.1.5@verdaccio/config:8.3.1→8.3.2@verdaccio/core:8.3.1→8.3.2@verdaccio/hooks:8.1.5→8.1.6@verdaccio/loaders:8.1.4→8.1.5@verdaccio/local-storage-legacy:11.4.4→11.4.5@verdaccio/logger:8.1.4→8.1.5@verdaccio/middleware:8.1.5→8.1.6@verdaccio/package-filter:13.2.2→13.2.3@verdaccio/signature:8.1.4→8.1.5@verdaccio/tarball:13.1.4→13.1.5@verdaccio/ui-theme:9.0.0-next-9.31→9.0.0-next-9.33@verdaccio/url:13.1.4→13.1.5verdaccio-audit:13.1.5→13.1.6verdaccio-htpasswd:13.1.4→13.1.5Package name validation now follows the npm rules for existing packages: names that start with an underscore, use
@without a scope, or contain characters that are not URL-friendly are rejected with HTTP 400 instead of being looked up. Packages whose names cannot be stored as a directory of the same name on every platform (for examplenuloraux.js) are still served from uplinks, but are not cached locally and cannot be published to local storage; a warning is logged when one is requested. Rename any private package with such a name before upgrading. Registry configuration does not need to change.3d1ca06: Improve version validation inGET /<package>/<version>.The endpoint now resolves only versions and dist-tags that the package actually defines. A version or tag name that the package does not define now returns HTTP 404 (
version not found) in every case, instead of an internal server error for some names. Requests for existing versions, ranges and dist-tags behave as before, and registry configuration does not need to change.Update the internal
@verdaccio/*modules to their latest 8.x releases (@verdaccio/coreand@verdaccio/config8.3.1,@verdaccio/auth8.1.4,@verdaccio/middleware8.1.5,verdaccio-htpasswd13.1.4,@verdaccio/local-storage-legacy11.4.4,verdaccio-auth-memory13.1.4,verdaccio-memory10.5.4,verdaccio-audit13.1.5 and the rest of the set), which improve validation of user registration, authentication, API tokens and request parameters. When the htpasswd file is reloaded, users removed from it now stop authenticating without a restart.Update
brace-expansionand ignore two advisories without a published fix (braces,http-cache-semantics) that are not reachable from the registry code paths.v6.10.4Compare Source
Patch Changes
7730e60: Update express to 4.22.3 — directly and through@verdaccio/middleware8.1.4,verdaccio-audit13.1.4 and@verdaccio/test-helper4.1.4 — so the registry's entire HTTPstack resolves qs 6.16.0, which fixes several denial-of-service advisories in query-string
handling: a remotely triggerable crash in
qs.stringify(TypeError on crafted input), anarrayLimitbypass through bracket-key comma parsing that allows memory exhaustion, and aDoS via an attacker-controlled
isBuffercheck (GHSA-4mjr-xmp4-gh2g). Abody-parser/qsresolution covers the one remaining consumer that pins qs below the fix. Query-string
parsing behaviour is otherwise unchanged and no configuration change is needed.
The same update refreshes the development dependency tree, clearing every high-severity
yarn npm auditfinding (stale transitive resolutions of tar, minimatch, socks/ip, js-yaml,form-data, nanoid, postcss, picomatch, tmp and systeminformation, plus vitest 4.1.11 for the
@vitest/mockerpath-traversal advisory) — none of these ship in the published package.aabb0b4: Fixnpm publishfailing withrequest size did not match content lengthwhen authenticating with a token created bynpm token create.The JSON body parser was registered by the API router, which runs after
apiJWTmiddleware()and afterenforceGeneratedTokenMetadata(). The latter awaits a storage lookup for tokens that carry a server-issued key, so the request body was partially consumed before the parser attached. It is now registered before both, as it already is onmaster.e2602b3: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.30→9.0.0-next-9.31v6.10.3Compare Source
Patch Changes
98b58ef: fix: do not fetch client-controlled dist.tarball urls off-uplink @cOmrade3267Only fetch a tarball url that a configured uplink actually serves. Off-uplink urls are
fetched without uplink credentials and only for uplink-synced packages (recorded in
_distfiles); a locally published package returns 404 instead of being fetched. Preventssending an uplink
Authorizationheader to an unrelated host.v6.10.2Compare Source
Patch Changes
6d972d1: fix: resolve fast-uri and brace-expansion security advisoriesfast-uri 3.1.6. Bumps the
ajv/fast-uriresolution from 3.1.5 to 3.1.6, whichfixes four high-severity advisories in the URI parser used by
ajvfor schemaformat validation: host confusion via skipped IDN canonicalization
(GHSA-5jgf-p345-68v8),
SSRF via malformed IPv6 normalization
(GHSA-f65p-4m7j-42xc),
SSRF via repeated hostname percent-decoding
(GHSA-fph4-wmhf-6fwf),
and host confusion via percent-encoded scheme normalization
(GHSA-jqff-g426-hqxp).
brace-expansion DoS cleanup. Updates the remaining vulnerable
brace-expansiontrees (1.1.11 → 1.1.18, 2.0.1 → 2.1.4) forGHSA-mh99-v99m-4gvg and
drops the temporary audit ignores that covered them while the patched
releases were still quarantined by the minimal-age gate.
6d972d1: chore: update e2e libraryca00ee0: fix: stop re-compressing tarballs for gzip-accepting clientsmime-db marks
application/octet-streamas compressible, so the compressionmiddleware re-gzipped every (already gzipped)
.tgzdownload for clientsthat accept gzip — npm and undici do by default — wasting CPU on every
download and stripping the
Content-Lengthheader. Tarball responses arenow excluded from compression; JSON metadata responses stay compressed.
Measured on a 30 MB tarball: ~18x less server CPU and ~20x faster downloads,
with slightly fewer bytes on the wire (gzip over gzip nets negative).
d4b8199: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.28→9.0.0-next-9.30d94ebff: fix: validate the scope segment on the web package endpointsThe readme and sidebar web endpoints now validate the
:scoperoute segmentand return 404 for malformed requests.
v6.10.1Compare Source
Patch Changes
90d5c20: Import shared helpers from@verdaccio/coreand drop the deprecated@verdaccio/utilsdependencyAll internal usages of
@verdaccio/utilsnow resolve the same helpers from@verdaccio/core(validation, auth, crypto, package and author utilities), andthe
@verdaccio/utilsdependency has been removed.7805d50: Limit web UI search responses to 20 packages.c84070b: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.27→9.0.0-next-9.28v6.10.0Compare Source
Minor Changes
51c2733: Expose the optional legacy authentication cache for Verdaccio 6.x throughserver.legacyAuthCache.This feature is intended for performance-sensitive installations that still use legacy bearer tokens. When enabled, Verdaccio caches successful legacy token authentication results for a short period of time, so repeated requests using the same token do not need to run password verification through the authentication plugin every time. Concurrent requests for the same legacy token can also share the same in-flight authentication result.
The cache is disabled by default, so existing installations keep their current authentication behavior unless they explicitly opt in. Basic authentication is not cached. If the cache is enabled, changed or revoked credentials may remain valid until the cached entry expires.
Enable it in
config.yaml:Options:
enabled: enables the legacy token authentication cache. Default:false.ttlMs: time in milliseconds before a cached validation expires. Default:15000.maxEntries: maximum number of cached legacy tokens. Default:1000.See #6147 and the original 8.x backport in #6143.
v6.9.3Compare Source
Patch Changes
3c8f391: Reject wildcard characters in package and tarball path validation.ebc08ba: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):This dependency refresh includes
@verdaccio/package-filter13.2.0withexcludeDeprecatedsupport from #6142 by @jotadeveloper, based on the original work by @davidus27. It also includes the@verdaccio/ui-themeupdate containing the homepage action hover fix from #6135 by @pranshuchittora.@verdaccio/auth:8.1.1→8.1.2@verdaccio/config:8.2.1→8.2.2@verdaccio/core:8.2.1→8.2.2@verdaccio/hooks:8.1.2→8.1.3@verdaccio/loaders:8.1.1→8.1.2@verdaccio/local-storage-legacy:11.4.1→11.4.2@verdaccio/logger:8.1.1→8.1.2@verdaccio/middleware:8.1.1→8.1.2@verdaccio/package-filter:13.1.1→13.2.0@verdaccio/signature:8.1.1→8.1.2@verdaccio/tarball:13.1.1→13.1.2@verdaccio/ui-theme:9.0.0-next-9.23→9.0.0-next-9.26@verdaccio/url:13.1.1→13.1.2@verdaccio/utils:8.2.1→8.2.2verdaccio-audit:13.1.1→13.1.2verdaccio-htpasswd:13.1.1→13.1.2v6.9.2Compare Source
Patch Changes
297dc43: fix: apply package access controls to thestarredByUserendpointThe
GET /-/_view/starredByUserview did not enforce the configured packageaccess policy when listing a user's starred packages. Results are now filtered
through
auth.allow_access, so the response only includes packages therequesting client is authorized to see.
05917d5: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/ui-theme:9.0.0-next-9.22→9.0.0-next-9.23v6.9.1Compare Source
Patch Changes
dfe3938: Update verdaccio dependencies to thelatestnpm dist-tag (@verdaccio/ui-themetracksnext-9):@verdaccio/auth:8.1.0→8.1.1@verdaccio/config:8.2.0→8.2.1@verdaccio/core:8.2.0→8.2.1@verdaccio/hooks:8.1.1→8.1.2@verdaccio/loaders:8.1.0→8.1.1@verdaccio/local-storage-legacy:11.4.0→11.4.1@verdaccio/logger:8.1.0→8.1.1@verdaccio/middleware:8.1.0→8.1.1@verdaccio/package-filter:13.1.0→13.1.1@verdaccio/signature:8.1.0→8.1.1@verdaccio/tarball:13.1.0→13.1.1@verdaccio/ui-theme:9.0.0-next-9.21→9.0.0-next-9.22@verdaccio/url:13.1.0→13.1.1@verdaccio/utils:8.2.0→8.2.1verdaccio-audit:13.1.0→13.1.1verdaccio-htpasswd:13.1.0→13.1.1Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.