Skip to content

update fast-jwt to 6.2.0#402

Merged
kibertoad merged 1 commit intofastify:mainfrom
kuritz:kuritz/update-fast-jwt
Apr 7, 2026
Merged

update fast-jwt to 6.2.0#402
kibertoad merged 1 commit intofastify:mainfrom
kuritz:kuritz/update-fast-jwt

Conversation

@kuritz
Copy link
Copy Markdown
Contributor

@kuritz kuritz commented Apr 7, 2026

Sets minimum version of fast-jwt to 6.2.0.

Closes: #401

Checklist

@kuritz kuritz marked this pull request as ready for review April 7, 2026 16:59
Copy link
Copy Markdown
Member

@jsumners jsumners left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The caret range qualifier covers this.

@kuritz
Copy link
Copy Markdown
Contributor Author

kuritz commented Apr 7, 2026

it allows updating, but it won't force it if an old version is already locked. i just went back and reinstalled this everywhere we use this package to update the versions in our lockfiles as you are suggesting is possible, but I thought it might be best to explicitly issue a new version that will force these updates for consumers given this version patches a critical vulnerability.

@kibertoad
Copy link
Copy Markdown
Member

I agree with @kuritz on this, it's more reliable this way

@kuritz
Copy link
Copy Markdown
Contributor Author

kuritz commented Apr 7, 2026

feel free to close it, just trying to help in case other consumers don't get CVE alerts and know how to update transitive deps

@kibertoad kibertoad merged commit e05f22a into fastify:main Apr 7, 2026
14 checks passed
@jsumners
Copy link
Copy Markdown
Member

jsumners commented Apr 7, 2026

We typically do not merge such updates. It causes way more churn than affected users simply updating their dependencies. It's literally a useless application of time.

@kibertoad
Copy link
Copy Markdown
Member

@jsumners can't be too prudent with security updates

@jsumners
Copy link
Copy Markdown
Member

jsumners commented Apr 8, 2026

@kibertoad maybe. You're not going to like my current thinking on such things 🤣 https://bsky.app/profile/james.sumners.info/post/3miygkad2ec2n

@kibertoad
Copy link
Copy Markdown
Member

@jsumners there are some good points in that post, I don't see a contradiction. here process worked as intended, community put in the effort

@Casper-Lee Casper-Lee mentioned this pull request Apr 13, 2026
2 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] CVE in fast-jwt <=6.1.0

3 participants