NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4995 most downloaded on npm
Plugin for serving static files as fast as possible.
Last release 8 days ago
26 Sep 2026
Release timing varies
gaps range from 8 days to 5 months
Nearly every release is documented
notes for 51 of 52 stable releases
Nothing withdrawn
no release was ever pulled
4 years old
53 releases · first in 2022
One column per quarter.
fix: use registered root for relative downloads by @lprnmns in #610
This is a security release for GHSA-r799-r9gc-m956 (CVE-2026-90982).
This is a security release for GHSA-r799-r9gc-m956 (CVE-2026-90982).
It fixes a route guard and allowedPath bypass on case-insensitive filesystems. Users should upgrade to @fastify/static 10.1.4.
Full Changelog: v10.1.3...v10.1.4
chore: bump c8 from 11.0.0 to 12.0.0 by @dependabot [bot] in #602
Full Changelog: v10.1.2...v10.1.3
ci: pin actions to commit-hash by @Fdawgs in #601
docs(readme): fix typos by @Fdawgs in #600
fix: set Vary: Accept-Encoding for preCompressed responses by @LeSingh1 in #586
@fastify/error for errors and add option suppressWarning by @climba03003 in #599Full Changelog: v10.0.0...v10.1.0
setHeaders now using FastifyReply instead of Response .
setHeaders now using FastifyReply instead of Response.You should refactor your code to use the reply helpers.
For example,
// Before
const fastify = require('fastify')({logger: true})
const path = require('node:path')
fastify.register(require('@fastify/static'), {
root: path.join(__dirname, 'public'),
prefix: '/public/', // optional: default '/',
setHeaders(res) {
res.setHeader('X-Test', 'Foo')
}
})
// After
const fastify = require('fastify')({logger: true})
const path = require('node:path')
fastify.register(require('@fastify/static'), {
root: path.join(__dirname, 'public'),
prefix: '/public/', // optional: default '/',
setHeaders(reply) {
reply.header('X-Test', 'Foo')
}
})Full Changelog: v9.3.0...v10.0.0
chore: update fastify-plugin dependency to version 6.0.0 by @Puppo in #594
chore(.gitattributes): retain binary file eol style by @Fdawgs in #577
Full Changelog: v9.1.3...v9.2.0
fix: support wildcard prefixes with route params by @mcollina in #576
Full Changelog: v9.1.2...v9.1.3
fix: resolve wildcard paths in encapsulated contexts by @mcollina in #574
Full Changelog: v9.1.1...v9.1.2
This fixes CVE CVE-2026-6410 https://github.com/fastify/fastify-static/security/advisories/GHSA-pr96-94w5-mx2h. This fixes CVE CVE-2026-6414 https://g…
This fixes CVE CVE-2026-6410 https://github.com/fastify/fastify-static/security/advisories/GHSA-pr96-94w5-mx2h. This fixes CVE CVE-2026-6414 https://github.com/fastify/fastify-static/security/advisories/GHSA-x428-ghpx-8j92.
Full Changelog: https://github.com/fastify/fastify-static/compare/v9.1.0...v9.1.1
build(deps-dev): bump @types/node from 24.10.4 to 25.0.3 by @dependabot[bot] in https://github.com/fastify/fastify-static/pull/552
Full Changelog: https://github.com/fastify/fastify-static/compare/v9.0.0...v9.1.0
build(deps): bump content-disposition from 0.5.4 to 1.0.1 by @dependabot[bot] in https://github.com/fastify/fastify-static/pull/547
Full Changelog: https://github.com/fastify/fastify-static/compare/v8.3.0...v9.0.0
refactor: remove usage of deprecated request.routeConfig by @inyourtime in https://github.com/fastify/fastify-static/pull/530
Full Changelog: https://github.com/fastify/fastify-static/compare/v8.2.0...v8.3.0
build(deps): bump @fastify/send from 3.3.1 to 4.0.0 by @dependabot[bot] in https://github.com/fastify/fastify-static/pull/513
Full Changelog: https://github.com/fastify/fastify-static/compare/v8.1.1...v8.2.0
chore: rename master to main by @Fdawgs in https://github.com/fastify/fastify-static/pull/507
preCompressed by @genki in https://github.com/fastify/fastify-static/pull/509Full Changelog: https://github.com/fastify/fastify-static/compare/v8.1.0...v8.1.1
build(dependabot): reduce npm updates to monthly by @Fdawgs in https://github.com/fastify/fastify-static/pull/504
Full Changelog: https://github.com/fastify/fastify-static/compare/v8.0.4...v8.1.0
docs(readme): update ci badge syntax by @Fdawgs in https://github.com/fastify/fastify-static/pull/486
node: prefix for builtins by @Fdawgs in https://github.com/fastify/fastify-static/pull/490Full Changelog: https://github.com/fastify/fastify-static/compare/v8.0.3...v8.0.4
style: remove trailing whitespace by @Fdawgs in https://github.com/fastify/fastify-static/pull/478
contentType send option by @Fdawgs in https://github.com/fastify/fastify-static/pull/484Full Changelog: https://github.com/fastify/fastify-static/compare/v8.0.2...v8.0.3
fix: respect custom status code when successfully send file by @climba03003 in https://github.com/fastify/fastify-static/pull/476
Full Changelog: https://github.com/fastify/fastify-static/compare/v8.0.1...v8.0.2
chore: update fastify to ^5.0.0 by @Fdawgs in https://github.com/fastify/fastify-static/pull/473
Full Changelog: https://github.com/fastify/fastify-static/compare/v8.0.0...v8.0.1
build(deps-dev): bump pino from 8.21.0 to 9.1.0 by @dependabot in https://github.com/fastify/fastify-static/pull/453
next into master by @jsumners in https://github.com/fastify/fastify-static/pull/454Full Changelog: https://github.com/fastify/fastify-static/compare/v7.0.4...v8.0.0
Nothing published for this version
Fix for files with % in filename by @chetbox in https://github.com/fastify/fastify-static/pull/452
% in filename by @chetbox in https://github.com/fastify/fastify-static/pull/452Full Changelog: https://github.com/fastify/fastify-static/compare/v7.0.3...v7.0.4
build(deps-dev): bump tsd from 0.30.7 to 0.31.0 by @dependabot in https://github.com/fastify/fastify-static/pull/446
Full Changelog: https://github.com/fastify/fastify-static/compare/v7.0.2...v7.0.3
chore(.gitignore): add .tap/ dir by @Fdawgs in https://github.com/fastify/fastify-static/pull/437
Full Changelog: https://github.com/fastify/fastify-static/compare/v7.0.1...v7.0.2
build(deps-dev): bump @fastify/compress from 6.5.0 to 7.0.0 by @dependabot in https://github.com/fastify/fastify-static/pull/433
dirList by @gurgunday in https://github.com/fastify/fastify-static/pull/435Full Changelog: https://github.com/fastify/fastify-static/compare/v7.0.0...v7.0.1
build(deps-dev): bump tsd from 0.29.0 to 0.30.0 by @dependabot in https://github.com/fastify/fastify-static/pull/424
fastify.io links with fastify.dev by @Fdawgs in https://github.com/fastify/fastify-static/pull/425fastify.io links with fastify.dev by @Fdawgs in https://github.com/fastify/fastify-static/pull/426setHeaders option by @EvanHahn in https://github.com/fastify/fastify-static/pull/428Full Changelog: https://github.com/fastify/fastify-static/compare/v6.12.0...v7.0.0
fix eslint by @gurgunday in https://github.com/fastify/fastify-static/pull/415
u unicode flag to regex by @Fdawgs in https://github.com/fastify/fastify-static/pull/418typeof undefined check by @Fdawgs in https://github.com/fastify/fastify-static/pull/420Full Changelog: https://github.com/fastify/fastify-static/compare/v6.11.2...v6.12.0
fix: allow fallback to fastify@2.22 route config by @climba03003 in https://github.com/fastify/fastify-static/pull/410
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.11.1...v6.11.2
Fix request route config deprecation warnings by @TTPO100AJIEX in https://github.com/fastify/fastify-static/pull/409
node: prefix to bypass require.cache call for builtins by @Fdawgs in https://github.com/fastify/fastify-static/pull/407Full Changelog: https://github.com/fastify/fastify-static/compare/v6.11.0...v6.11.1
Update README with 404+wildcard behavior by @Ethan-Arrowood in https://github.com/fastify/fastify-static/pull/390
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.10.2...v6.11.0
ci: only trigger on pushes to main branches by @Fdawgs in https://github.com/fastify/fastify-static/pull/377
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.10.1...v6.10.2
chore(example/public/images): compress sample image by @Fdawgs in https://github.com/fastify/fastify-static/pull/373
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.10.0...v6.10.1
chore(.gitignore): add bun lockfile by @Fdawgs in https://github.com/fastify/fastify-static/pull/361
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.9.0...v6.10.0
Fix/348 multi root and pre compression infinite loop by @davideroffo in https://github.com/fastify/fastify-static/pull/360
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.8.0...v6.9.0
Update to @fastify/send v2 by @mcollina in https://github.com/fastify/fastify-static/pull/358
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.7.0...v6.8.0
chore(license): update license year by @Fdawgs in https://github.com/fastify/fastify-static/pull/355
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.6.1...v6.7.0
build(deps-dev): bump tsd from 0.24.1 to 0.25.0 by @dependabot in https://github.com/fastify/fastify-static/pull/347
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.6.0...v6.6.1
feat: allow to serve hidden files by @leandroandrade in https://github.com/fastify/fastify-static/pull/345
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.5.1...v6.6.0
chore: replace use of deprecated variadic listen() by @Fdawgs in https://github.com/fastify/fastify-static/pull/329
listen() by @Fdawgs in https://github.com/fastify/fastify-static/pull/329return from sync route handlers examples by @Fdawgs in https://github.com/fastify/fastify-static/pull/333Full Changelog: https://github.com/fastify/fastify-static/compare/v6.5.0...v6.5.1
docs: use npm install alias; remove redundant --save arg
📚 PR:
npm install alias; remove redundant --save argchore(.gitignore): use updated skeleton template by @Fdawgs in https://github.com/fastify/fastify-static/pull/312
"module": "nodenext" compatible by @wight554 in https://github.com/fastify/fastify-static/pull/311Full Changelog: https://github.com/fastify/fastify-static/compare/v6.4.0...v6.4.1
chore: fix typo by @is2ei in https://github.com/fastify/fastify-static/pull/305
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.3.0...v6.4.0
Nothing published for this version
fix: correct ListOptions type by @is2ei in https://github.com/fastify/fastify-static/pull/304
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.2.0...v6.3.0
feat: list option with dotfiles option by @is2ei in https://github.com/fastify/fastify-static/pull/302
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.1.0...v6.2.0
fix: update glob to version 8 and fix broken tests by @guilhermelimak in https://github.com/fastify/fastify-static/pull/297
Full Changelog: https://github.com/fastify/fastify-static/compare/v6.0.0...v6.1.0
Update to fastify@4 by @mcollina in https://github.com/fastify/fastify-static/pull/292
Full Changelog: https://github.com/fastify/fastify-static/compare/v5.0.2...v6.0.0
fix: follow symlink subdir without wildcard by @is2ei in https://github.com/fastify/fastify-static/pull/282
Full Changelog: https://github.com/fastify/fastify-static/compare/v5.0.1...v5.0.2
docs: update references to old fastify-* modules by @Fdawgs in https://github.com/fastify/fastify-static/pull/288
Full Changelog: https://github.com/fastify/fastify-static/compare/v5.0.0...v5.0.1
docs(readme): fix dead link to fastify docs by @is2ei in https://github.com/fastify/fastify-static/pull/275
Full Changelog: https://github.com/fastify/fastify-static/compare/v4.6.1...v5.0.0
Your coding agent can read these notes before it upgrades. Set up the MCP server →