NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3210 most downloaded on npm
Koa web app framework
Last release 4 months ago
21 May 2026
Release timing varies
gaps range from 9 days to 4 months
Some releases are documented
notes for 15 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
13 years old
125 releases · first in 2013
fix: request.length overflows on Content-Length > 2GB by @tejgokani in https://github.com/koajs/koa/pull/1961
Full Changelog: https://github.com/koajs/koa/compare/v3.2.0...v3.2.1
docs: remove dead Job Board links by @Jerry-CodeHub in https://github.com/koajs/koa/pull/1926
Full Changelog: https://github.com/koajs/koa/compare/v3.1.2...v3.2.0
One column per quarter.
fix: typo in troubleshooting.md by @WuMingDao in https://github.com/koajs/koa/pull/1916
ctx.hostname by @killagu https://github.com/koajs/koa/security/advisories/GHSA-7gcc-r8m5-44qmFull Changelog: https://github.com/koajs/koa/compare/v3.1.1...v3.1.2
fix: only original value destroy if the new value is not a stream by @yowainwright in https://github.com/koajs/koa/pull/1914
Full Changelog: https://github.com/koajs/koa/compare/v3.1.0...v3.1.1
feat: fixes mem leak relating to issue-1834 by @yowainwright in https://github.com/koajs/koa/pull/1893
Full Changelog: https://github.com/koajs/koa/compare/v3.0.3...v3.1.0
fix: normalize referer before redirect by @fengmk2 in https://github.com/koajs/koa/pull/1908
Full Changelog: https://github.com/koajs/koa/compare/v3.0.2...v3.0.3
fix: fixes response.attachment behaviour leads to Content-Type Sniffing by @yowainwright in https://github.com/koajs/koa/pull/1904
Full Changelog: https://github.com/koajs/koa/compare/v3.0.1...v3.0.2
fix(security): only allow same origin referer on response back https://github.com/koajs/koa/commit/422c551c63d00f24e2bbbdf492f262a5935bb1f0
Full Changelog: https://github.com/koajs/koa/compare/v3.0.0...v3.0.1
Removes generator deprecation messages. Generators are no longer supported. Koa no longer asserts if generators are used. Set content-length: 0 if bod…
This is a major release.
.redirect('back'), adds .back(fallback_url) @fl0w https://github.com/koajs/koa/pull/1115.redirect(), don't render redirect values in anchor ref https://github.com/koajs/koa/commit/ff25eb4a7f2392df46481fe86355161067687312req.origin should display the origin header if it exists, not the current hostname https://github.com/koajs/koa/issues/1008. origin now aligns with the Origin header as used in CORS..body=<json> should not overwrite type if type already json https://github.com/koajs/koa/issues/1120ctx.throw now requires a format of ctx.throw(status, error, properties). See: https://www.npmjs.com/package/http-errorsconst ctx = app.currentContext.ctx.type = 'json' and ctx.body = null #1059 @likegunfix: don't render redirect values in anchor ref
fix: don't render redirect values in anchor ref
.req.origin now represents req.headers.origin
Breaking Changes:
req.headers.origin.body=<json> does not overwrite .type= if the type is already jsonENOENT error support - please check your file handling functionsNothing published for this version
Update http-errors to v2.0.0 #1486
breaking changes
http-errors to v2.0.0 #1486
ctx.throw now requires a format of ctx.throw(status, error, properties). See: https://www.npmjs.com/package/http-errorsres.redirect('back'), add back() method to ctx #1115URLSearchParams #1828createAsyncCtxStorageMiddleware #1817features
updates
fixes
exports.defaults in package.json #1630ctx in error handler #1758migrations
jest to the native node test runner #1845Nothing published for this version
Nothing published for this version
fix(security): Host Header Injection via ctx.hostname by @killagu https://github.com/koajs/koa/security/advisories/GHSA-7gcc-r8m5-44qm
ctx.hostname by @killagu https://github.com/koajs/koa/security/advisories/GHSA-7gcc-r8m5-44qmfix: normalize referer before redirect by @fengmk2 in https://github.com/koajs/koa/pull/1909
Full Changelog: https://github.com/koajs/koa/compare/v2.16.2...v2.16.3
fix: only allow back redirect to the same origin referer by @fengmk2 in https://github.com/koajs/koa/pull/1898
Full Changelog: https://github.com/koajs/koa/compare/v2.16.1...v2.16.2
fix: don't render redirect values in anchor ref
fix: don't render redirect values in anchor ref
This is a backported release to fix core underlying issue with HEAD requests when using http2.createSecureServer. See discussion at https://github.com
This is a backported release to fix core underlying issue with HEAD requests when using http2.createSecureServer. See discussion at https://github.com/koajs/koa/pull/1593 and https://github.com/koajs/koa/issues/1547.
Fix: avoid redos on host and protocol getter, see https://github.com/koajs/koa/security/advisories/GHSA-593f-38f6-jp5m
Full Changelog: https://github.com/koajs/koa/compare/2.15.3...2.15.4
Fix: avoid redos on host and protocol getter, see https://github.com/koajs/koa/security/advisories/GHSA-593f-38f6-jp5m
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →