NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3817 most downloaded on npm
The routing foundation of `serve`
Last release 7 months ago
03 Mar 2026
Ships unpredictably
gaps range from 2 weeks to 2.4 years
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
67 releases · first in 2018
Fix: update minimatch to 3.1.5 to resolve security vulnerabilities: #228
Huge thanks to @ParakhJaggi for helping!
Replace the fast-url-parser module with the node:url module: #207
fast-url-parser module with the node:url module: #207jest: #216path-to-regexp to 3.3.0: #217Huge thanks to @gweesin, @alana-cruickshank, and @GabrielCastro for helping!
One column per quarter.
Ensure npm run prepublish gets executed: #190
npm run prepublish gets executed: #190Bump lodash from 4.17.15 to 4.17.19: #124
Huge thanks to @kachkaev for helping!
Regenerate yarn.lock file: 55962ccdc80f00286b8f32e608020c5bac48ab61
yarn.lock file: 55962ccdc80f00286b8f32e608020c5bac48ab61cleanUrls config is enabled: #122Update deps to fix GitHub Security Alerts: #100
Huge thanks to @TooTallNate for helping!
Include file extension in ETag header generation: #101
ETag header generation: #101Add etag response header config option: #94
etag response header config option: #94Update style same as Now platform directory listing: #93
Using posix path resolution: #89
Huge thanks to @joeldenning and @AxlLind for helping!
Removed faulty description: #88
Disable symlinks by default: #84
### Patches - Fix path issue: #76
Encode redirection targets properly: #72
Huge thanks to @pd4d10 for helping!
Huge thanks to @pd4d10 for helping!
Include missing file in production bundle: #66
Add missing info to readme: #53
Huge thanks to @compulim and @WellingGuzman for helping!
Interpolate template variables correctly: #64
### Patches - Bring back full coverage: #57
Handle errors thrown in createReadStream properly: #56
createReadStream properly: #56Allow config.public to be an absolute path: #50
config.public to be an absolute path: #50headers example JSON: #46Huge thanks to @balupton, @WellingGuzman, and @timothyis for helping!
Only try range if size is accessible: #44
Huge thanks to @mischnic for helping!
Huge thanks to @mischnic for helping!
Updated link of Spectrum badge: #43
Make extglobs work as they should: #41
Huge thanks to @igorklopov for helping!
Handle ETag and If-None-Match: #39
ETag and If-None-Match: #39Support sendError as middleware: #38
sendError as middleware: #38Huge thanks to @remy for helping!
Allow for setting headers in createReadStream: #37
createReadStream: #37Huge thanks to @terrencewwong for helping!
Huge thanks to @terrencewwong for helping!
Allow custom headers to be set for default error responses: #34
Properly handle requests with malformed URIs: #33
Fixes public url in options table: #32
public url in options table: #32Huge thanks to @manovotny for helping!
Allow dots in value of public option: #29
public option: #29Huge thanks to @andyburke for helping!
### Minor Changes - Added error templates: #25
Fixed requests to /index being redirected wrong: #24
/index being redirected wrong: #24Added use cases for this library: #23
Added renderSingle configuration property: #22
renderSingle configuration property: #22Make cleanUrls stop stripping .htm extension: #20
cleanUrls stop stripping .htm extension: #20Update README.md to fix 'public' option data type: #18
Huge thanks to @MunGell for helping!
Added default Content-Disposition header: #16
Content-Disposition header: #16Added charset to Content-Type header: #15
Content-Type header: #15Prevent path traversal vulnerabilities: #14
Fallback to mime type of rewrittenPath when mime type of relativePath is null: #13
Huge thanks to @quocnguyen for helping!
Render correct icon for parent path: #12
### Patches - Fixed rewriting behavior: #11
Prevent maximum call size from being reached: #9
Precisely document potential value for paths: #8
Applied improvements from another round of testing: #7
Added support for async createReadStream: #6
fs-extra package: #5createReadStream: #6Made license legally correct: 0cbc7ce6d58929fc6a5356235c977de48d02eee8
Added NYC and ignored its output: 4d0d91a691ce4b0e826da961a436f8c96935edd6
Upload only the files needed to npm: 6ef12ade0e262fad1ca75383b730ba769f338137
Added 10 integration tests: 6522921d2e25cdec0a8588742ecfd887026289f8
README.md and added 10 more tests: f933403d898de8563ce918263b2375afcd0c6c5aAllow directory listing and clean URLs to work at the same time: 0a349f3f83ecc9d59d43601b02a30f65b58f0088
Removed useless file extension: 1af51ac3937563d511dec218d69c1b68a477503f
Made file sorting a little more efficient: a97c836b496c3765070061f197fbea64b2588b17
Automatically try to render 404.html for not-found routes: 36a25832e95f1be6cf58f7f1a821eccbcb1cff7c
404.html for not-found routes: 36a25832e95f1be6cf58f7f1a821eccbcb1cff7cProperly display size of files in directory listing: 57c03d33ff242b0abfb666184b62e1a716c7ad23
Documented config property for excluding paths from listing: 605b56d72a19a63f64f1bc87c43bfb0e273ea16a
trailingSlash config property: 2abc1dd9879a9a92a8399fa7900d148574c46c40trailingSlash is true: 4fb8ddda521d7ddd94fedf94d86099b8e324ea78Ignored template file: 295718fc72c805fa93c6cbe7c63df0bad36b6e3d
Your coding agent can read these notes before it upgrades. Set up the MCP server →