NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1453 most downloaded on npm
The optimized & lightweight middleware for serving requests to static assets
Last release 1 years ago
03 Sep 2025
Release timing varies
gaps range from 2 weeks to 1.3 years
Most releases are documented
notes for 36 of 41 stable releases
Nothing withdrawn
no release was ever pulled
8 years old
50 releases · first in 2018
Do not serve top-level files that begin with the directory name: f0113f3
directory name: f0113f3Full Changelog: v3.0.1...v3.0.2
(sirv): ensure "types" field points to real file ( #169 ) Thank you @bluwy
(sirv): ensure "types" field points to real file (#169)
Thank you @bluwy
(sirv-cli): ensure PORT is used if available (#165, #164)
When string, always chose a random port.
Thank you @pixeldrew
Full Changelog: v3.0.0...v3.0.1
One column per quarter.
Now requires Node 18+ : c7d2479 ,
node: prefix for explicit native imports, which unlocks Deno support (#163): 912af6fget-port to 5.1.1 for TS definitions: e5e0826Full Changelog: v2.0.4...v3.0.0
( sirv ) bump mrmime version ( #156 ): ed8fd84 See mrmime@2.0.0 release notes for info. Thank you @benmccann
sirv) bump mrmime version (#156): ed8fd84mrmime@2.0.0 release notes for info.Full Changelog: v2.0.3...v2.0.4
fix(sirv): avoid false-positive on too big range end by @dmkret in #147
Full Changelog: v2.0.2...v2.0.3
( sirv ) Bump totalist version: e8c66e2 This allows for full native ESM support on Node.js
sirv) Bump totalist version: e8c66e2Full Changelog: v2.0.0...v2.0.2
(sirv-cli) Change default port from 5000 to 8080 ( #124 ): 93a920b With macOS Monterey, Apple now reserves port 5000 for AirPlay. This would cause sir
5000 to 8080 (#124): 93a920bsirv-cli to start seemingly successfully, but macOS would intercept all traffic to localhost:5000, causing unexpected behavior for users/clients.(sirv): Supports native ESM usage within Node~!
Now sirv and all its dependencies support ESM natively.
(sirv-cli): Support the NO_COLOR standard (#108): 4b8703b
Thank you @spytec~!
(sirv): Bump totalist version (#86): 0cf66d8
Thank you @aleclarson~!
Add http-server benchmark comparison (#4): 17ea37f
http-server (cache=1) 5,247 req/sec
http-server (cache=0) 5,091 req/sec
sirv-cli (cache=1) 12,612 req/sec
sirv-cli (cache=0) 8,490 req/sec
sirv-cli (cache=1, logs=0) 13,609 req/sec
sirv-cli (cache=0, logs=0) 10,157 req/sec
Full Changelog: v1.0.19...v2.0.0
Replace mime/lite with mrmime : d93f33f Dependency swap for a significant size reduction and makes sirv more ESM-friendly.
mime/lite with mrmime: d93f33fsirv more ESM-friendly.uvu version: 6008dafFull Changelog: v1.0.18...v1.0.19
(sirv): Append charset=utf-8 to HTML content-type ( #106 , #122 ): d1b8ba6 Thank you @aleclarson ~!
charset=utf-8 to HTML content-type (#106, #122): d1b8ba6Full Changelog: v1.0.17...v1.0.18
Nothing published for this version
Nothing published for this version
Nothing published for this version
(sirv): Bump @polka/url to take advantage of this fix
sirv): Bump @polka/url to take advantage of this fix(sirv) Only use req.path if has req._decoded flag exists (#82):
(sirv) Only use req.path if has req._decoded flag exists (#82):
The req._decoded check was added & should have always been in there, since this was sirv's way of preventing duplicate decodeURIComponent calls. However, this was only true when it received a request from a polka@next app, since Polka was previously writing the decoded value to req.path – this changed with polka@v1.0.0-next.16
Now that the latest polka@next (and Express) doesn't decode automatically anymore, req.path isn't trustworthy on its own. It needs req._decoded to be there too in order to trust it.
This combo-check is backwards compatible for polka@next users who don't upgrade and will unblock Express users for the first time, who have always had a "raw" req.path value set.
(sirv-cli): Ensure boolean options are parsed as booleans (#97): 8ebca7c
boolean options are parsed as booleans (#97): 8ebca7c@polka/url dependency version: 7c5162a(sirv) Add Vary header when gzip or brotli is in use (#95): 86e6733 _Thank you @istarkov~!_
sirv) Add Vary header when gzip or brotli is in use (#95): 86e6733
Thank you @istarkov~!(sirv) Use Cache-Control: no-cache when both dev & etag are enabled (#90): c8fe11b _By default dev-mode always used no-store – but this also means tha
sirv) Use Cache-Control: no-cache when both dev & etag are enabled (#90): c8fe11b
By default dev-mode always used no-store – but this also means that any ETag on the response is ignored too. Changing this to no-cache allows the browser to remember the ETag and send if as the If-None-Match header on next request.(sirv) More specific ignore regex default (#88): 5e3d7a8 _Thank you @adam-lynch~!_
(sirv) More specific ignore regex default (#88): 5e3d7a8
Thank you @adam-lynch~!
(sirv) Replace VoidFunction usage in TypeScript definitions (#89): 478b487
(sirv): Use a separate FILES cache per sirv instance (#84): c69bbfb _Thank you @Rich-Harris~!_
(sirv): Use a separate FILES cache per sirv instance (#84): c69bbfb
Thank you @Rich-Harris~!
(sirv): Append must-revalidate Cache-Control directive when maxAge: 0 is used: fb31a46
Only appends when immutable option is not in use!
(sirv) Ensure options.setHeaders changes are respected (#79): 25eb012
sirv) Ensure options.setHeaders changes are respected (#79): 25eb012(sirv) Ensure cached response headers (in "prod" mode) are not mutated between requests (#75, #55): b33bb15 _Thank you @imtiazmangerah!_
sirv) Ensure cached response headers (in "prod" mode) are not mutated between requests (#75, #55): b33bb15
Thank you @imtiazmangerah!(sirv) Set "br" for content-encoding header value (#65): fa4f7db, 7205446 _Thank you @DaGhostman~!_
sirv) Set "br" for content-encoding header value (#65): fa4f7db, 7205446
Thank you @DaGhostman~!sirv) Add additional dotfiles tests: d01fe72Both sirv and sirv-cli now require at least Node v10.x to function (19061bef5206df230102343f1eae1f8d218eaa58). This is the oldest LTS version of Node.
Both sirv and sirv-cli now require at least Node v10.x to function (19061bef5206df230102343f1eae1f8d218eaa58). <br>This is the oldest LTS version of Node.js that's still possesses the "ACTIVE" label.
(sirv-cli) Added HTTP/2 support (#2, #64): 36ba7344fc3896291f32a7e6cb572f87cfebe77d, 8c92751ba976e27d48a9c752256482d8b3d2c8ba
(sirv-cli) Added --gzip and --brotli flags (#3)
(sirv-cli) Allow --single to accept custom fallback: fd55ecab7d20e1cdaa7e5190b1a92d9262a51e07
(sirv-cli) Added --ignores option to escape single: 918102ed741463c6154d458ca63d3637deb54210
(sirv) Added TypeScript definitions (#61): 05058a20cc93fa1ad1a1dca6091c76aec5de571c
(sirv) Support If-None-Match/ETag matching (#56, #46)
(sirv) Added single option, with customizable fallback: f13fbb8bd698d6c9b95df55845dbb237aca1340d, fd55ecab7d20e1cdaa7e5190b1a92d9262a51e07
(sirv) Allow serving of precompiled gzip and/or brotli files: 3d34763619eb6ed520d3377d96e8e64862f90285
(sirv): Ships separate "module" (ESM) and "main" (CJS) entries: 9754302969bc9a603e7a4795a11ecc42d6ed8bc8
sirv) Prevent server crash with malformed URLs (#54): 1757b26bd713368a1d7cde7df338fe843bb5e31csirv) Allow dotfiles option in "dev" mode (#51)sirv) Allow requests to /.well-known/* files (#50): 0a04d66221325ff34b0145bdcac97a8e6a60f64esirv) Force Cache-Control: no-store value for "dev" mode (#45): 604f926c2324781d1f57d37f8ad93674677b82cfsirv) Respect any previous Content-Type on response (#38): c08ac50b25e60ec1518c8712fd25e8f9d5eda7f5, 5ef168f48d8bea850e28d4094ea1a907f3d06a14sirv) Ignore deeply-nested dotfiles (default): 84d4f33f74a7cff2373de6916888a85a1537fe6asirv) Refactor: Consolidate "dev" & "prod" handlers: f1bcc431463605ae112f943a466f8d9809234b68sirv): Refactor: Extract list utility into totalist: 535b2c262e1ca430e4b9de09a7fe3d23d0286a31Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
> NOTICE This version patches a directory-traversal security vulnerability that exists in dev mode only. All users should update _immediately_, even i…
NOTICE <br>This version patches a directory-traversal security vulnerability that exists in
devmode only. All users should update immediately, even if they don't think they're using--devoropts.devon live servers. There are no other changes in this release.
Fixes dev mode security vulnerability (#63): 1e0bac5
Thank you @marvinhagemeister~!
As Marvin describes:
This allows an attacker to traverse the file system outside of the specified directory.
Let's say sirv was initialized to serve files from /foo/bar:
sirv("/foo/bar");
...and an attacker makes a request to:
GET /../../etc/passwd
...then they are able to download the contents of that file.
Attach GitHub Actions: ea15d6a
Update test runner: 2b965cd
Update lerna version: 0b6de8d
Immediately fix regression for --single flag in "dev" mode: c73fd13
--single flag in "dev" mode: c73fd13(sirv): Handle files without an extension correctly (#26): b2e1baf _Wrongly assumed all extensionless files were pathnames meant to be expanded._
(sirv): Handle files without an extension correctly (#26): b2e1baf
Wrongly assumed all extensionless files were pathnames meant to be expanded.
(sirv): Call return from for-loop directly: c39f0e4
(sirv) Change opts.onNoMatch from (res) to (req, res): abe9d69 _Allowing the callback to consume the original request & response is more expected and
sirv) Change opts.onNoMatch from (res) to (req, res): abe9d69
Allowing the callback to consume the original request & response is more expected and flexible.sirv-cli) Maintain Range/partial requests during --dev mode: abe9d69
By sending an empty object, the original request's headers were all lost.Run custom opts.setHeaders function in dev mode: (#22): e4b7cc3
opts.setHeaders function in dev mode: (#22): e4b7cc3(sirv) Respond to `Range` headers/partial requests correctly! (#19): 135db55
(sirv) Respond to Range headers/partial requests correctly! (#19): 135db55
Now, larger files (video, PDF, etc) will be served correctly. Previously, sirv would ignore the ranged requests and pipe down the entire file at once.
sirv) Running dev mode will also send Last-Modified and Content-Length headers: 135db55Replace tiny-glob with manual directory traversal: 38ba617
Replace tiny-glob with manual directory traversal: 38ba617
While tiny-glob is very much a great globbing library, sirv really had no need for a globbing library because it asks for all files within the directory. This makes declaring & responding to filter patterns pointless.
(sirv) Decode incoming URL pathnames (#20, #21): 54dde5f _Thanks @Seb35!_
(sirv) Decode incoming URL pathnames (#20, #21): 54dde5f
Thanks @Seb35!
(sirv) Allow maxAge option to have 0 value: 9a392f1
(sirv) Capitalize all outgoing header names: 633644f
(sirv-cli) Preserve scroll history when initialized (#12): 11ad541 _Thanks @MarSoft!_
sirv-cli) Preserve scroll history when initialized (#12): 11ad541
Thanks @MarSoft!--help output (#14): 35fe1a5
Thanks @paulocoghi!(sirv) Fix: Always add Content-Type response header during dev mode (#10): 810ceb7 _Thanks @btakita for reporting!_
sirv) Fix: Always add Content-Type response header during dev mode (#10): 810ceb7
Thanks @btakita for reporting!(sirv) Added dev option, which skips the file CACHE entirely: 99f6adf, 885cd7f
sirv) Added dev option, which skips the file CACHE entirely: 99f6adf, 885cd7fsirv-cli) Added --dev and -D flags for "dev" mode: f80b4ed, 35394c0Important: As the name suggests, you should only use
devduring development!
sirv) Extracted toAssume from find helper: efdf783sirv-cli) Formatted CLI construction for better legibility: b5c9dbeAllows sub-directory paths to properly match (#7, #8): 9c65ad5 _Thanks @antonheryanto~! 🎉_
(sirv-cli) Update to kleur@2.0.1: 99ed4460b9e5627042e6ebcf895208c778de6b72
sirv-cli) Update to kleur@2.0.1: 99ed4460b9e5627042e6ebcf895208c778de6b72(sirv-cli) Use kleur as color lib: f25349f9dc672cc32872269637955e8167162f84
sirv-cli) Use kleur as color lib: f25349f9dc672cc32872269637955e8167162f84(sirv) Fix setHeaders placement: 72a8b8c
(sirv) Fix setHeaders placement: 72a8b8c
(sirv-cli) Make executable available as sirv not sirv-cli: b0187f2
(sirv) Fix next() caller — don't pass res: 45b73c6 _Passing anything to next() is interpreted as an Error; shuts down instead of skips._
sirv) Fix next() caller — don't pass res: 45b73c6
Passing anything to next() is interpreted as an Error; shuts down instead of skips.sirv) Update README docs for conditional next() handling: 0bf6b9esirv-cli) Replace clorox with ansi-colors: 4a558e6Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →