Conversation
Snyk has created this PR to upgrade koa from 2.13.1 to 2.16.4. See this package in npm: koa See this project in Snyk: https://app.snyk.io/org/heap-3EMkSLLMkNg97NWFTBZBsv/project/ff732764-bc42-4f85-87dd-7bd34e66c700?utm_source=github-cloud-app&utm_medium=referral&page=upgrade-pr
|
This is a minor version upgrade for Koa that includes several security fixes. No major API changes are documented, but a behavioral change was introduced to enhance security. Key Changes:
Recommendation: Source: Koa GitHub Releases
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Snyk has created this PR to upgrade koa from 2.13.1 to 2.16.4.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 16 versions ahead of your current version.
The recommended version was released 22 days ago.
Issues fixed by the recommended upgrade:
SNYK-JS-KOA-15353398
SNYK-JS-KOA-10944994
SNYK-JS-KOA-8720152
SNYK-JS-KOA-9679272
Breaking Change Risk
Release notes
Package name: koa
-
2.16.4 - 2026-02-25
- fix(security): Host Header Injection via
-
2.16.3 - 2025-10-18
- fix: normalize referer before redirect by @ fengmk2 in #1909
-
2.16.2 - 2025-07-30
- fix: only allow back redirect to the same origin referer by @ fengmk2 in #1898
-
2.16.1 - 2025-04-06
-
2.16.0 - 2025-02-27
-
2.15.4 - 2025-02-11
-
2.15.3 - 2024-04-11
-
2.15.2 - 2024-03-21
-
2.15.1 - 2024-03-15
-
2.15.0 - 2023-12-29
-
2.14.2 - 2023-04-12
-
2.14.1 - 2022-12-07
-
2.14.0 - 2022-12-06
-
2.13.4 - 2021-10-19
-
2.13.3 - 2021-09-24
-
2.13.2 - 2021-09-24
-
2.13.1 - 2021-01-04
from koa GitHub release notesWhat's Changed
ctx.hostnameby @ killagu GHSA-7gcc-r8m5-44qmWhat's Changed
Full Changelog: v2.16.2...v2.16.3
What's Changed
Full Changelog: v2.16.1...v2.16.2
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: